Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects access to sensitive browser credential storage files (Login Data, key4.db, logins.json) by unauthorized processes. This behavior is indicative of credential theft, where an adversary attempts to extract stored passwords from browser profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
Detects instances where the Firefox browser process executes from a path containing 'ProgramData' and creates a new file within the 'ProgramData' directory. This behavior is highly suspicious as legitimate Firefox installations reside in 'Program Files' or 'Program Files (x86)', and 'ProgramData' is often abused by malware for persistent storage or staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
105
Detects instances where PowerShell is executed with a command line string containing 'Google Chrome Update' and initiates a network connection. This behavior is indicative of a malicious process masquerading as a legitimate browser update mechanism to hide network activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
Detects the loading of .NET Common Language Runtime (clr.dll) and System.Management.Automation.dll into a process that is not a recognized PowerShell binary (e.g., powershell.exe, pwsh.exe). This behavior is associated with the 'PSInline' technique used by SloppyRAT, where PowerShell capabilities are invoked directly via COM objects to execute commands in memory. The rule further correlates this activity with the creation of files with a .png extension in temporary directories, which is consistent with the exfiltration staging behavior of the malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
003
Detects the creation of scheduled tasks that masquerade as a 'Google Chrome Update' task but are initiated by suspicious processes like cmd.exe, powershell.exe, or schtasks.exe, and do not originate from the legitimate Google Chrome installation directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
This rule detects potential PowerShell script execution without spawning the standard powershell.exe process. It monitors for the loading of clr.dll and System.Management.Automation.dll into any process other than powershell.exe, which is a technique used by some malware families like SloppyRAT to execute PowerShell code directly within a compromised process memory space.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
003
Detects the creation of a file on the system that matches a known malicious SHA256 hash.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
003
This rule detects the creation, modification, or renaming of files that contain sensitive keywords (e.g., 'password', 'seed', 'wallet', 'recovery') by processes other than standard system or productivity applications. This activity is indicative of credential or sensitive data harvesting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
003
Detects instances where a process that is not a known PowerShell host (powershell.exe, pwsh.exe, powershell_ise.exe) loads the System.Management.Automation.dll assembly, which is a strong indicator of an attempt to execute PowerShell code within a different process to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
003
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
4012
This rule monitors process creation events for common command-line obfuscation patterns used to evade detection. It flags suspicious usage of encoding (e.g., base64), character manipulation (e.g., caret char insertion, case randomization), and scripting-related concatenation or dynamic reassembly techniques within cmd, powershell, or script host commands.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
26 days ago
7014
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
000
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
000
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
000
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
000
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
000
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
000
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
000
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
000
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
000
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
000
Page 198 of 1871