Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects attempts by AutoIt scripts (running as AutoIt3.exe or from Temp directories) to perform process injection into the Windows Character Map utility (charmap.exe). It monitors for suspicious API calls like OpenProcess, CreateRemoteThread, and VirtualAllocEx, specifically looking for memory access and protection flags commonly used during malicious process injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of MSBuild.exe initiated by PowerShell involving specific suspicious file names or extensions (.csproj, .xml) or project naming conventions, followed immediately (within 15 minutes) by an external network connection from the MSBuild process to a specific suspicious IP address or non-standard port.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
202
Detects potential misuse of the WinGet configuration feature, where remote Desired State Configuration (DSC) YAML files are retrieved using masqueraded file extensions (e.g., .jpg or .txt) or suspicious outbound connections on port 8443, which may indicate an adversary attempting to hide malicious configurations or bypass network filtering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects specific samples of the Rmrlx information stealer by identifying unique file artifacts, mutex names (e.g., Global\EVOLUTION), and debugging/staged files commonly associated with its execution environment, including samples exhibiting IP-checking evasion techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of 'rundll32.exe' or 'dllhost.exe' with command-line arguments typically associated with loading Control Panel items (.cpl files). This behavior is often used by adversaries to proxy execution of malicious payloads or bypass security controls by leveraging legitimate Windows binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the creation of a file named 'Normaliz.dll' within an 'AppData\Roaming\Traiolx Custom Utils' directory. The rule matches a known malicious MD5 hash or a specific folder path structure, which is indicative of potential DLL sideloading or persistence mechanisms using an abnormally located DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects unexpected crashes or restarts of the Windows Defender service (MsMpEng.exe) occurring in temporal proximity to activities associated with the ShieldCrash PoC or tampering within the Windows Defender object manager namespace. This rule aims to identify potential exploitation attempts targeting Windows Defender, specifically correlating security service instability with known malicious indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
7025
Detects anomalous child processes spawned by a Chrome renderer process. This behavior is often indicative of exploitation attempts, such as the BlueMoon exploit kit leveraging CVE-2026-85046, where a compromised renderer attempts to escape the sandbox or execute arbitrary code in the host process.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
8025
This rule detects suspicious PowerShell activity including the use of PowerShell to invoke 'curl.exe' for data transfer or the creation of randomly named executables (6-10 characters) within the 'AppData\Local\Temp' directory, which is a common indicator of file staging or malware execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule detects the creation of a Windows scheduled task that triggers an hourly execution of an obfuscated PowerShell script. The script incorporates XOR-encoded data and references known external malicious URLs, suggesting a persistence mechanism used by malware to download or communicate with attacker-controlled infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects execution of 'codeflush.exe' or attempts to rename files involving 'codeflush.exe' and 'pythonw.exe' within 'MusicLibrariesPackage' directories. This activity often indicates the execution of potentially malicious scripts or tools masquerading as legitimate software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects a specific sandbox/analysis evasion pattern associated with the QUICAgent malware, which involves a tight hashing loop and a randomized 100-600ms delay occurring between process initiation and the first outbound network connection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the creation of a shortcut (.lnk) file within the Windows startup folder using PowerShell. The rule monitors for PowerShell processes executing commands to create .lnk files (e.g., via WScript.Shell) or directly monitors file creation events targeting the startup directory. This behavior is indicative of malicious persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule detects the execution of cmd.exe with a command line containing both '/k' and 'Set' commands, alongside a regex pattern that searches for specific variable expansion techniques ('%var:~offset,length%'). This pattern is frequently used to obfuscate command lines or bypass static security signatures by reconstructing strings at runtime, often in conjunction with PowerShell commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of PowerShell with execution policy bypass flags that simultaneously attempts to use curl.exe and Copy-Item to interact with suspicious remote domains or obfuscated command line arguments, potentially indicating a malicious payload delivery and staging attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule detects the use of xcopy.exe with a specific set of flags (/s, /e, /y, /c, /q, /h, /b) typically used for recursive, forced, and quiet file copying, when executed from a path matching 'C:\Users\Public\[A-Za-z0-9]+'. This behavior is often associated with adversaries staging data for exfiltration or moving lateral movement tools within a compromise directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the execution of 'gitlab-runner.exe' with command-line arguments indicative of runner registration, configuration file interaction, or process execution. This activity may be indicative of legitimate CI/CD pipeline setup or potential persistence mechanism installation if performed by unauthorized accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule monitors for the creation of files with the .ent extension within the Microsoft Internet Explorer directory. The rule specifically looks for files with a six-character alphanumeric name (e.g., abc123.ent), which may indicate the use of custom scripts, configuration files, or data staging by potentially malicious actors leveraging the browser's directory structure for persistence or data storage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects the creation of scheduled tasks using schtasks.exe that are configured to repeat every minute, specifically targeting known malicious or suspicious filenames such as 'MicrosoftUserInterfacePicturesUpdateTackMachine', 'userscreen.exe', or 'config.cat'. The rule monitors both process creation command lines and registry modifications within the Windows Task Scheduler tree.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
This rule detects suspicious directory creation or file attribute modifications within the 'naverwhale' roaming AppData directory. Adversaries may use this path to stage malicious payloads, persistence mechanisms, or to impersonate legitimate browser files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Detects execution of potential Python-based backdoors or loaders that reference specific configuration files named 'config.cat' or 'AccountConfig.cat'. This behavior may indicate an adversary utilizing Python for command and control or malicious script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
002
Page 189 of 1871