Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects instances where PowerShell is launched with hidden window arguments by explorer.exe or mshta.exe, and the command line indicates interactions with specific file extensions (.vbs, .ps1) located within the AppData directory. This pattern is often indicative of malicious script execution, such as those used in Konni malware campaigns to drop and execute payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects the execution of LNK files that use a double extension (e.g., .pdf.lnk) to masquerade as PDF documents. This behavior is indicative of spear-phishing campaigns where malicious shortcuts are delivered via ZIP archives to execute hidden PowerShell commands for secondary stage downloader or persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects the exploitation of WinRAR CVE-2023-38831, where a maliciously crafted archive triggers WinRAR to execute a secondary payload (such as a script, LNK, or binary) from its temporary extraction directories (Rar$EXa, Rar$DIa, Rar$SR). This behavior is characteristic of adversaries using WinRAR as an initial access vector to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects the execution of VelvetCake modular scripts by PowerShell, which involves downloading and executing scripts from %TEMP% via Invoke-Expression, and monitoring the C:\Users\Public directory for file staging and subsequent exfiltration. This rule captures the tactical loop of script execution, output file creation, and exfiltration preparation often observed in Operation Conflict Compass activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects malicious PowerShell scripts that perform a sequence of reconnaissance activities, including security product enumeration via WMI (SecurityCenter2), system configuration discovery (ipconfig, systeminfo), process enumeration, recent file access, and drive mapping. This behavior is indicative of second-stage reconnaissance by threat actors to map the target environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects execution of PowerShell commands indicative of the VelvetCake variant of the Konni malware. The rule identifies the use of 'Net.WebClient.DownloadString' combined with 'Invoke-Expression' (iex) to execute scripts in memory, alongside specific command-line indicators such as the 'Areyou=cake' campaign marker or associated C2 domains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects instances where dllhost.exe (COM Surrogate) running under high-integrity accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) loads an unsigned DLL file located in the C:\ProgramData\ directory. This pattern is commonly associated with DLL side-loading or malicious library injection to maintain persistence or escalate privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
This rule detects suspicious PowerShell activity involving the enumeration and manipulation of COM objects and .NET assemblies, patterns often associated with reconnaissance or post-exploitation activities. It flags instances where PowerShell scripts utilize specific command-line arguments (e.g., Get-ComDatabase, Get-ComClass, Import-Win32Module, NtObjectManager) in conjunction, suggesting automated discovery of COM infrastructure or assembly loading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects the use of OleViewDotNet or NtObjectManager PowerShell tools to enumerate running COM host processes (e.g., dllhost.exe) and check for the absence of specific security mitigations like EOAC_NO_CUSTOM_MARSHAL or COMGLB_UNMARSHALING_POLICY_STRONG. This behavior is indicative of reconnaissance activity aimed at identifying targets for fake-marshaled CoGetInstanceFromIStorage exploit chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects a SYSTEM-level dllhost.exe process, associated with specific COM object instantiation (CLSID {135fd325-45b7-4c30-89f8-4386961669f0}), loading a DLL from the C:\ProgramData\ directory. This behavior is indicative of an attacker-planted DLL being unmarshaled through a crafted OBJREF, effectively bypassing security controls like EOAC_NO_CUSTOM_MARSHAL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects the presence of a specific Russian-language error string ("Не удалось сгенерировать HWID") within binary files, which is characteristic of the HWID generation mechanism used by Vidar Stealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects Vidar Infostealer variants by identifying its unique per-build polymorphic virtual machine bytecode interpreter and custom ARX stream cipher. The rule uses a combination of high file entropy, lack of standard OS cryptographic API imports, and the presence of structurally invariant indirect jump-table dispatch patterns used in custom VM execution loops.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects unauthenticated access attempts or requests originating from system/service accounts targeting the PaperCut NG/MF administrative interface, which may indicate exploitation of authentication bypass vulnerabilities (e.g., CVE-2026-81578).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
105
Detects instances where the PaperCut application server process (pc-app.exe) or its underlying Java processes (javaw.exe or java.exe) spawn command-line interpreters such as cmd.exe or powershell.exe. This behavior is indicative of potential post-exploitation activity, specifically Remote Code Execution (RCE) via vulnerabilities targeting PaperCut servers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
005
Detects the Microsoft Edge browser executable running from an anomalous path (C:\ProgramData\Microsoft\Windows\Telemetry\) or exhibiting suspicious network behavior (to a known malicious domain 'deadhub.org' or IP address '193.23.118.155'). This behavior is indicative of a masquerading attempt to hide malicious activity by mimicking a trusted browser binary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects instances where PowerShell is executed by a process masquerading as a common application (e.g., Telegram, WhatsApp, KeePass) to write a registry run key for persistence. This behavior is indicative of malicious installers or secondary stage delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
104
This rule detects potentially malicious activity where a Python-based process or a PyInstaller-compiled executable invokes a command shell (cmd.exe, powershell.exe) or command execution via 'os.popen', followed by a network connection to 'api.telegram.org' within a 60-second window. This behavior is often characteristic of malware or tools using Telegram's API as a command-and-control (C2) channel or for data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
104
This rule detects the invocation of the undocumented ntdll.dll function 'EtwpCreateEtwThread'. This API call can be abused by adversaries as an alternative to standard thread creation APIs (like CreateThread) to execute shellcode or malicious code in a suspicious process context, often as part of process injection techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects sophisticated shellcode execution patterns characteristic of MovieReaper, specifically monitoring for the combination of RWX memory protection allocation, manipulation of Vectored Exception Handlers (VEH), and usage of manual syscall stubs (NtProtectVirtualMemory) to bypass EDR user-mode API hooking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects execution of potential MovieReaper loader components by monitoring for the creation of a specific, statically defined global mutex or patterns indicative of dynamic mutex naming conventions often used to ensure single-instance execution by malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
104
Detects the use of PowerShell with the EncodedCommand parameter to modify or create entries in the HKEY_CURRENT_USER Run registry keys, a technique used by the HEAVYGRAM malware for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Page 204 of 1871