Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Page 199 of 1871