Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects execution of potentially malicious or dual-use tools (such as credential dumpers or security-bypass utilities) from within ScreenConnect temporary directories via the 'RunFile' command. This is indicative of an attacker leveraging legitimate remote support software to deploy secondary payloads.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects execution of potentially malicious or dual-use tools (such as credential dumpers or security-bypass utilities) from within ScreenConnect temporary directories via the 'RunFile' command. This is indicative of an attacker leveraging legitimate remote support software to deploy secondary payloads.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects execution of potentially malicious or dual-use tools (such as credential dumpers or security-bypass utilities) from within ScreenConnect temporary directories via the 'RunFile' command. This is indicative of an attacker leveraging legitimate remote support software to deploy secondary payloads.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects DNS queries and TLS SNI traffic directed at known actor-controlled domains and subdomains associated with ScreenConnect remote management software usage in malicious RMM chains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects DNS queries and TLS SNI traffic directed at known actor-controlled domains and subdomains associated with ScreenConnect remote management software usage in malicious RMM chains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects files matching known SHA256 hashes of the masqueraded MSP360 RMM v2.5.0.67 installer and associated ScreenConnect/utility payloads used in phishing-to-dual-RMM campaigns
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects files matching known SHA256 hashes of the masqueraded MSP360 RMM v2.5.0.67 installer and associated ScreenConnect/utility payloads used in phishing-to-dual-RMM campaigns
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects files matching known SHA256 hashes of the masqueraded MSP360 RMM v2.5.0.67 installer and associated ScreenConnect/utility payloads used in phishing-to-dual-RMM campaigns
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects instances where the Faronics Deploy Agent process initiates the installation or download of ScreenConnect remote access software via PowerShell or the Windows Installer (msiexec.exe). This pattern is often indicative of authorized RMM deployment, but it is also a common tactic for adversaries to establish persistent remote access to endpoints.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000