Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the use of PowerShell script interpreters that utilize .NET runtime methods, such as 'RunspaceFactory' and 'CreateRunspace', to dynamically create and execute scripts, pipelines, or invoke methods. This technique is often used by fileless malware and offensive security tools to bypass traditional command-line logging by interacting directly with the System.Management.Automation assembly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects the execution of a specific MSI package identified by its filename and hash (MD5/SHA256). The rule monitors 'msiexec.exe' process executions and alerts when the process command line or file hash matches a known malicious indicator.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects the execution of a specific MSI package identified by its filename and hash (MD5/SHA256). The rule monitors 'msiexec.exe' process executions and alerts when the process command line or file hash matches a known malicious indicator.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of 7-zip (7z.exe) to interact with a specific file (drata.dat) using command-line arguments typical of an archival or extraction operation. This may indicate an adversary attempting to stage, compress, or exfiltrate sensitive data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of cmd.exe as a child process of msiexec.exe, specifically when the command line includes 'xupdate.bat' and references a suspicious file path within 'AppData\Roaming\Traiolx Custom Utils'. This pattern is indicative of potential malicious installer abuse or software updates being used for code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule monitors for the presence of a file named '_socket.pyd', which is a standard Python library component. The alert triggers when this file appears within a specific directory path 'Traiolx Custom Utils' or matches a known file hash associated with potentially malicious activity or unauthorized use of Python modules.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects access, retrieval, or modification of the 'RegisteredOrganization' registry value under 'SOFTWARE\Microsoft\Windows NT\CurrentVersion'. This key often contains information about the registered owner or organization of the Windows installation and is frequently queried or modified during reconnaissance or environment configuration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This pattern can indicate suspicious activity where a legitimate updater process is being misused or abused to spawn additional malicious code or side-load components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule monitors for PowerShell commands that combine common data collection flags ('-Recurse', 'Documents') with 'Invoke-WebRequest' to perform a POST method upload. This pattern is commonly associated with the staging and exfiltration of sensitive files from local directories to a remote destination via HTTP/S.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of the Windows binary InstallUtil.exe using specific flags (/logfile=, /LogToConsole=false, and /U) commonly used to execute arbitrary .NET code while bypassing application control mechanisms such as AppLocker or Windows Defender Application Control (WDAC).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of regsvr32.exe with flags indicative of the Squiblydoo technique, which utilizes the /i parameter to load a remote COM scriptlet (.sct file) via scrobj.dll. This method is a known application allowlisting bypass technique.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects the presence of compiled Python 3.10 bytecode (.pyc) files that have been renamed to or disguised with a .cat extension. It specifically looks for the 'settingenv.cat' file associated with the Chinotto backdoor, as well as associated C2 URL patterns or command-line artifacts indicative of its download and execution chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of odbcconf.exe with the REGSVR action. This technique leverages the legitimate Windows utility odbcconf.exe to load and execute arbitrary DLLs, bypassing security controls that might not monitor or restrict this binary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects the execution of suspicious shortcut (.lnk) files or the use of command-line interpreters (cmd.exe, powershell.exe, wscript.exe, cscript.exe) to initiate processes related to specific, potentially malicious filenames often associated with phishing or social engineering campaigns. The rule monitors for these activities occurring in user-writable directories such as Downloads, Desktop, or Temp.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects execution of PowerShell with bypassed execution policy used to download or copy files from remote locations using curl.exe and Copy-Item. This pattern is commonly associated with file staging or retrieving malicious payloads from external URLs, including specific paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of forfiles.exe to execute command-line interpreters such as cmd.exe or powershell.exe. This pattern is commonly used by adversaries as a LOLBAS (Living Off the Land Binary and Script) technique to achieve indirect command execution and bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to initiate process creation on remote hosts. This is achieved by combining the '/node:' flag (to specify a remote target) with the 'process call create' command. This technique is frequently utilized by adversaries and ransomware operators for lateral movement across a Windows network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of cmstp.exe with silent (/s) and auto-install (/au) flags pointing to an attacker-supplied INF file. This pattern is a documented technique for bypassing User Account Control (UAC) and performing signed-binary proxy execution to load malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of Regasm.exe or Regsvcs.exe where the target assembly is located in a path other than standard Windows or .NET framework directories. This behavior is often indicative of an adversary attempting to use these signed utilities to load and execute malicious .NET payloads as a proxy, thereby bypassing application allowlisting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of command-line utilities (cmd.exe, curl.exe, tar.exe) to download or interact with specific suspicious zip archives (python-3.10.0-embed-amd64.zip, temp012.zip, MusicLibrariesPackage) from known staging directories or external sources often associated with malicious staging or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of Control Panel (.cpl) files via control.exe from non-standard system directories, or the use of rundll32.exe to invoke CPL applets. These methods are commonly used to proxy malicious code execution while appearing legitimate.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Page 233 of 1871