Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation of scheduled tasks initiated by the WinGet DSC configuration processes, specifically ConfigurationRemotingServer.exe or WindowsPackageManagerServer.exe. This activity is indicative of the abuse of the 'ScheduledTask' resource within a WinGet configuration file to establish persistence via a logon-triggered task.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects unauthorized or suspicious persistence attempts where Windows Package Manager (WinGet) configuration processes (ConfigurationRemotingServer.exe or WindowsPackageManagerServer.exe) write to the Windows 'Run' registry keys in HKLM. This behavior can be abused to execute malicious code automatically at system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects instances where cmd.exe spawns a PowerShell process with the '-executionpolicy bypass' argument. This pattern is commonly used by attackers to execute malicious scripts while circumventing Windows PowerShell execution policy restrictions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of the Python interpreter (pythonw.exe) renamed to 'codeflush.exe' residing in non-standard paths like '\Public\Music\MusicLibrariesPackage\'. This behavior is characteristic of adversaries attempting to camouflage malicious Python scripts or binaries as legitimate files to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects execution of cmd.exe with suspicious command-line patterns utilizing environment variable substring expansion (%VAR:~offset,length%). This technique is used to dynamically reconstruct and execute obfuscated commands, a method historically observed in APT37 delivery chains to hide malicious payloads and bypass simple string-based signatures.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the download and subsequent extraction of the Python embeddable zip package to directories under 'C:\Users\Public'. This activity is consistent with techniques used by threat actors, such as APT37, to establish a covert Python runtime environment on a compromised host for further malicious operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of cmd.exe spawned by explorer.exe that contains suspicious command line parameters. The rule specifically targets the use of obfuscated Windows batch substring expansion (e.g., %VAR:~0,1%) or commands being executed directly from common user-writable directories like Temp or Downloads, which are common indicators of malicious LNK file abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects outbound TCP traffic containing system reconnaissance data, such as OS information, computer name, and location, being sent to a known C2 server address. The rule monitors for specific content patterns indicative of an infected host checking in or exfiltrating host configuration details.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the creation of a mutex with the 'Global\evolution' prefix, which is a known indicator of the XMRig cryptocurrency miner execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects instances of MSBuild.exe executing from within the Microsoft.NET framework directory while initiating outbound network connections to a specific known command-and-control (C2) IP address associated with rmrlx infrastructure, or standalone network activity matching these parameters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the use of Windows command shell variable substring expansion to obfuscate commands. Adversaries use this technique to build malicious command lines dynamically, making them less visible to standard keyword-based detection mechanisms by storing parts of strings in environment variables and reassembling them using substring notation (e.g., %var:~start,length%).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects instances of MSBuild.exe executing from within the Microsoft.NET framework directory while initiating outbound network connections to a specific known command-and-control (C2) IP address associated with rmrlx infrastructure, or standalone network activity matching these parameters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the use of Windows command shell variable substring expansion to obfuscate commands. Adversaries use this technique to build malicious command lines dynamically, making them less visible to standard keyword-based detection mechanisms by storing parts of strings in environment variables and reassembling them using substring notation (e.g., %var:~start,length%).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the use of Windows command shell variable substring expansion to obfuscate commands. Adversaries use this technique to build malicious command lines dynamically, making them less visible to standard keyword-based detection mechanisms by storing parts of strings in environment variables and reassembling them using substring notation (e.g., %var:~start,length%).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
101
Detects instances where curl.exe is spawned by cmd.exe or wscript.exe and uses the -o flag to save downloaded files into user-writable directories (e.g., Temp or AppData), a technique often used to stage secondary payloads during the exploitation process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of Python interpreters from non-standard, user-writable directories (such as Public\Music) or using suspicious filenames. This behavior is indicative of threat actors abusing the Python Embeddable package to run disguised Python backdoors, such as the Chinotto malware family observed in APT37 operations, often staged via batch scripts or curl.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
101
Detects the execution of batch files from temporary directories that employ command obfuscation techniques such as environment variable substring expansion, or which execute with a hidden window in conjunction with chained system utilities commonly associated with malicious activities (e.g., curl, tar, schtasks). This behavior is often indicative of staged payload delivery and execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of batch files from temporary directories that employ command obfuscation techniques such as environment variable substring expansion, or which execute with a hidden window in conjunction with chained system utilities commonly associated with malicious activities (e.g., curl, tar, schtasks). This behavior is often indicative of staged payload delivery and execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects malicious file system activity where the legitimate Python interpreter (python.exe) is deleted and replaced or renamed to a deceptive filename (codeflush.exe) within the 'C:\Users\Public\Music\MusicLibrariesPackage' directory. This technique is used by threat actors, including APT37, to mask the execution of Python-based backdoors and evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
101
Detects HTTP POST requests to a known suspicious endpoint ('/board.php') often used by the Chinotto Python backdoor. The rule monitors for outgoing web traffic containing 'data=' parameters or connections to known malicious domains, indicating potential exfiltration of base64-encoded command output.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of the Pester framework's Build.bat script, which is being abused as a LOLBAS (Living Off the Land Binary and Script) technique. This activity is typically characterized by being launched from an LNK file, often indicating a malicious dropper or secondary stage payload delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Page 216 of 1871