Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
001
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
001
This rule monitors for DNS queries and network connections to known infrastructure domains associated with the threat group UTA0565. It acts as an indicator of compromise (IOC) sweep to identify internal systems attempting to communicate with malicious command-and-control (C2) servers identified by typosquatting and registration-pattern analysis.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
001
This rule monitors for DNS queries and network connections to known infrastructure domains associated with the threat group UTA0565. It acts as an indicator of compromise (IOC) sweep to identify internal systems attempting to communicate with malicious command-and-control (C2) servers identified by typosquatting and registration-pattern analysis.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
101
Detects outbound network connections to specific IOCs associated with UTA0565 threat activity, including the use of an exploit-loader path (/config.html) on impersonated decoy sites.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
001
Detects potential Certificate Authority (CA) key theft by correlating command-line execution of certutil (with export flags) on a CA server with subsequent suspicious certificate issuance events. Suspicious issuance includes unauthorized certificate requests (missing event 4886), requests for high-privilege subjects (e.g., Domain Admins), or requests with unusually long validity periods.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
208
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
104
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
104
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
20 days ago
002
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
20 days ago
002
Detects the use of PowerShell's Start-Sleep cmdlet with a duration of 3 minutes or longer within process command lines. This technique is commonly used by malware, such as ClickFix-style droppers, to bypass sandbox time-based analysis by delaying execution until the sandbox timeout period has elapsed.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
20 days ago
002
Detects execution chains where explorer.exe (acting as the Run dialog host) spawns suspicious processes like mshta.exe, powershell.exe, or cmd.exe with command lines containing URL indicators (http), common payload filenames (rtdx.dat), or specific IP address strings associated with known ClickFix social-engineering campaigns.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
20 days ago
002
Detects the execution of mshta.exe with a command line involving remote HTTP connections or suspicious file extensions (.dat), which are often used by adversaries to proxy the execution of malicious scripts or HTA files.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
20 days ago
102
Detects the execution of mshta.exe with a command line involving remote HTTP connections or suspicious file extensions (.dat), which are often used by adversaries to proxy the execution of malicious scripts or HTA files.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
20 days ago
002
Detects the creation of a process in a suspended state using the CREATE_SUSPENDED flag. This technique is commonly employed during process hollowing, process injection, or by legitimate security/debugging tools to prepare a process for memory modification before execution begins.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
102
This rule detects processes accessing or modifying Microsoft Outlook data files (.pst or .ost), which may indicate an attempt to collect, stage, or export sensitive email data from a local system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
102
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
104
IOC hunt for the HEAVYGRAM/CRUDEEXCLUDE campaign: matches known SHA256 file hashes (first-stage malware, implant, RAR/ZIP artefacts) via DeviceFileEvents and DeviceProcessEvents, plus known-malicious domains/staging infrastructure by parsed hostname across network connections, process command lines, and file origin URLs.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
004
This rule detects devices that have both accessed a specific suspicious external domain ('thefatshallot.com') and performed file operations involving HTML files or files containing 'chromecache' in their name within the same 24-hour period. This behavior pattern suggests a potential download of malicious web content or drive-by-download attempt where browser cache files are utilized for file staging or persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
002
Detects the use of PowerShell's Start-Sleep cmdlet with a duration of 3 minutes or longer within process command lines. This technique is commonly used by malware, such as ClickFix-style droppers, to bypass sandbox time-based analysis by delaying execution until the sandbox timeout period has elapsed.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
002
Detects instances where a browser process (Chrome, Edge, Firefox, or IE) programmatically writes content to the system clipboard using JavaScript commands. This pattern is commonly observed in 'ClickFix' style social engineering attacks, where a user is coerced into copying and executing a malicious command script provided by an attacker, often in the context of resolving a fake system error.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
20 days ago
102
Page 206 of 1871