Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Monitors network connections initiated by the Logitech Options Plus agent process (logioptionsplus_agent.exe) on a specified host. This rule facilitates tracking of outbound communications generated by this background service.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
23 days ago
006
Detects evidence of a SharePoint pre-authentication RCE exploit chain where an adversary injects a malicious Namespace containing an ExpandedWrapper-wrapped XamlServices payload (e.g., ObjectDataProvider or LosFormatter gadget) into the w3wp.exe worker process. This specifically looks for command-line arguments indicative of deserialization-based exploit attempts targeting SharePoint web server components.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
001
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
001
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
101
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
101
Detects PowerShell processes using the .NET System.IO.File methods (SetLastWriteTime, SetCreationTime, SetLastAccessTime) to modify file timestamps, a common anti-forensic technique to obfuscate file creation or modification times.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
101
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
001
Detects the use of csc.exe (C# compiler) launched from PowerShell with hidden or bypass flags, as well as the subsequent execution of cvtres.exe. This activity is commonly associated with fileless malware techniques where helper classes or payloads are compiled and executed in-memory at runtime to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
101
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
001
Detects the creation of a scheduled task via schtasks.exe initiated by wscript.exe or cscript.exe where the task configuration or execution occurs within common user-writable directories (e.g., AppData, Temp, Downloads). The rule specifically flags behavior involving multiple task invocations in a short time frame, which is indicative of persistence mechanisms used by scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
101
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
005
Detects the execution of PowerShell or Windows Script Host (wscript/cscript) spawned by explorer.exe that utilize hidden window styles and target suspicious filenames or external paths, often indicative of a dropper or malicious script stage.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
101
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
101
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
001
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
101
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
001
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
001
This rule identifies developer or contractor workstations that have Node.js/npm installed but currently lack active EDR sensor coverage (i.e., the sensor is either not onboarded or not in an active state). It employs a 24-hour grace period to filter out transient onboarding issues and ensures that the device has reported activity within the last 7 days to avoid alerting on decommissioned hardware. This gap in visibility increases the risk of undetected supply-chain malware execution and credential theft on sensitive developer endpoints.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
003
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
001
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
Defender - KQL
18 days ago
201
Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
001
Page 205 of 1871