Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects execution of rundll32.exe from non-standard locations or utilizing specific exported DLL functions often associated with bypassing application whitelisting, executing scripts, or proxying malicious code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects the use of PowerShell to modify Windows Defender configuration settings, specifically targeting the disabling of real-time monitoring, behavioral monitoring, or other security protections via the Set-MpPreference cmdlet.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects the creation of scheduled tasks using schtasks.exe or PowerShell where the task binary path resides in suspicious directories frequently used by adversaries for staging, such as AppData, Temp, Downloads, or Public folders.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects a dual persistence mechanism where an adversary establishes both an identically-named Registry Run key and a Scheduled Task, both masquerading as legitimate Canon or Stardock configuration software. These artifacts are configured to launch side-loaded host binaries (COTFileReadApp.exe or DeElevate64.exe) to maintain persistence on a Windows host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network activity associated with the Psychedelic Stealer malware, including C2 check-ins, API-based tasking, and communication with known C2 infrastructure using specific URI patterns and headers like 'X-API-Key'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a loader module and a corresponding RIFF/WAVE file that utilizes steganography to conceal a secondary malicious payload. The loader extracts the payload from the WAV file using specific offsets and XOR decoding, then executes it in memory. This pattern is characteristic of a DLL sideloading chain involving WMPCL.dll and WPFLocalizeExtension.dll.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the execution of PowerShell scripts that utilize large arrays of negative integers to reconstruct and dynamically execute code via the [scriptblock]::Create method. This technique is commonly used to obfuscate malicious payloads such as downloaders or API calls from static analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a sequence of distinct system and network reconnaissance commands typically performed by malware or RATs for environment fingerprinting. The rule triggers when three or more unique reconnaissance activities—such as querying antivirus status, enumerating network adapters, checking domain information, or listing installed software—occur from the same host within a 5-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects HTTP traffic patterns associated with the Psychedelic Stealer malware command and control (C2) agent. The rule matches specific URI paths used for pinging, configuration retrieval, and tasking, while verifying the presence of the required 'X-API-Key' header, indicating established C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects HTTP traffic patterns associated with the Psychedelic Stealer malware command and control (C2) agent. The rule matches specific URI paths used for pinging, configuration retrieval, and tasking, while verifying the presence of the required 'X-API-Key' header, indicating established C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network traffic attempting to connect to common public DNS-over-HTTPS (DoH) providers (Cloudflare, Google, Quad9) via TLS SNI or HTTP headers. This activity is often associated with malware or malicious agents attempting to bypass traditional DNS monitoring for command and control (C2) communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects malicious DLLs identified by specific exports and imports (e.g., rdCore.dll, I++u.dll) that are intended to be sideloaded by signed binaries such as Canon's COTFileReadApp.exe or Stardock software. The detection relies on identifying the combination of sideloaded component names and the presence of suspicious import structures characteristic of these specific staging loaders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects outbound HTTP POST requests associated with the Psychedelic Stealer malware, which attempts to exfiltrate data from web browser-based cryptocurrency wallet extensions by targeting specific API endpoints and wallet extension IDs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where the GOMCam2024 executable launches or spawns a Chrome process with specific command-line arguments involving the user-data-directory being set to the system Temp folder. This behavior is often indicative of process injection, proxy-based credential theft, or attempts to execute browser sessions in a non-standard, potentially malicious context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the creation of a Windows scheduled task using 'schtasks.exe' or the system's scheduled task creation event where the command line or task details contain the string 'psychedelicloveUtils'. This pattern is often indicative of specific malicious persistence mechanisms or automated task-based payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule detects the creation or modification of browser native messaging host configuration files (e.g., com.lunex.explorer.json) combined with the simultaneous or subsequent termination of common web browsers. This pattern is indicative of potential browser hijacking, where an adversary sets up a malicious native messaging host to facilitate persistence or intercept browser communications and subsequently restarts or terminates the browser process to reload the configuration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the execution of msiexec.exe to install an MSI package from a remote URL. This pattern involves the Windows Installer utility being invoked by explorer.exe with the /i (install) and /passive (unattended installation) flags, indicating a potentially malicious download and execution chain often used to deliver payloads via social engineering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the exploitation of the CMSTPLUA COM-object (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7) to bypass User Account Control (UAC). The rule monitors for PowerShell processes instantiating this object, followed by the execution of a hidden-window PowerShell process, bypassing the consent.exe UAC prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects low-prevalence processes executing from non-standard directories that communicate with the same domain across multiple destination IP addresses over HTTPS (443) or DNS (53) within a short period. This behavior may indicate the use of Domain Generation Algorithms (DGA), fast-flux infrastructure, malware beaconing, or resilient command-and-control (C2) communications.
avatar
Ajay Kumar@Karanajay
avatar
Detections.ai Community
13 days ago
103
Detects CARBONATO botnet activity where malicious processes are masquerading as legitimate Linux system components. This includes XMRig mining software running as /usr/sbin/systemd-logind, process arguments attempting to mimic kernel kworker threads, or processes running from directories associated with netd-svc/resolved container images.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule detects a multi-tool attack chain involving the Cairn autonomous exploitation engine and the Hermes Agent. It flags the co-occurrence of outbound network traffic to both the DeepSeek API (Cairn engine) and the Anthropic Claude API (Hermes Agent) from the same host within a one-hour window. This behavior is indicative of an automated, AI-driven post-exploitation orchestration campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000