Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the use of PowerShell cmdlets and parameters to perform system, hardware, and external drive discovery. This includes querying volume information, disk/partition details, and checking for removable or specific bus-type media (USB, SD, MMC), which is commonly associated with reconnaissance activities by an adversary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects instances where PowerShell is executed with encoded commands, seemingly spawned by a process masquerading as or related to the Microsoft Edge Update Task. The rule specifically monitors for process chains involving 'conhost.exe' with '--headless' arguments and subsequent PowerShell execution containing encoded commands, often associated with obfuscated activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects the execution of cmd.exe or powershell.exe where the command line arguments involve the deletion or renaming of specific file names potentially associated with unauthorized activities or malware components. It looks for common command-line utilities (del, ren) being used by command shells on specific files that may indicate artifact cleanup or staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects PowerShell processes attempting to download specific ZIP files (e.g., DriverInstaller.zip, Automata-20.zip, ww.zip) from Backblaze B2 cloud storage buckets. This pattern is commonly associated with the delivery of malicious payloads or staged tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the creation or modification of a file named 'uploaded_files.json' within a directory containing 'SmartUploader' under the user's AppData path. This pattern is often indicative of data staging or local file tracking activity by potentially malicious software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects the execution of cmd.exe or powershell.exe where the command line arguments involve the deletion or renaming of specific file names potentially associated with unauthorized activities or malware components. It looks for common command-line utilities (del, ren) being used by command shells on specific files that may indicate artifact cleanup or staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects common Windows command-line utilities used for internal network reconnaissance, including ARP cache queries, NetBIOS enumeration, SMB share/session discovery, and subnet ping sweeps. These techniques are frequently employed by adversaries for lateral movement preparation and internal network mapping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule monitors network HTTP traffic containing specific strings related to gym-membership APIs and client IDs, alongside process or file activity referencing 'getFitnessProfile'. This combination is a behavioral fingerprint associated with a specific Golang-based remote access trojan (RAT) attempting to exfiltrate or interact with fitness profile data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the use of PowerShell to enumerate storage devices (USB, disk, partition information) and perform file operations such as copying or logging, potentially indicating malicious data collection from removable media or external drives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects execution of command lines containing suspicious, potentially obfuscated substrings that do not correspond to standard Windows utilities. The use of custom delimiters like 'ASISFH' within common command strings suggests an attempt to bypass signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the creation of files within the 'AppData\Local\SystemFolder32' directory. This path is non-standard and is frequently used by malware or unauthorized scripts to conceal malicious payloads or persistence mechanisms while masquerading as legitimate system components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
602
Detects a scenario where a process (cmd.exe) executing a file named 'config.bat' subsequently launches another instance of cmd.exe to delete files with a '.lnk' extension. This behavior is indicative of cleanup activities after potential malicious script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects unauthorized persistence attempts by monitoring processes (reg.exe or powershell.exe) modifying the Windows 'CurrentVersion\Run' registry key to execute an application named 'DailyFitnessTracker' upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects the execution of processes identified as 'DriverInstaller.exe' or files with known malicious SHA256 hashes associated with suspicious driver installation activity. The rule excludes legitimate system processes like msiexec.exe and trustedinstaller.exe, which are typically responsible for authorized software and driver installations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the execution of PowerShell with encoded commands in headless mode, associated with the Microsoft Edge Update Task (MicrosoftEdgeUpdateTaskUserS-1-5-24). This pattern is indicative of potential malicious activity where legitimate update tasks are abused to run obfuscated scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
Detects the use of PowerShell commands (Get-Volume, Get-Partition, Get-Disk) to identify and inspect information about connected removable storage media such as USB, IEEE 1394, SD, or MMC devices. This behavior is indicative of an adversary enumerating potential targets for data staging or exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the use of the Windows 'net.exe' utility to establish an IPC$ null session or an authenticated connection to the IPC$ share. These techniques are often used by attackers to perform remote service discovery, interact with remote shares, or facilitate lateral movement within a network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects instances where the process 'UBPUpdater.Exe' spawns a process or command line utilizing 'UBPPatch.Psh'. The rule highlights that 'UBPPatch.Psh' is masquerading as a non-executable PowerShell script while likely operating as a malicious binary or PowerShell executable.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the suspected RUSTYMOVE activity by identifying the creation of specific malicious files (ZIP and LNK) on the root directory of removable drives, followed by reconnaissance commands targeting removable media volumes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects PowerShell script execution that interacts with the GitHub API, specifically targeting the upload of files or JSON data to repository endpoints. The logic looks for commands related to file system access, inclusion of 'api.github.com', and references to 'SmartUploader' or 'uploaded_files.json'. It further filters for activity occurring within standard user directories and enforces a check to ensure the GitHub repository name matches the local hostname, which is a common indicator of automated exfiltration scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
This rule detects potential lateral movement activity involving the use of the 'net use' command to connect to remote IPC$ shares or administrative tools like 'Test-NetConnection' to probe for SMB and RPC ports (445/135). Such techniques are often used by threat actors like APT36 to verify network connectivity and establish authenticated sessions for lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Page 211 of 1871