Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the presence of PIVOTPIPE .NET loader components within files by searching for specific magic bytes, debug strings, hardcoded developer file paths, and agent-related operational strings.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the GHAPPIER four-stage loader execution chain initiated during npm postinstall processes. This rule monitors for malicious child process spawning (cmd, powershell, curl, wget) by node or npm, as well as the presence of specific markers like the '.git-checker' string or URLs associated with the PolinRider/FAMOUS CHOLLIMA npm supply chain campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the GHAPPIER four-stage malware loader, specifically targeting npm-based JavaScript files. The rule identifies malicious activity through specific artifacts including hardcoded C2 URLs (vercel.app domains), campaign markers, file paths, and eval-based execution patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the deletion of 'loader.js' from the '%APPDATA%\VSCODE\' directory. This activity is consistent with the initial execution phase of GHAPPIER RAT, where the implant removes its dropper file to avoid detection and hinder forensic analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects instances where rundll32.exe is used to execute a DLL file directly from a remote WebDAV-mounted network path (indicated by the 'DavWWWRoot' string). This technique allows for the execution of arbitrary code without writing the malicious payload to the local disk, a common tactic seen in fileless malware delivery and campaigns like ClearFake.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
This rule detects the presence of ZigCryptoStealer malware deployed via a NativeAOT-compiled Windows executable. The detection relies on identifying specific hardcoded infrastructure strings, such as a BNB Smart Chain RPC endpoint and a specific contract address used to resolve C2 domains. It also looks for common sideloading hosts associated with the malware's delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects internal SMB traffic indicative of P2P beaconing using the IPC$ named pipe, which is often a sign of lateral movement or command-and-control communication between compromised hosts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects unauthorized attempts to modify or patch the AmsiScanBuffer function within amsi.dll in a remote process. This behavior is indicative of an AMSI bypass attempt, a technique often used by malicious loaders and fileless malware to evade security product scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the PIVOTPIPE .NET loader's AMSI-bypass routine by monitoring for the suspicious concurrent loading of amsi.dll and .NET runtime modules (clr.dll, mscoree.dll, or coreclr.dll) within the same process. This behavior is indicative of an attempt to hook into the AMSI interface to disable security scanning before executing malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the execution of rundll32.exe from a WebDAV network path ('@\DavWWWRoot\') where specific suspicious substrings (e.g., 'verification.google', 'pf.ch', 'moor', 'CfgInspectModuleData') are present in the command line. This pattern is commonly associated with the execution of remote payloads or malicious DLLs to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
102
Detects processes attempting to interact with the Anti-Malware Scan Interface (AMSI) via loading amsi.dll, calling functions such as AmsiScanBuffer or AmsiOpenSession, or modifying related registry keys. This behavior is highly indicative of attempts to disable or bypass AMSI protection, a common step in executing malicious scripts or payloads on Windows systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
This rule detects potentially malicious modifications to package.json files in npm projects or suspicious npm registry telemetry. It flags manifest files containing common obfuscation markers or excessive/unusual dependencies often associated with supply chain attacks, such as crypto, child_process, and common third-party packages frequently used in malicious npm activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
This rule detects command line patterns associated with common Impacket tools (wmiexec, psexec, smbexec) executed via Windows processes (cmd.exe, powershell.exe) or via network connections to ports 445 and 135 initiated by Python processes. These tools are frequently used by adversaries for lateral movement, remote service execution, and command execution on compromised systems.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
3018
Detects evidence of the PIVOTPIPE .NET loader attempting to disable AMSI scanning. The detection focuses on activity related to patching the 'AmsiScanBuffer' function within 'amsi.dll', specifically identifying the use of the hex signature '80070057' or direct references to the function name, which is an indicator of an AMSI bypass attempt performed to facilitate malicious code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the PIVOTPIPE loader extracting a 'sleepmask.o' Common Object File Format (COFF) file into a temporary directory prefixed with 'nb_'. This behavior is associated with the deployment of post-exploitation sleepmask functionality designed to obfuscate or encrypt beacon memory footprints to evade memory scanners.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the execution of PowerShell commands intended to gather system information, such as OS details, boot time, or video controller configurations. These techniques are often used during the discovery phase to profile a target machine before further malicious actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
202
Detects instances where a process attempts to delete its own executable file on disk. This behavior is often associated with malware or adversary tools attempting to remove their footprint post-execution or as part of a cleanup routine.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects instances where a Node.js process spawns another Node.js process as a child. This behavior is often associated with malicious npm packages attempting to evade detection during runtime execution or executing secondary malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the deletion of specific files associated with the indexed-btree malware loader, such as 'sharedLoad.min.js' or files within an 'extended/' directory. This behavior indicates potential anti-forensic cleanup following malicious code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects persistence attempts using Component Object Model (COM) hijacking by modifying HKCU CLSID InProcServer32 registry keys. The rule specifically identifies instances where the registry value points to a DLL file located within the user's AppData or LocalAppData directories, excluding typical system or program directories, as seen in sideloading persistence chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
102
Page 193 of 1871