Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation of a local user account using the hardcoded 'Numlock!123' password, a characteristic artifact associated with Ransom Busters threat group operations. The rule monitors command-line activity from net.exe or net1.exe to identify attempts to add users with this specific, known malicious credential.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects a high frequency of process terminations occurring within a 5-minute window on a device where specific driver-related processes or command lines ('nvfsflt64.sys', 'Alinubx.sys') have been identified. Such behavior is characteristic of malicious activity attempting to disrupt system security components or clear traces, potentially indicating an endpoint denial of service or evasion attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
102
Detects instances where PowerShell or mshta.exe are launched by a web browser or Windows Explorer, often indicative of the 'ClickFix' social-engineering campaign. In this scenario, users are tricked into copying and pasting malicious commands from a fake CAPTCHA or update prompt directly into a Windows terminal or the Run dialog, leading to code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
303
Detects the loading of known vulnerable kernel drivers 'truesight.sys' or 'rentdrv2.sys'. These drivers are frequently abused in Bring-Your-Own-Vulnerable-Driver (BYOVD) attack chains, where attackers leverage specific IOCTL calls (such as 0x22E044 or 0x22E010) to interact with the driver to perform privileged actions, such as terminating security processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects the use of standard Windows administrative utilities (wmic.exe, vssadmin.exe, and wbadmin.exe) to perform destructive operations on volume shadow copies or backup catalogs. These actions are frequently associated with ransomware attacks to prevent system recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
303
Detects the execution of Active Directory Explorer (ADExplorer.exe or ADExplorer64.exe), a legitimate tool often repurposed by adversaries to enumerate Active Directory structures, accounts, and group memberships.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the invocation of SQL Server Management Studio (ssms.exe) by the PsExec or PsExec service process. This behavior is indicative of administrative tools being used for potentially unauthorized remote execution or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the use of the net.exe or net1.exe utilities to create a new user account with a hardcoded password string ('Numlock!123') in the command line. This is a common indicator of automated exploitation, credential hardcoding, or post-exploitation activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the presence or installation of 'truesight.sys' or 'rentdrv2.sys' drivers, which are associated with malicious activity. The rule also triggers when system utilities like sc.exe or services.exe are used to set services related to these names to a 'demand' start type, indicating potential persistence or malicious driver loading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects execution of PowerShell processes using the '-w hidden' argument and '-enc' (EncodedCommand) parameter, which is a common technique used by attackers to execute obfuscated code silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
103
Detects modifications to the Windows Explorer RunMRU registry key where values contain suspicious commands such as 'powershell', 'curl', or long base64-encoded strings, indicating potential command execution or persistence attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
103
Detects the creation or modification of InprocServer32 registry keys within CLSID paths in HKEY_LOCAL_MACHINE. These registry locations are frequently abused by adversaries to achieve persistence or execute arbitrary code (COM hijacking) by pointing the server path to a malicious DLL or executable.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects access, reading, or modification of sensitive credential files (such as KeePass databases, VPN profiles, private SSH keys, and certificates) by a process. This behavior is often associated with pre-encryption staging for data exfiltration during ransomware attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects instances where powershell.exe appears to be launched by explorer.exe via parent process ID (PPID) spoofing. The rule identifies processes where the reported parent explorer.exe was created at or after the child powershell.exe, or within a suspiciously short timeframe, indicating that the parent PID association is likely fraudulent rather than a genuine explorer-initiated shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the creation of a scheduled task using the schtasks utility where the execution principal is set to SYSTEM. This pattern is commonly observed in malware such as DragonForce ransomware to establish persistence or execute payloads with elevated privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the execution of the s5cmd utility using 'cp' or 'sync' commands directed towards S3 storage paths. This behavior is indicative of unauthorized data exfiltration to attacker-controlled cloud storage, a tactic identified in intrusions associated with the 'Ransom Busters' group.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the loading of rstrtmgr.dll by processes other than explorer.exe. Adversaries, particularly ransomware, utilize the Windows Restart Manager API (RmStartSession, RmRegisterResources, RmShutdown) to identify and forcibly terminate processes that hold file handles to files they intend to encrypt, thereby bypassing file-in-use locks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the execution of the 'net user' command with the '/add' parameter using the hardcoded password 'Numlock!123'. This pattern is frequently observed as a persistence mechanism employed by threat actors during ransomware operations to establish unauthorized administrative access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects the execution of a renamed Microsoft CoreCLR Debugger (vsdbg.exe) from a directory outside of standard Visual Studio installation paths. This behavior is indicative of DLL side-loading, where a malicious vsdbg.dll is planted alongside the renamed vsdbg.exe, a technique observed in malware loader chains like Rapuncel/BoryptGrab.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the execution of ServiceModelReg.exe following parent process activity involving vsdbg.dll/vsdbg.exe, coupled with cross-process access indicators consistent with COM Elevation Moniker UAC bypass and potential process hollowing. This pattern is associated with the PUROSANGUE loader chain used to execute malicious code within a high-integrity process context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the execution of ServiceModelReg.exe following parent process activity involving vsdbg.dll/vsdbg.exe, coupled with cross-process access indicators consistent with COM Elevation Moniker UAC bypass and potential process hollowing. This pattern is associated with the PUROSANGUE loader chain used to execute malicious code within a high-integrity process context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Page 240 of 1871