Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
Matches known SHA-256 hashes of AvisLoader toolkit components recovered from an exposed staging server: the Windows loader client, UAC-bypass helper, and process-hiding DLL
Matches known SHA-256 hashes of AvisLoader toolkit components recovered from an exposed staging server: the Windows loader client, UAC-bypass helper, and process-hiding DLL
Matches known SHA-256 hashes of AvisLoader toolkit components recovered from an exposed staging server: the Windows loader client, UAC-bypass helper, and process-hiding DLL
Detects AvisLoader Windows loader requiring both decoy non-executable packer-named sections and an embedded c-toxcore developer build path to co-occur in a valid PE
Page 201 of 1871
