Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution or presence of AnyDesk.exe within directories containing 'UBP-Asset' that are outside of known, legitimate installation paths. This behavior often indicates an adversary attempting to use remote access software for persistent access or command and control, commonly disguised within unconventional directories.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
102
Detects anomalous GitLab CI pipeline execution that matches patterns associated with GitRunner C2 abuse. The detection identifies pipelines triggered via API (CI_PIPELINE_SOURCE=api) with cloning disabled (GIT_STRATEGY=none) and a specific static job name (run_command), which can indicate the CI runner is being abused as a command-and-control channel for arbitrary script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects cmd.exe processes utilizing variable assignment and dynamic substring expansion to reconstruct and execute obfuscated PowerShell commands, a technique frequently observed in malicious LNK file decoy campaigns to evade static signature detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects execution of xcopy with specific flags intended to perform recursive copying of files, including hidden and system files, into a staging directory located within C:\Users\Public\. This behavior matches the known exfiltration collection routine of the NarwhalRAT malware, often invoked by processes such as python.exe or userscreen.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of 'userscreen.exe' (a renamed pythonw.exe used by NarwhalRAT) loading 'user32.dll'. This behavior is associated with the use of ctypes in Python to perform window enumeration via EnumWindows, specifically used by the malware to identify and monitor KakaoTalk application windows.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the creation of an NTFS Alternate Data Stream named ':changelist' on files with a .sys extension. This activity is indicative of potential malicious configuration staging or persistent storage, as seen in techniques involving BTR.sys or similar driver-based persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
201
This rule detects the deletion of critical Windows Defender security files (such as drivers and executables) by the System process. This behavior is highly indicative of an attempt to tamper with or disable security features on a host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
101
Detects AutoIT executables running from a Temp directory that take an .ini file as a command-line argument. This pattern is commonly used by AutoIT-based malware loaders or droppers to ingest configuration files containing obfuscated code or C2 communication parameters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects a classic process injection technique where an external process attempts to gain high-level access (OpenProcess with 0x1F0FFF) to charmap.exe. This activity is often a precursor to further injection steps such as VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread, a behavior consistent with malicious payloads like AsyncRAT executed via an abused AutoIT interpreter.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
002
Detects a potential destructive activity pattern involving the staging of a payload in a non-standard directory (utilizing a directory name with a trailing space) followed by a burst of file deletions on the same device. This behavior is indicative of a secondary destructive payload execution, often associated with disk-wiping malware.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
101
Detects a suspicious sequence of activity involving persistence via Registry Run keys (specifically targeting SMQDService or winappx entries) followed by modifications to Microsoft Defender configuration (adding exclusions via PowerShell) within a two-hour window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
101
Detects the execution of an installer file (.exe, .msi, .scr) located in common download or temporary directories that masquerades as a legitimate application (e.g., KeePass, Adobe Flash) or a medical document. The rule specifically identifies this behavior when it occurs within an hour of activity involving messaging applications like WhatsApp or Telegram, which is a known tactic in the 'CHOSEN BRICK' social engineering delivery chain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
001
This rule detects potential command and control (C2) activity where a non-browser or non-Telegram application initiates network connections to the Telegram Bot API within 24 hours of a new entry being created in the Windows Registry Run key. This combination suggests a persistence mechanism combined with a C2 channel.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
101
Detects the execution of processes named 'UpdateAssistant.exe', 'AppUpdateHelper.exe', or 'SysMaintenance.exe' from specific common application directories that are either unsigned or lack a valid Microsoft digital signature. This pattern is commonly used by adversaries to masquerade malicious binaries as legitimate system update components to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects network traffic to the Telegram Bot API originating from processes other than the official Telegram desktop client. The rule correlates this network activity with the presence of specific suspicious or renamed processes (e.g., SMQDService, winappx.exe) associated with the CHOSEN BRICK campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
001
Detects execution of mass file-deletion or system wipe commands triggered by processes running from known persistence or staging locations associated with the CHOSEN BRICK campaign. The rule monitors for the combination of suspicious process paths (such as disguised winappx.exe or SysWOW64-lookalike directories) and destructive command-line arguments like 'del', 'cipher', 'format', or 'vssadmin' operations.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
101
Detects unauthorized processes attempting to read or manipulate local storage, session storage, or database files associated with messaging applications like Telegram and WhatsApp, or email clients like Outlook and Thunderbird. This behavior is indicative of credential or data theft by malicious software or unauthorized scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
101
Detects the use of the WinGet 'configure' command to process PowerShell DSC configuration files. This method can be abused to execute arbitrary PowerShell code within a Script resource without explicitly invoking powershell.exe, potentially bypassing certain monitoring or security controls focused solely on the PowerShell executable.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the creation of scheduled tasks initiated by the WinGet DSC configuration processes, specifically ConfigurationRemotingServer.exe or WindowsPackageManagerServer.exe. This activity is indicative of the abuse of the 'ScheduledTask' resource within a WinGet configuration file to establish persistence via a logon-triggered task.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects unauthorized or suspicious persistence attempts where Windows Package Manager (WinGet) configuration processes (ConfigurationRemotingServer.exe or WindowsPackageManagerServer.exe) write to the Windows 'Run' registry keys in HKLM. This behavior can be abused to execute malicious code automatically at system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Page 215 of 1871