Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects unauthorized access to VPN configuration files associated with common VPN providers (CyberGhost, NordVPN, ExpressVPN). This behavior is characteristic of the Hannibal Stealer, which attempts to exfiltrate these files to compromise user VPN sessions and credentials. The rule filters out legitimate process access to minimize false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects suspicious process command lines that access sensitive cryptocurrency wallet data files or registry keys associated with wallet applications, which is a common behavior of information-stealing malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the execution of a renamed DISM binary (index.exe) that subsequently loads a specific DLL (DismCore.dll), which is a common technique used for DLL side-loading to evade security controls by masquerading as a legitimate system utility.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
101
Detects the creation of a shortcut (LNK) file within the Windows Startup directory that points to a msedge.exe binary located in a non-standard, masqueraded location within the user's Local AppData path. This behavior is associated with the LucidPawn/LucidRook persistence mechanism.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
101
Detects process execution events where a process is launched with command line arguments containing 's' as an isolated character (often indicative of token stealing tools like Incognito or similar utilities) combined with a discrepancy in the initiating process account or logon session, suggesting potential token duplication or impersonation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects execution of common administrative and potentially malicious processes originating from the Microsoft Exchange Server worker process (w3wp.exe). This pattern is indicative of a web shell or post-exploitation activity where an attacker has achieved code execution on an Exchange server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects processes repeatedly loading GDI/display libraries (gdi32.dll, gdi32full.dll, user32.dll) at a sustained cadence indicative of automated screen capturing. The rule excludes common collaboration and remote access tools known to perform these functions legitimately, flagging high-frequency, long-duration activity consistent with malicious screen scraping techniques.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects process injection and hook evasion attempts where a thread is created or modified with a start address that does not resolve to a known, legitimate memory module. This pattern is indicative of shellcode execution or reflective DLL injection where the malicious code resides in anonymous or unbacked memory regions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects a variant of the ClickFix technique where an attacker directs a user to open an administrative PowerShell or Command Prompt instance via the Windows+X power user menu through Windows Terminal. This execution chain, involving WindowsTerminal.exe, OpenConsole.exe, and a shell binary, bypasses traditional RunMRU registry artifacts often associated with the standard Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects instances where wscript.exe spawns powershell.exe with command-line arguments indicative of stealth or obfuscation, such as hidden windows or encoded commands. This behavior is frequently associated with malicious script execution lures, such as JavaScript-based droppers or ClickFix-style campaigns that use PowerShell to stage and execute in-memory payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects PowerShell command lines that simultaneously utilize .NET cryptography classes (TripleDES or AES) for decryption and runspace pipeline creation. This pattern indicates an in-memory execution technique where malicious payloads are decoded and executed directly within the PowerShell process, effectively bypassing disk-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the presence of PureLogs Stealer, a .NET-based information stealer, by identifying specific family name strings embedded within PE files that conform to the .NET assembly structure. This rule targets the static analysis of malicious binaries often used in credential harvesting campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects malicious PowerShell command chains often used in ClickFix campaigns. These commands typically move zip files from the user's Downloads directory to a temporary folder, extract them using the tar utility, and execute an embedded PowerShell script using conhost in headless mode. This technique is designed to bypass AMSI command-line inspection by offloading the actual payload execution to an extracted, unmonitored script.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects PowerShell scripts attempting to evade detection through programmatic runtime creation using Runspaces (RunspaceFactory, CreatePipeline, AddScript) combined with cryptographic operations or dynamic string substitution techniques. This behavior is often associated with obfuscated malware payloads attempting to execute code in memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the use of PowerShell string concatenation to construct the malicious C2 domain 'merabs.pro'. This technique is used to bypass simple string-based detections that look for the full domain name in command-line arguments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
Detects the ClickFix social-engineering technique where an adversary tricks a user into pasting and executing a malicious command via Windows Explorer (Run dialog) or Windows Terminal. This pattern is often used in fake CAPTCHA or job-interview lures to achieve initial code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
001
This rule detects the execution of known Remote Monitoring and Management (RMM) tools across the environment. RMM tools are frequently used by IT administrators for legitimate support, but are also commonly abused by threat actors to establish persistence and gain remote access to systems. The rule tracks the first instance of these processes appearing on any device within a 30-day window.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
26 days ago
14012
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
104
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
104
Detects known malicious files associated with Kimsuky (APT-C-55) Stella_Gary attack chain by MD5 hash: OrionQuests-Setup.exe installer, guide.url.lnk, test.bef_fri, and backdoor payload component
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
004
Detects known malicious files associated with Kimsuky (APT-C-55) Stella_Gary attack chain by MD5 hash: OrionQuests-Setup.exe installer, guide.url.lnk, test.bef_fri, and backdoor payload component
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
004
Page 217 of 1871