Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects process and file creation activity matching known MovieReaper loader and downstream module file hashes (MD5/SHA256). C2 IP/domain network indicators for this campaign require a separate network_connection-category rule, since Sigma logsource categories cannot be mixed within a single rule.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
104
Detects the execution of msiexec.exe to install an MSI package from a remote URL (http/https). The command line includes flags for passive installation (/passive) and an installation parameter (/i), initiated directly by Windows Explorer (explorer.exe), which is often associated with a user manually downloading and opening a malicious MSI file.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
Detects the creation of a scheduled task or registry manipulation involving the string 'psychedelicloveUtils' occurring within 30 minutes of the execution of the process 'psychedeliclove.exe'. This pattern is indicative of a persistence mechanism being established by potentially malicious software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
This rule detects the creation of specific suspicious files (e.g., host.ps1, host.bat) within browser native messaging host directories, followed by the termination of the associated web browser process. This pattern suggests an adversary attempting to establish persistence or manipulate browser functionality via native messaging components.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
Detects a process accessing browser credential files (Login Data) followed by an outbound network connection to a suspicious exfiltration endpoint commonly associated with credential-stealing malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
Detects the clearing of Windows event logs using native 'wevtutil.exe' or PowerShell cmdlets. The rule monitors for common log-clearing commands and triggers an alert when multiple such events occur on a single host within a 15-minute window, which is indicative of bulk log-wiping often performed by ransomware or during post-exploitation defense evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects User Account Control (UAC) bypass attempts where an adversary writes to specific registry keys under HKCU\Software\Classes to hijack COM handlers, followed shortly by the execution of auto-elevating Windows binaries like fodhelper.exe, computerdefaults.exe, or sdclt.exe. This activity facilitates silent privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects processes attempting to enumerate Active Directory objects (users, groups, trusts) while simultaneously establishing a network connection to Active Directory Web Services (ADWS) on port 9389. This behavior is characteristic of tools like SharpADWS, which performs AD enumeration via the ADWS protocol rather than traditional LDAP, potentially bypassing legacy detection mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects the creation of a remote service using 'sc.exe' where the executable was recently written to an administrative share (ADMIN$ or C$). This behavior often indicates lateral movement by threat actors deploying malicious binaries as services on remote systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects unauthorized modifications to Group Policy Objects (GPO) involving critical attributes (such as SYSVOL paths or extension configurations) combined with the creation of new script or executable files in the SYSVOL Scripts folder. This behavior is indicative of potential GPO tampering to gain persistence or facilitate large-scale execution, such as ransomware deployment via GPOs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects the execution of Microsoft-signed .NET utilities (RegSvcs, InstallUtil, MSBuild, CSC, VBC, ILAsm, AspNet_Compiler) when spawned by scripting engines like PowerShell, wscript, or cscript. This behavior is indicative of the Veil#Drop framework using trusted developer utilities as a fallback mechanism to execute secondary payloads or bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects instances where msiexec.exe, the Windows Installer utility, spawns cmd.exe to execute a batch file named 'xupdate.bat' located within the 'AppData\Roaming\Traiolx Custom Utils\' directory. This behavior is indicative of malicious persistence or execution mechanisms, often associated with loaders like LegionLoader that leverage installer binaries for evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the creation of temporary files with names starting with 'MSI' and ending in '.tmp' within the system's temporary directory. Legitimate installations typically perform these actions via the 'msiexec.exe' process; therefore, files created by other processes may indicate suspicious payload staging or activity by malware attempting to masquerade as MSI installer components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of a specific VBScript file 'Telegram_Private_Call_Session.vbs' via WScript, or its execution when spawned as a child process of MSHTA. This behavior is indicative of an HTA-dropped malicious script attempting to execute.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the suspicious initiation of Control Panel applet functionality via the COM object 'COpenControlPanel'. Adversaries may leverage this COM interface or the associated 'CPL_INIT' message to proxy malicious code execution through standard Windows processes like dllhost.exe or rundll32.exe, effectively bypassing security controls that might otherwise flag the direct execution of malicious .cpl files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of wmic.exe when launched by uncommon parent processes, specifically mshta.exe or wscript.exe. These parent processes are often associated with the execution of malicious scripts (e.g., .hta or .vbs files), which may use wmic.exe for system discovery or execution of commands, a common pattern in file-based living-off-the-land attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects modifications to the Windows Registry designed to disable PowerShell ScriptBlockLogging. This is a common defense evasion technique used by attackers to hide malicious PowerShell commands and scripts from security monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects evidence of PowerShell execution occurring within a GitLab CI runner environment that exhibits characteristics of command-and-control (C2) activity. This rule monitors PowerShell Script Block Logging (Event ID 4104) for indicators such as specific CI environment variables (e.g., CI_PIPELINE_SOURCE=api, GIT_STRATEGY=none), static job names associated with known exploitation patterns (e.g., CI_JOB_NAME=run_command), and the dynamic execution of commands using Invoke-Expression (IEX) on environmental variables.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the modification of the registry value 'EnableScriptBlockLogging' to '0' (Disabled) under the PowerShell policy path. This action suppresses the generation of Windows Event ID 4104 (PowerShell Script Block Logging), which is a critical source for monitoring attacker-issued PowerShell commands and detecting post-exploitation activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the creation of files with the .ent extension within the Microsoft Internet Explorer directory. This behavior is associated with the NarwhalRAT malware, which uses this specific file extension and location to store AES-encrypted configuration files, likely for persistence or subsequent execution by the malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the creation or execution of a scheduled task masquerading as a Microsoft Update process. The task is configured to execute potentially malicious components, specifically identified by filenames such as userscreen.exe, UserInerfacePicture, or config.cat. This behavior is indicative of persistence and execution of malicious payloads, as seen in campaigns involving the NarwhalRAT loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Page 214 of 1871