Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects execution of PowerShell scripts attempting to modify Windows Defender settings by adding directory exclusions (including the C:\ drive) via cmdlets like Add-MpPreference, Set-MpPreference, or WMI/CIM methods, often followed by a forced Group Policy refresh. This pattern is associated with malicious staging activity, including malware loaders like LausivLoader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
22 days ago
104
Detects PNG image files containing an 'iTXt' metadata chunk and a specific byte marker (FF 89 AD 4A). This signature is characteristic of LausivLoader, which hides an encrypted payload within the image using steganographic techniques, intended for subsequent extraction via XOR decryption and DEFLATE decompression.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the execution of DahuaConsole processes that are spawned by or associated with the scannerdahua utility. This pattern is often associated with discovery or exploitation activities targeting Dahua devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
This rule detects suspicious activity related to specific hardcoded indicators 'p2pwn', 'p2password', and references to 'cve-2024-39943'. It scans authentication logs (Identity) and EDR logs (process command lines) for these terms, flagging potential unauthorized access, credential use, or exploitation attempts associated with this specific threat activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the creation or execution of scheduled tasks named 'MicrosoftEdgeUpdateTaskCore' that exhibit suspicious behaviors, specifically those marked as hidden, tasks utilizing a LogonTrigger, or tasks executing wscript.exe with specific command-line arguments (e.g., //B, //Nologo) often associated with malicious script execution patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects attempts by a process (specifically targeting PowerShell or .NET loaders) to tamper with Windows Antimalware Scan Interface (AMSI) components in memory. It correlates EDR or Sysmon events (process access, module loads) targeting 'amsi.dll' or involving specific AMSI API strings like 'AmsiScanBuffer' or 'AmsiInitFailed' with potential malicious loader activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
This rule detects the creation of XML files matching the 'export_batch_*.xml' naming convention, which is consistent with the output pattern of the Dahua DeviceManager utility. Attackers often use this tool to export camera configuration files containing sensitive credentials (IP, Port, Username, Password). The rule flags activity where multiple such files are created in a short duration, suggesting potential mass exfiltration of camera credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects a suspicious execution chain where WScript.exe initiates a process with '--headless' arguments, which in turn spawns a PowerShell process with hidden, encoded, and non-interactive command line flags. This pattern is commonly used by adversaries to execute malicious scripts while attempting to evade detection and user interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects PowerShell script blocks that exhibit multiple indicators of obfuscation and in-memory execution. It identifies the combination of AES encryption, embedded key bytes commonly associated with deobfuscation routines, GZip compression, and reflective assembly loading (Assembly.Load). The use of multiple techniques simultaneously significantly increases the likelihood of malicious activity, such as fileless malware loading or execution of obfuscated payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects attempts to modify Windows Defender security settings by adding exclusions to the scan path using various PowerShell cmdlets or WMI methods. This behavior is often associated with adversaries attempting to evade detection by excluding malicious tools or directories from antivirus scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the execution of JavaScript files using wscript.exe from user-writable directories (e.g., Temp, Downloads, AppData) that exhibit high levels of obfuscation. The rule specifically flags scripts containing a high ratio of comment lines to code, a technique often used in the LausivLoader malware family to mask malicious payloads constructed using String.fromCharCode.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the addition of a file path exclusion to Windows Defender via the command-line registry utility (reg.exe), followed immediately by the execution of gpupdate to force a policy refresh. This pattern is commonly used by adversaries to exclude malicious directories from security scanning and ensure the configuration change takes immediate effect.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects attempts to patch ETW (Event Tracing for Windows) functions such as EtwEventWrite within the memory space of PowerShell or PWSH processes. This is a common technique used by attackers to suppress telemetry and evade security monitoring tools, often associated with bypassing AMSI/ETW logging mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects attempts to patch ETW (Event Tracing for Windows) functions such as EtwEventWrite within the memory space of PowerShell or PWSH processes. This is a common technique used by attackers to suppress telemetry and evade security monitoring tools, often associated with bypassing AMSI/ETW logging mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects attempts to disable Windows Defender Tamper Protection via direct Registry modification or by executing PowerShell commands. Disabling Tamper Protection is a common tactic used by adversaries to facilitate further malicious activity, such as impairing security controls or deleting malware artifacts without interference from Windows Defender.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the creation of a JavaScript file masquerading as a legitimate Microsoft PhotoEngine component ('PhotoStudio.js') within the '%LOCALAPPDATA%' directory. This behavior is associated with the LausivLoader malware, which uses this masquerading technique to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects the LausivLoader initial-stage obfuscated JavaScript dropper. It identifies the malware either by specific file hashes (MD5/SHA256) or by detecting characteristic behaviors: small file size (<1MB), the presence of 'String.fromCharCode' obfuscation techniques, excessive junk comments, and supply-chain related lure strings.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects the creation or registration of scheduled tasks using common scripting engines (PowerShell, WScript, CScript) or specific task name patterns (MicrosoftEdgeUpdateTaskCore, PhotoStudio.js) often associated with malicious persistence or execution. It monitors command lines for flags such as /create, /sc onlogon, or /ru system that suggest non-standard or unauthorized task creation patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
202
Detects the presence of known Vidar infostealer samples by matching file hashes against a list of identified malicious artifacts. The rule monitors for file creation events, process execution (both as the primary process and as an initiating process), and network activity originating from these known malicious files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
101
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detection & Hunting Community
21 days ago
103
Page 209 of 1871