Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
001
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
001
Detects the malicious OIC_Invitation_General_Official.lnk sample used as the entrypoint for PlugX infection chain
avatar
Kaung Khant Ko@kaungkhantko
avatar
Hunters
21 days ago
003
Detects the malicious OIC_Invitation_General_Official.lnk sample used as the entrypoint for PlugX infection chain
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detection & Hunting Community
21 days ago
003
Detects the malicious OIC_Invitation_General_Official.lnk sample used as the entrypoint for PlugX infection chain
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
203
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
004
Detects the Stella_Gary .NET backdoor loader used by Kimsuky/APT-C-55, identified by managed-layer reflective assembly loading strings (loader.Program.Main, AssemblyResolve callback, Stella_Gary.Program.Main)
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
004
This rule detects known side-loaded PlugX RAT host processes ('GRrte.exe' or 'Jarte.exe') located in 'JartePortable' directories attempting to modify process tokens or privileges. This behavior is indicative of privilege escalation preparation, a common activity for the PlugX modular RAT.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
103
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
803
Detects execution of the PlugX side-loaded host process (Jarte.exe / GRrte.exe) from the JartePortable directory. This process performs in-memory host/system profiling (GetComputerNameW, GetVersionEx, system directory queries) via the decoded PlugX core (T1082), which is not directly visible as command-line telemetry.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
003
Detects the execution of known Jarte-derived host processes (GRrte.exe or Jarte.exe) which are commonly leveraged as side-loading proxies for the PlugX remote access trojan. The rule flags the process initiation as a proxy indicator for the subsequent execution of PlugX's modular payload, which performs system enumeration and process discovery.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
003
Detects the creation of a scheduled task configured to run under the SYSTEM account that executes a command to add a Windows Defender exclusion using Add-MpPreference. This technique is often used to ensure persistence of security exclusions by re-applying them automatically with high privileges, even if an interactive user attempts to remove them.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects instances where Adobe Acrobat (Acrobat.exe) is launched by an unusual or potentially obfuscated process (GRrte.exe), specifically when loading a PDF file from a temporary user directory. This pattern is indicative of potential malicious document execution where a PDF is used as a delivery mechanism for malware.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
203
Detects 32-bit Windows PE files packed with UPX that exhibit a zeroed compile timestamp, a characteristic often associated with staged SalatStealer or XenoRAT binaries observed in Operation CameraSwarm.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects the execution of processes containing 'OnvifUser' and command line arguments specifying '-u', which is consistent with the usage of ONVIF device discovery tools. ONVIF discovery protocols are used to identify network video transmitters. Unauthorized use of these tools can indicate reconnaissance activity within a network to identify cameras or video surveillance devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects various system events (including process execution and user account creation) that contain the specific string 'p2pwn' in combination with the string 'p2password'. This pattern suggests the activity involves potentially malicious credential testing, hardcoded credential usage, or suspicious account interaction activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
This rule detects two potentially malicious activities: the addition of exclusions to Windows Defender using reg.exe, which can be used to hide malicious files from security scanning, and the forceful update of Group Policy using gpupdate.exe with /force and /wait:0, which can be used to propagate malicious policy changes or force re-application of settings.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
Detects instances where the Windows command shell (cmd.exe) creates, modifies, or renames specific suspicious files ('My_Resume.pdf', 'Documents_Details.pdf') within the 'ProgramData' directory, often associated with execution of batch files or file copy operations that may indicate staging of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the unknown or suspicious process 'doxc' (or 'doxc.exe') executing common Windows system administration utilities ('wmic.exe', 'fsutil.exe', 'cmd.exe') or command-line arguments typically used for reconnaissance and system information discovery, such as listing logical disks or volume information.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the creation or modification of a file named 'uploaded_files.json' within a directory containing 'SmartUploader' under the user's AppData path. This pattern is often indicative of data staging or local file tracking activity by potentially malicious software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the use of PowerShell cmdlets and parameters to perform system, hardware, and external drive discovery. This includes querying volume information, disk/partition details, and checking for removable or specific bus-type media (USB, SD, MMC), which is commonly associated with reconnaissance activities by an adversary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Page 210 of 1871