Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the MovieReaper Stage-3 module which masquerades as Microsoft Edge (msedge.exe) within the C:\ProgramData\Windows\Telemetry directory. The detection focuses on suspicious process execution from this directory and identifies instances where the process respawns itself, suggesting malicious activity post-UAC bypass.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the use of the Add-MpPreference cmdlet with -ExclusionPath, or processes spawned by CRUDEEXCLUDE.exe, which are associated with configuring Microsoft Defender exclusion paths. This is often used by adversaries to evade detection by excluding malicious files or directories from antivirus scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects instances where Windows scripting engines (WScript or MSHTA) execute script files (WSF, VBS, HTA) which subsequently spawn a PowerShell process using encoded command arguments. This pattern is commonly used by adversaries to mask malicious payloads and bypass execution policy or simple command-line monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
101
Detects the execution of PowerShell with common obfuscation flags (-W Hidden, -nop, -nol) that attempt to load and execute a script directly from the user's local Temp directory. The detection specifically monitors for processes launched by command interpreters like cmd.exe or batch files, which is a common indicator of a malware dropper or stager.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
26 days ago
609
This rule detects potentially malicious activity where specific non-standard processes (e.g., RuntimeSSH.exe, MicDriver.exe, MsCache.exe) either execute PowerShell commands related to security feature tampering (disabling Windows Defender exclusions) or create persistent Registry run keys associated with these process names. This pattern is indicative of malware attempting to establish persistence or evade security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the invocation of the C# compiler (csc.exe) by PowerShell, where the command line includes specific references to .cmdline files. This pattern is commonly used in fileless execution techniques to compile and execute malicious code in memory after delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
101
Detects SVG image files that contain embedded HTML or script payloads, often used as an initial delivery vector to smuggle malicious code (such as downloaders or web redirects) into a target environment. This technique has been associated with the delivery of various remote access trojans (RATs).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of 'winget.exe' with the 'configure' command. This command is used to apply configuration files (typically YAML-based) to the system, which can automate software deployment, environment setup, or system changes. Adversaries may abuse this utility to facilitate malicious software deployment or system configuration changes via legitimate administrative tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of ConfigurationRemotingServer.exe initiated by winget.exe. This could indicate usage of the Windows Package Manager to facilitate remote configuration or management tasks, which warrants investigation for potential unauthorized use or process manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects instances of MSBuild.exe executing or communicating over the network while referencing .NET Framework paths. MSBuild is often abused as a LOLBAS (Living Off the Land Binary and Script) to execute arbitrary code or bypass application control, and unusual network activity from this process is a common indicator of beaconing or command-and-control communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
101
This rule detects the use of 'winget' or 'ConfigurationRemotingServer.exe' to execute Windows Configuration DSC (Desired State Configuration) files, specifically targeting the invocation of 'PSDscResources/Script' resources, 'SetScript', 'TestScript', or 'GetScript' operations. This technique may be leveraged by attackers to execute arbitrary code or maintain persistence through the configuration management framework.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule monitors for outbound TCP traffic from internal hosts to a specific IP address (212.34.141.103) on port 4521, which is associated with C2 beaconing behavior, potentially involving the abuse of MSBuild.exe as a LOLBin.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects two suspicious activities: first, the execution of 'conhost.exe' with a headless command line argument containing 'cmd /c echo' and either a '.tmp' file reference or a suspicious base64-like encoded string, initiated by explorer.exe or cmd.exe. Second, it identifies the presence of '.lnk' shortcut files within common user-writable directories such as Downloads, Desktop, or Public folders, which is a common indicator of staging or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule monitors process creation events for suspicious activity, specifically detecting two patterns: 1) The creation of a scheduled task named 'OneDrive KeepAlive' using schtasks.exe, which is indicative of persistence mechanisms masquerading as legitimate software, and 2) Execution of the 'taskhostw.exe' binary with command-line arguments 'exec' and 'hide', which is a common indicator of the NirCmd utility being renamed and used for stealthy execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects persistence attempts via Component Object Model (COM) hijacking. It identifies a specific process 'December_blob.exe' creating or modifying registry keys associated with COM CLSIDs (specifically InprocServer32) and simultaneously dropping or utilizing a file named 'hvcsrv.dll' within an 'IdentityNexusIntegration' directory. This combination of registry modification and file system activity suggests the registration of a malicious COM object to achieve execution persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects instances where Windows Terminal (WindowsTerminal.exe) is launched by Explorer and immediately spawns a shell process (PowerShell, PWSH, or CMD), specifically excluding devices that have recorded recent RunMRU registry history. This pattern may indicate suspicious or non-interactive execution by an adversary attempting to bypass traditional shell history tracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects attempts to query or access the MachineGuid registry key located in HKLM\SOFTWARE\Microsoft\Cryptography. This registry key is commonly used to uniquely identify a Windows installation and is frequently targeted by malicious software to perform system identification or fingerprinting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of nodejs.exe to initiate external network tunnels to known tunneling services like pinggy.io or generic tunnels using common tunnel configuration flags.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of nodejs.exe to initiate external network tunnels to known tunneling services like pinggy.io or generic tunnels using common tunnel configuration flags.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of the Windows 'tasklist' utility or command execution via 'cmd.exe' when the command line includes strings associated with common debugging tools (e.g., windbg, x64dbg). This behavior may indicate an adversary checking for the presence of analysis tools or attempting to manipulate running processes, which is often associated with debugger evasion or malicious environment reconnaissance.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Page 232 of 1871