Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation of a suspicious file named 'FitnessMonitor.exe' within the Windows Startup folder. This technique is commonly used by remote access trojans (RATs) to ensure persistent execution upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the creation of files with the name 'README_KRSID.Txt', which is a hallmark behavior of the KRSID ransomware strain used to leave ransom notes on compromised systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the execution of command-line operations that involve the deletion of shortcut (.lnk) files or the self-deletion of batch scripts, often used by malware or malicious scripts to minimize their footprint and remove evidence after execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the creation of specific file paths and files associated with the PSNATCH file stealer tool, specifically monitoring for the presence of SmartUploader application directories and its associated upload index files. This behavior is indicative of an adversary staging collected data on a local system for subsequent exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects the presence of KRSID ransomware by identifying specific embedded strings associated with its configuration, including ransom notes (README_KRSID.Txt), log files (ransomware-silent.Log), encrypted file extensions (.krsid), and common command-line arguments used for operational control.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
003
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
103
Detects known malicious SilverFox trojan payloads by matching their SHA256 file hashes. This rule operates on file hashing metadata to identify specific binary artifacts associated with the SilverFox threat actor, regardless of the delivery mechanism or download source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects the execution of files related to 'UBPPatch' or 'HTSPnew', specifically looking for PowerShell scripts (.psh) or executables (.exe) that match these potentially non-standard or obfuscated update/patch filenames. The rule also looks for command lines referencing 'Update.Lst', often associated with custom or unauthorized patch mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
Detects modifications to Active Directory user accounts (Event IDs 4720, 4738) that coincide with suspicious MFA registration indicators—such as increased device counts, software token activations, or default device/token placeholders—within one hour of a successful user authentication event. This behavior is indicative of potential account takeover or persistence activities involving MFA manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects the execution of the KRSID ransomware binary, which is written in Rust. The rule identifies the malware based on its unique file extensions, ransom note filenames, specific command-line arguments, log file indicators, and compiled code characteristics.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects evidence of the RUSTYMOVE USB-propagation tool, associated with APT36 (Transparent Tribe). The rule identifies the creation of specific staged files (DriverInstaller.zip, DocScanner-11-Aug-2026-5-37pm.pdf.LNK) at the root of removable drives, as well as the creation of a 'log.txt' file on removable media that contains markers indicating successful file copying operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
002
Detects host-based network reconnaissance behaviors commonly associated with the threat group APT36 (Transparent Tribe). The rule identifies the execution of various built-in Windows network discovery commands including arp, nbtstat, net view/share/session, and automated ping sweeps or PowerShell-based subnet enumeration scripts, which are used to map reachable hosts and network shares.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
Detects individual file access events performed by non-browser python processes. This rule is designed as a proxy to identify automated file collection activities, such as those performed by 'python-httpx', that may be indicative of low-volume data exfiltration when aggregated over time.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
This rule detects the execution of 'DriverInstaller.exe' (either by filename or a known malicious SHA256 hash) that subsequently initiates network connections to GitHub domains. This behavior is indicative of potential malicious activity, such as downloading secondary payloads, command-and-control communication, or beaconing from a suspected rogue or masquerading driver installation utility.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
Detects the creation of scheduled tasks using either 'schtasks.exe' or 'powershell.exe' (Register-ScheduledTask) where the task name or configuration references common update or startup task patterns, or contains indicators of potential process hiding or encoded command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
Detects evidence of PSNATCH or BASHNATCH tools exfiltrating data to GitHub. The rule identifies suspicious file operations related to an 'SmartUploader' tracking file in standard user directories (AppData, .local/share), monitors for SmartUploader process execution, and flags network connections to api.github.com from processes identified as SmartUploader, bash, or PowerShell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
102
Detects the PUROSANGUE malware loader, which achieves execution by being sideloaded as 'vsdbg.dll' alongside a legitimate debugger executable. The detection leverages YARA rules focusing on specific artifacts such as a hardcoded build path, a custom Base16 alphabet, and a structural anomaly in the PE file's .reloc section compared to the declared base relocation directory size, alongside known malicious hash values.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the creation of specific staging files and directories associated with the Rapuncel infostealer (e.g., UserInformation.txt, installed_applications.txt, sends.log, browser_decryption.log, or the Filegraber directory) within Windows temporary storage paths. This activity typically occurs following the unauthorized collection of sensitive data such as credentials, digital wallet information, and messenger session data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the loading of the Alinubx.sys kernel driver or the creation of an NvFsFilter service, which are associated with a BYOVD (Bring Your Own Vulnerable Driver) attack leveraging a renamed CcProtect driver to bypass security protections such as PPL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
001
Page 212 of 1871