Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects instances where the Faronics Deploy Agent process initiates the installation or download of ScreenConnect remote access software via PowerShell or the Windows Installer (msiexec.exe). This pattern is often indicative of authorized RMM deployment, but it is also a common tactic for adversaries to establish persistent remote access to endpoints.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects instances where the Faronics Deploy Agent process initiates the installation or download of ScreenConnect remote access software via PowerShell or the Windows Installer (msiexec.exe). This pattern is often indicative of authorized RMM deployment, but it is also a common tactic for adversaries to establish persistent remote access to endpoints.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects a suspicious sequence of events where a process named RMM.Agent.exe executes a PowerShell command to download and install 'ClientSetup.msi' via msiexec.exe, followed closely by the execution of a ScreenConnect client process. This chain of activity is consistent with unauthorized or potentially malicious deployment of ScreenConnect (ConnectWise Control) for persistent remote access.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the execution of known browser credential harvesting tools (WebBrowserPassView, WebBrowserBookmarksView, or WS_Password variants) from ScreenConnect temporary directories. This behavior often indicates post-compromise activity where an adversary uses an existing Remote Monitoring and Management (RMM) session to extract credentials from browsers.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects the execution of known browser credential harvesting tools (WebBrowserPassView, WebBrowserBookmarksView, or WS_Password variants) from ScreenConnect temporary directories. This behavior often indicates post-compromise activity where an adversary uses an existing Remote Monitoring and Management (RMM) session to extract credentials from browsers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the execution of known browser credential harvesting tools (WebBrowserPassView, WebBrowserBookmarksView, or WS_Password variants) from ScreenConnect temporary directories. This behavior often indicates post-compromise activity where an adversary uses an existing Remote Monitoring and Management (RMM) session to extract credentials from browsers.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
001
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
001
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001