Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
This rule detects a specific persistence technique used by AvisLoader malware. It monitors for the creation of a .lnk.backup file alongside a corresponding .lnk shortcut modification in common shell locations (Desktop, Taskbar, etc.), coupled with the execution of wscript.exe or cscript.exe referencing the 'VLCAssistant' VBScript within a short time window. This sequence indicates an attempt to persist malicious activity by backing up existing shortcuts and replacing them with a launcher for the AvisLoader payload.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects execution of auto.exe (associated with AvisLoader) combined with a specific registry-based UAC bypass technique using the ICMLuaUtil COM elevation moniker (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7). This pattern is characteristic of UACME method 41 to achieve privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects execution of shell commands (cmd, powershell) by processes associated with AvisLoader (e.g., 78324.exe, VLCAssistant.exe, auto.exe), followed by the creation or modification of files in suspicious user-writable directories (e.g., appdata, temp) within a 10-minute window, suggesting potential C2 activity and secondary payload staging.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
Matches known SHA-256 hashes of AvisLoader toolkit components recovered from an exposed staging server: the Windows loader client, UAC-bypass helper, and process-hiding DLL
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Matches known SHA-256 hashes of AvisLoader toolkit components recovered from an exposed staging server: the Windows loader client, UAC-bypass helper, and process-hiding DLL
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Matches known SHA-256 hashes of AvisLoader toolkit components recovered from an exposed staging server: the Windows loader client, UAC-bypass helper, and process-hiding DLL
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
Detects AvisLoader Windows loader requiring both decoy non-executable packer-named sections and an embedded c-toxcore developer build path to co-occur in a valid PE
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Page 201 of 1871