Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects the loading of the 'vsstrace.dll' module by processes that are not standard system processes or authorized software. The 'vsstrace.dll' is a library used by the Volume Shadow Copy Service (VSS). Unauthorized or unexpected processes loading this DLL may indicate an attempt to interact with or manipulate volume shadow copies, which is a common behavior for ransomware attempting to inhibit system recovery.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
15 days ago
106
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
306
Detects indicators of compromise related to the TraderTraitor (KelpDAO) threat actor, including specific file hashes, malicious process paths, C2 network infrastructure (IPs and domains), and malicious TLS certificates. The rule uses filename-path matching to reduce noise from legitimate macOS binaries.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
106
This rule detects the creation of scheduled tasks on a remote host via the Task Scheduler RPC interface (opnum 1, RegisterTask). This interface is commonly abused by lateral movement tools such as Impacket's atexec, SharpTask, and SynkLoader to execute code or establish persistence on a remote system.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
11 days ago
002
Detects a multi-stage loader execution chain, potentially named GHAPPIER, by identifying sequential stages of execution. These stages include initial marker file checks, shell-based command dispatching via curl/wget, renaming and execution of secondary payloads, Node.js-based runtime staging, and the eventual creation of implant artifacts in common paths such as VSCode extensions or hidden directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
006
Detects the use of 'terraform init' where the command line arguments reference known typosquatted HashiCorp registry domains. This behavior is indicative of a supply chain attack attempting to pull malicious providers or modules from an adversary-controlled source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
206
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
11 days ago
102
This rule monitors network, DNS, and HTTP activity to identify connections to known infrastructure associated with the ClickFix social engineering campaign and Vidar infostealer malware. The rule correlates device network events, HTTP request events, and DNS queries against a list of known malicious domains, IP addresses, and URL patterns used for C2, staging, and lures.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
102
This rule detects potential unauthorized account creation by correlating suspicious administrative activity on network edge devices (VPNs, firewalls) with subsequent local administrator account creation on an internal host within a one-hour window. This behavior is indicative of ransomware affiliates exploiting internet-facing infrastructure to gain initial access and escalate privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
302
Detects multiple methods of tampering with Windows Defender security controls within a short time window. This includes PowerShell commands to modify Defender preferences (e.g., disabling Real-time Monitoring or adding exclusions), modifications to Defender-related registry keys, and attempts to stop or disable the WinDefend service.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
102
Detects processes establishing persistence via Windows Registry 'Run' keys followed by frequent outbound network connections over non-standard ports. This behavior is consistent with the SystemBC/Coroxy SOCKS5 proxy backdoor often utilized by ransomware actors like Ryuk, Conti, BlackBasta, Play, and Rhysida.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects persistence mechanisms used by The Gentlemen ransomware, specifically the creation of malicious scheduled tasks (UpdateUser, UpdateSystem, or gentlemen_system) and modification of registry Run keys (GupdateS or GupdateU). The rule also monitors for the presence of the operator password string 'G7Vz9eyG' within command line arguments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
102
Detects attempts to terminate security-related processes (AV/EDR) using common administrative tools including taskkill.exe, wmic.exe, and PowerShell Stop-Process. This behavior is frequently observed during the pre-encryption phase of ransomware attacks, such as Nova and Gentlemen, to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
302
Detects ClickFix-style social engineering attacks where a user is tricked into manually executing a PowerShell command. The command typically utilizes Invoke-RestMethod to fetch a remote payload and Invoke-Expression to execute it in memory, bypassing execution policies. This behavior is commonly associated with campaigns like SmartApeSG and DeepLoad.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects the DeepLoad malware staging process injection by spawning trusted Windows binaries (LockAppHost.exe, makecab.exe, or Magnify.exe) in a suspended state from an unauthorized parent process. This behavior is indicative of an APC-based injection sequence where malicious code is written into the suspended process before execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects the execution of PowerShell scripts 'first.ps1' and 'main1.ps1', which are components of a known credential phishing toolset. This tool displays a fake Windows Update dialog to trick users into providing their credentials, which are then exfiltrated via SMB, DNS, or HTTP.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects reconnaissance and persistence behaviors associated with the Akira ransomware attack chain, specifically the execution of the Cloudflare Tunnel daemon for remote access or the creation/modification of local user accounts via standard Windows tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
KQL Query from file: Detect Docker API activity on port 2375
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
002
KQL Query from file: Carbonato: C2 Communication Detected
avatar
Ankit Mehta@Secvyn
avatar
Hunters
11 days ago
102
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
102
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002