Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of diskshadow.exe with the /s (scripted) flag, followed by file access to sensitive Windows credential files (ntds.dit or SAM). This behavior indicates the abuse of the Windows Diskshadow utility to create a volume shadow copy for the purpose of offline credential exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects file creation, modification, or renaming activity within AppData directories associated with VPN clients (CyberGhost, NordVPN, ExpressVPN). This rule is intended to identify potential unauthorized access, staging, or tampering with VPN configuration files or credentials often stored in these application directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
101
Detects the use of dnscmd.exe to register a server-level plugin DLL for the Windows DNS service. This action is a known persistence mechanism that can be used to achieve arbitrary code execution within the context of the DNS service (dns.exe) upon service restart. The rule specifically alerts when a DLL file path outside of standard System32 or SysWOW64 directories is configured.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects behaviors associated with the Hannibal Stealer, specifically the identification of the Bitcoin Core wallet directory via registry lookups (strDataDir) followed by the unauthorized copying of 'wallet.dat' files into a staging directory structure, commonly used for cryptocurrency wallet exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of dnscmd.exe to register a server-level plugin DLL for the Windows DNS service. This action is a known persistence mechanism that can be used to achieve arbitrary code execution within the context of the DNS service (dns.exe) upon service restart. The rule specifically alerts when a DLL file path outside of standard System32 or SysWOW64 directories is configured.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
Detects non-standard processes loading the iphlpapi.dll library and subsequently executing commands related to ARP network discovery, such as GetBSSID, SendARP, GetDefaultGateway, or GetAllNetworkInterfaces. This behavior is characteristic of network reconnaissance and fingerprinting activities often employed by information stealers like Hannibal Stealer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects remote lateral movement attempts using DCOM to launch the Microsoft Management Console (mmc.exe) via svchost.exe (RPCSS/DCOM), followed by mmc.exe spawning an unexpected child process. This pattern indicates potential remote execution and abuse of signed binary proxies for post-exploitation activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
000
This rule detects instances where the DISM core library (DismCore.dll) is loaded by a process named 'index.exe', or where a process named 'index.exe' is executing from or interacting with a folder path containing 'DISM'. This behavior is characteristic of malicious tools or scripts attempting to proxy execution through the Deployment Image Servicing and Management (DISM) binary, a common technique for bypassing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects modifications, creation, or renaming of common cryptocurrency wallet files (e.g., wallet.dat, .wallet files) within known storage directories. This behavior is often associated with infostealers or malware attempting to exfiltrate or manipulate user financial assets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects presence of configuration markers associated with the Hannibal Stealer 'clipper' functionality. These markers (e.g., 'cclipper', 'clipboard_check_delay') are used by the malware to monitor the system clipboard and replace cryptocurrency wallet addresses with attacker-controlled addresses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects components of the LucidPawn malware family using DLL side-loading (e.g., index.exe loading DismCore.dll) or renaming DISM binaries within WindowsApps folders. The detection identifies these processes subsequently querying system locale or language registry keys, indicating a geo-targeting execution gate used to determine if the environment matches the intended target profile (specifically zh-TW).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects instances of the Hannibal Stealer module that attempt to masquerade as the legitimate 'CefSharp.BrowsersSubprocess.dll' by spoofing publisher metadata ('LLC Windows'). The detection triggers when this process is identified initiating network connections shortly after execution, which aligns with the malware's known behavior of performing geolocation-based checks before continuing activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the use of WMI (via wmic.exe, PowerShell, or other scripting engines) to query the Win32_Process class for process identification or path resolution. This behavior is commonly used by malicious actors, including info-stealers, to map active processes and their file locations for discovery purposes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects instances where an executable masquerading as 'msedge.exe' (Microsoft Edge) is launched from a user's Startup folder. The rule looks for files identified as 'msedge.exe' that contain metadata or product information associated with DISM (Deployment Image Servicing and Management) or base Windows operating system components, indicating a potential attempt to disguise a different utility or payload as a trusted web browser.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of PowerShell with specific Pester build script arguments, initiated by Windows Explorer, followed within 5 minutes by the execution of 'index.exe' on the same host. This sequence may indicate malicious activity involving script execution leading to the spawning of an unknown or suspicious 'index.exe' binary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects potential information stealer activity by identifying the staging of files (.html, .txt, .log) in common user directories like AppData or Temp, combined with process command lines querying sensitive system information (e.g., BIOS, wallets, screen resolution) and network connections to the Telegram API for likely exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
000
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
16 days ago
000
This rule detects the execution of specific suspicious binary names (TempuARKK20.exe, uARKK20.exe) from within temporary directories or their association with command-line arguments involving 'curl.exe' or specific suspicious web hosting strings. This behavior is indicative of malware staging and downloading secondary payloads in an attempt to masquerade as legitimate utilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects various suspicious activities associated with file staging and execution in the C:\Users\Public directory, including the handling of suspicious ZIP archives, renaming of executables (pythonw.exe to userscreen.exe), and the execution of specific batch scripts or obfuscated commands. These behaviors are indicative of an adversary staging tools or persistence mechanisms on a compromised system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Page 235 of 1871