Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

This rule detects potential multi-stage desktop takeover attacks by monitoring sequences of process execution within a 5-minute window. It looks for initial shell (explorer.exe or cmd.exe) spawning script-based tools (mshta.exe, wscript.exe, cscript.exe, powershell.exe, cmd.exe) with suspicious command-line arguments (extensions like .lnk, .url, .hta, or PowerShell-specific artifacts like 'IEX', 'DownloadString', or '-enc'). This is immediately followed by a secondary stage where PowerShell, cmd, or rundll32 are used to load external DLLs, register modules via regsvr32, or interact with AppData/Local/Temp directories, indicative of payload staging and execution.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
003
This rule detects potential adversary activity aimed at disabling security tools, critical infrastructure services, or cloud synchronization agents. It monitors for a high volume (6 or more) of process termination commands (e.g., taskkill, net stop) or registry-based service disabling (Start value 4) targeting a predefined list of security and critical system services within a 3-minute window, which is indicative of an attempt to blind security monitoring or disrupt system availability.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
005
This rule detects mass disabling of Windows Event Log channels by monitoring registry value modifications where multiple 'Enabled' values are set to '0' within a short timeframe. This behavior is indicative of anti-forensics activity where an adversary attempts to suppress specific log sources to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
415
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
405
Detects a security-software presence check (360 Total Security/eScan process names) followed within 10 minutes by a persistence-establishing event from the same parent process.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects registration/activity of the msagent.sys filesystem minifilter driver used to deny access to and hide CoolClient-protected files and directories.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
102
Detects DLL sideloading where a renamed Sangfor executable (defender.exe/Sang.exe) loads libngs.dll/libsrapc.dll outside the legitimate install path or with a signer mismatch.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects modification of the CoolClient rootkit's stealth-configuration registry value (Wid_H1deF5Dirs) under the \SYSTEM\RNG hive.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects CoolClient's elevated self-relaunch using the 'passuac' command-line parameter combined with RPC-based process creation and PPID spoofing to bypass UAC.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
202
Detects creation of the 'goopdate' Run-key value pointing to Sang.exe/defender.exe with the 'work' argument and a %programdata% path, used by CoolClient for persistence.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Correlates at least 3 of 4 distinct Abyssos background polling threads (clipboard, process list, network connections, screen capture) launched by the same unsigned/unknown-signature parent process within the same 5-minute window.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects the DOUBLECUP/ClickFix loader activity which involves a sequence of suspicious command-line execution patterns. The rule correlates three specific behaviors occurring within a 5-minute window: finding PowerShell paths using 'where', searching for the 'ZZ1984' marker using 'findstr', and executing a minimized background command process. This combination is highly indicative of the ClickFix delivery chain used to trick users into running malicious commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
8019
Detects the Abyssos UAC_BYPASS_FODHELPER technique: a ms-settings\Shell\Open\command registry value set immediately before fodhelper.exe launches an unsigned child payload, silently elevating to a high-integrity process without a UAC prompt.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a WinRAR-extracted OnyxC2 loader spawning an identical self-copy child process from a temp/download path, marking the transition from loader stage to active stealer logic.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
302
Detects creation of the ONYXC2 mutex used by the malware to enforce single-instance execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects extraction and execution of OnyxC2 lure archives (Setup_File*.zip, Fling-Standalone*.zip) via WinRAR/7-Zip from a Downloads/Temp directory, correlating the archive-open with the lure-named installer executing shortly after.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Matches endpoint file/process hashes and network IPs against a curated, freshness-checked OnyxC2 indicator feed.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
302
Detects creation of a non-default hidden desktop by a browser process, correlated with either an inherited long-lived authenticated browser network session or a non-standard parent process, consistent with OnyxC2's HVNC capability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects a multi-hop HTTP redirect chain traversing two or more known OnyxC2 phishing lure domains from the same host within a two-minute window, consistent with the redirect obfuscation used before final payload delivery.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
This rule detects DNS configuration changes (via 'netsh' commands or registry modifications to the 'NameServer' value) initiated by specific system processes ('SwiService.exe' or 'svchost.exe') shortly after a Plug-and-Play (PnP) event, such as a USB drive connection. This pattern is indicative of potential malicious activity attempting to redirect DNS queries upon the insertion of unauthorized hardware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
208
This rule detects potential privilege escalation through the abuse of a debug backdoor in the Wacom WTabletServiceISD service. It identifies when the 'PowerT' registry value is set for the service, followed shortly by the service spawning a command shell (cmd.exe or powershell.exe) under SYSTEM privileges. It specifically excludes scenarios where AutoAdminLogon is enabled, which might otherwise trigger false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
008
Page 476 of 1866