Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the abuse of the legitimate Windows script 'SyncAppvPublishingServer.vbs' to proxy the execution of malicious commands, specifically by appending an arbitrary command separated by a semicolon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of csc.exe (C# compiler) from non-standard directories or when compiling source files located in user-writable paths like Temp or AppData. This behavior is indicative of on-host code compilation used by attackers to bypass static antivirus detection by delivering and compiling malicious payloads on the fly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of the Program Compatibility Assistant (pcalua.exe) with the '-a' flag to launch executables located in common user-writable directories such as Temp, Downloads, or AppData. This behavior is a known Living off the Land Binaries and Scripts (LOLBAS) technique used to proxy execution and potentially bypass security controls or break parent-child process lineage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of command-line utilities (cmd.exe, curl.exe, tar.exe) to download or interact with specific suspicious zip archives (python-3.10.0-embed-amd64.zip, temp012.zip, MusicLibrariesPackage) from known staging directories or external sources often associated with malicious staging or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of wscript.exe or cscript.exe with VBScript or JScript files from user-writable and temporary directories, such as %TEMP%, %APPDATA%, and Downloads folders. This pattern is commonly associated with the execution of malicious droppers and loaders in malspam campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of cmd.exe with suspicious command-line obfuscation patterns. The rule looks for the use of the '/k' flag combined with variable assignment and character substitution/expansion patterns (e.g., %var:~start,len%), often used in batch file obfuscation to execute malicious logic. It specifically triggers when originating from common suspicious parents like explorer.exe or Bandizip.exe, or when targeting syswow64 locations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects potentially malicious command execution initiated by or linked to the Bandizip archive utility. It identifies scenarios where Bandizip launches shells (cmd, powershell, wscript, cscript) to execute scripts or commands (e.g., .lnk files, .bat, .vbs, .js, .ps1), or where suspicious 'cmd.exe /k' commands are executed directly or through an updater process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects the execution of the Windows FTP client (ftp.exe) using a command script file (via the -s: parameter). It monitors for process creation of ftp.exe with this flag, excluding known legitimate paths. It then correlates this with any child processes initiated by the FTP client to identify potential data exfiltration or automated file transfers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of odbcconf.exe with the REGSVR flag to load DLLs from suspicious directory locations (such as Temp, Downloads, or AppData), a technique used by adversaries to proxy execution and bypass application control.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of installutil.exe with specific command-line arguments (logging disabled, uninstall flag) from file paths outside of the standard .NET directory structure. This pattern is commonly used by attackers to proxy execution of arbitrary managed code, effectively bypassing application whitelisting and security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the abuse of the legitimate Windows utility 'certutil.exe' to download files from external sources or to decode/deobfuscate files on the host, commonly used as a LOLBIN for malicious activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects file creation, renaming, or deletion events within the Recycle Bin directory involving suspicious filenames or PDF files, which may indicate an adversary attempting to hide, stage, or delete evidence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of regasm.exe or regsvcs.exe where the command line arguments reference paths typically used for temporary files, user downloads, or public directories. These signed .NET utilities can be abused to proxy the execution of malicious code by loading custom COM assemblies via ComRegisterFunction or ComUnregisterFunction attributes, effectively bypassing application control.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects Hancom HWP documents that contain an OLE BIN0001.OLE stream and specific JScript storage structures, which are indicative of a weaponized document used to execute scripts and fetch remote payloads from a specific command-and-control URL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects execution of MSBuild.exe (Microsoft Build Engine) where the project file is located in a potentially user-writable, temporary, or staging directory, or when the command line includes indicators of inline task compilation (e.g., UsingTask or TaskFactory). This behavior is often associated with the use of MSBuild to proxy execution of arbitrary code to bypass application control mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the execution of an executable named 'Windowsupdate.exe' located in non-standard user-writable directories (e.g., AppData\Local) when initiated by an FTP client process. This is a common pattern for malicious masquerading or persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of WMIC to invoke XSL files or perform suspicious process creation commands, a technique often used for proxy execution or script-based attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects potential User Account Control (UAC) bypass attempts involving the abuse of the COM object associated with 'sppextcomobj.exe'. The rule looks for scenarios where 'rundll32.exe' initiates 'sppextcomobj.exe', which in turn triggers 'slui.exe'. This behavioral chain is a known technique for achieving elevated privileges by exploiting how Windows handles COM auto-elevation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the abuse of the forfiles.exe utility to indirectly execute command-line interpreters such as cmd.exe, powershell.exe, or other common LOLBins. Adversaries use this technique to bypass security controls that monitor or restrict direct execution of these interpreters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the use of pcalua.exe to launch executables or scripts located in potentially transient or user-writable directories such as Temp, Downloads, or AppData. This behavior is indicative of an adversary attempting to execute payloads while bypassing security controls or masquerading as legitimate system processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects the Microsoft Support Diagnostic Tool (msdt.exe) being launched by Office applications or web browsers using the ms-msdt protocol handler or PCWDiagnostic parameters, which is indicative of the Follina (CVE-2022-30190) vulnerability exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Page 234 of 1871