Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects modifications to the Windows Registry subkeys associated with the 'ms-settings' URI scheme, which are targeted by the 'fodhelper.exe' UAC bypass technique. The rule correlates registry operations in HKCU with the execution of fodhelper.exe to identify attempts to elevate privileges without triggering a UAC prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects potential abuse of rundll32.exe to execute commands or functions, particularly those involving references to 'WindowsUpdate.log' or direct execution with ordinal identifiers ('#1'). This rule also monitors file operations involving 'WindowsUpdate.log' initiated by common script interpreters like powershell.exe, cmd.exe, or rundll32.exe, which is often associated with obfuscated techniques to execute malicious payloads or bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects unauthorized in-memory memory modifications (specifically writing to memory segments with execute permissions) targeting critical security functions within 'amsi.dll' or 'ntdll.dll', such as 'AmsiScanBuffer' or 'EtwEventWrite'. This activity is characteristic of AMSI/ETW blinding, a technique used by threat actors to disable endpoint security scanning and event tracing capabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects high volumes of file rename operations within a short timeframe, which is a behavioral indicator often associated with the encryption process of ransomware such as CRPx0.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the execution of SoftPerfect Network Scanner (netscan.exe), a tool frequently utilized by threat actors such as Ransom Busters for internal network reconnaissance and host discovery activities prior to lateral movement or data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the modification of boot configuration data (BCD) using bcdedit to enable 'Safe Mode with Networking' on the next reboot. Adversaries, including Akira ransomware affiliates, use this technique to bypass endpoint detection and response (EDR) solutions by ensuring they do not start when the system boots in a restricted safe mode.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the creation of a local user account using the hardcoded 'Numlock!123' password, a characteristic artifact associated with Ransom Busters threat group operations. The rule monitors command-line activity from net.exe or net1.exe to identify attempts to add users with this specific, known malicious credential.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects a high frequency of process terminations occurring within a 5-minute window on a device where specific driver-related processes or command lines ('nvfsflt64.sys', 'Alinubx.sys') have been identified. Such behavior is characteristic of malicious activity attempting to disrupt system security components or clear traces, potentially indicating an endpoint denial of service or evasion attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
102
Detects instances where PowerShell or mshta.exe are launched by a web browser or Windows Explorer, often indicative of the 'ClickFix' social-engineering campaign. In this scenario, users are tricked into copying and pasting malicious commands from a fake CAPTCHA or update prompt directly into a Windows terminal or the Run dialog, leading to code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
303
Detects the loading of known vulnerable kernel drivers 'truesight.sys' or 'rentdrv2.sys'. These drivers are frequently abused in Bring-Your-Own-Vulnerable-Driver (BYOVD) attack chains, where attackers leverage specific IOCTL calls (such as 0x22E044 or 0x22E010) to interact with the driver to perform privileged actions, such as terminating security processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects the use of standard Windows administrative utilities (wmic.exe, vssadmin.exe, and wbadmin.exe) to perform destructive operations on volume shadow copies or backup catalogs. These actions are frequently associated with ransomware attacks to prevent system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
303
Detects the execution of Active Directory Explorer (ADExplorer.exe or ADExplorer64.exe), a legitimate tool often repurposed by adversaries to enumerate Active Directory structures, accounts, and group memberships.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the invocation of SQL Server Management Studio (ssms.exe) by the PsExec or PsExec service process. This behavior is indicative of administrative tools being used for potentially unauthorized remote execution or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the use of the net.exe or net1.exe utilities to create a new user account with a hardcoded password string ('Numlock!123') in the command line. This is a common indicator of automated exploitation, credential hardcoding, or post-exploitation activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the presence or installation of 'truesight.sys' or 'rentdrv2.sys' drivers, which are associated with malicious activity. The rule also triggers when system utilities like sc.exe or services.exe are used to set services related to these names to a 'demand' start type, indicating potential persistence or malicious driver loading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects execution of PowerShell processes using the '-w hidden' argument and '-enc' (EncodedCommand) parameter, which is a common technique used by attackers to execute obfuscated code silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
103
Detects modifications to the Windows Explorer RunMRU registry key where values contain suspicious commands such as 'powershell', 'curl', or long base64-encoded strings, indicating potential command execution or persistence attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
103
Detects the creation or modification of InprocServer32 registry keys within CLSID paths in HKEY_LOCAL_MACHINE. These registry locations are frequently abused by adversaries to achieve persistence or execute arbitrary code (COM hijacking) by pointing the server path to a malicious DLL or executable.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects access, reading, or modification of sensitive credential files (such as KeePass databases, VPN profiles, private SSH keys, and certificates) by a process. This behavior is often associated with pre-encryption staging for data exfiltration during ransomware attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects instances where powershell.exe appears to be launched by explorer.exe via parent process ID (PPID) spoofing. The rule identifies processes where the reported parent explorer.exe was created at or after the child powershell.exe, or within a suspiciously short timeframe, indicating that the parent PID association is likely fraudulent rather than a genuine explorer-initiated shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the creation of a scheduled task using the schtasks utility where the execution principal is set to SYSTEM. This pattern is commonly observed in malware such as DragonForce ransomware to establish persistence or execute payloads with elevated privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Page 239 of 1871