Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects malicious staging and C2 activity characteristic of RatHat Android malware. The rule identifies processes running under the Android shell user (UID 2000) that execute specific tools (minicap, minitouch, or disguised libraries) from the /data/local/tmp directory, followed by an outbound network connection, which is indicative of a persistence mechanism and reverse-tunneling command-and-control communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the NeedyMantis second-stage loader, typically encountered as a malicious script (e.g., encryptbase64.ps1). The detection identifies raw shellcode residing in files that exhibit specific traits: PEB-walking for API resolution using a ROR(11) hashing algorithm, the inclusion of the 'RtlDecompressBuffer' API for payload expansion, and the absence of standard PowerShell script headers at the start of the file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects evidence of the Rapuncel infostealer attempting to compromise Chrome or Edge browsers. The rule identifies suspicious image loads into browser processes linked to known malicious hashes or the creation of specific browser decryption log files used by the malware to defeat App-Bound encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects Android applications that request Device Admin privileges followed by the execution of coercive commands, such as disabling biometric authentication, setting admin passwords, or enabling uninstall protection. This behavior is indicative of malicious applications (e.g., RatHat) aiming to establish persistence and prevent uninstallation by the user or security software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects NeedyMantis malware loader components that utilize the RtlDecompressBuffer API for custom XOR-compressed archive extraction. The rule specifically looks for the presence of known staged file names (dnsapi.dll, ws2_32.dll, msvcrt140.dll, or encryptbase64.ps1) alongside decoy file references typically used by the threat actor.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the NeedyMantis malware component loading configuration and communications modules (specifically dnsapi.dll or ws2_32.dll) from a non-standard system directory. This behavior is indicative of DLL hijacking or side-loading, where a malicious library is substituted for a legitimate Windows system library to facilitate command and control or malicious execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects persistence mechanisms associated with 'ComponentTask33Agent' which involves either creating a scheduled task or modifying Windows Registry Run keys, alongside potential VBScript-based agent execution via wscript.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the creation of Windows services by known binary hosts frequently utilized by NeedyMantis for DLL sideloading. This activity is indicative of the persistence phase where the actor's 'is' module registers itself as a service to ensure survival across system reboots following the execution of the sideloading chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a specific privilege escalation and code execution chain attributed to the PUROSANGUE methodology. This activity involves using a COM Elevation Moniker (specifically with the 'Elevation:Administrator!new:' syntax) to bypass UAC, followed by process hollowing into ServiceModelReg.exe. The attack is initiated from unconventional parent processes such as vsdbg.exe or its associated DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects NeedyMantis first-stage loader activity where a legitimate application (e.g., Poedit, curl, Vim, TightVNC) is executed to load an update or support DLL from a non-standard staging path (e.g., %ProgramData% subdirectories), followed by the presence of a co-located encrypted second-stage archive.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the ChainScript RAT, executing via a masqueraded Node.js process, enumerating Local Extension Settings for browser wallet plugins. This reconnaissance activity is a precursor to exfiltrating crypto wallet data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects specific Android device admin command sequences that indicate attempts to establish persistent access by hardening the device against removal (e.g., enabling uninstall protection, setting device admin passwords, disabling biometrics) or destructive actions like performing a factory reset or self-uninstallation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the spawning of script interpreters or loaders by Visual Studio Code (Code.exe) shortly after a workspace is initialized, specifically looking for command-line arguments referencing .vscode or tasks.json. This behavior is consistent with exploitation techniques where a user accepts a 'Trust Workspace' prompt, allowing malicious tasks defined in a repository's .vscode folder to execute.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects DNS queries for RatHat C2 panels using characteristic naming patterns and specific malicious domains, as well as outbound network connections to known RatHat C2 IP infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network traffic from mobile devices to the Google Gemini API (generativelanguage.googleapis.com) specifically targeting the 'generateContent' endpoint. This behavior is indicative of mobile malware (e.g., RatHat/PromptSpy) that may be utilizing AI-assisted UI-automation, potentially to exfiltrate screen content or automate malicious interactions by processing visual layout data through a generative model.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects behavior associated with the TeamFiltration backdoor, where a user account downloads a file from OneDrive, modifies or replaces that file, and re-uploads it within a short timeframe (30 minutes). This pattern is consistent with the 'taint shared content' technique used to distribute malicious files through legitimate cloud storage.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
002
Detects specific malicious archive payloads associated with NeedyMantis that contain a second-stage loader and spoofed system DLLs (e.g., dnsapi.dll, ws2_32.dll, msvcrt140.dll). These archives utilize XOR encoding or RtlDecompressBuffer packing and are designed for DLL sideloading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network traffic from mobile devices to the Google Gemini API (generativelanguage.googleapis.com) specifically targeting the 'generateContent' endpoint. This behavior is indicative of mobile malware (e.g., RatHat/PromptSpy) that may be utilizing AI-assisted UI-automation, potentially to exfiltrate screen content or automate malicious interactions by processing visual layout data through a generative model.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the NeedyMantis first-stage loader (e.g., WinSparkle.dll variants) which employs anti-debug techniques such as NtQueryInformationProcess and ThreadHideFromDebugger, alongside stack-based string deobfuscation, to prepare for the extraction and execution of a secondary payload (e.g., encryptbase64.ps1).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects HTTP traffic patterns associated with a custom 'RatHat' malware variant utilizing Google's Gemini API for command and control or remote automation. The rule identifies the initial POST request to the API with specific generation parameters (temperature 0.1, 256 tokens) and the corresponding JSON-formatted coordinate response from the server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a potential TeamFiltration-style compromise where multiple accounts with no history of successful authentication and no MFA enforced authenticate successfully within a 7-minute burst window. This behavior is indicative of an adversary mass-testing or accessing newly compromised dormant or un-secured service accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002