Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects attempts to bypass Windows User Account Control (UAC) by identifying processes that use specific command-line arguments (such as /Elevation:Administrator, /shell:RunAs, or /runas /savecred) combined with known binaries (such as vsdbg, rundll32, or cmstp) often abused to achieve elevated privileges or proxy execution of malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the installation of Windows services with image paths containing strings associated with known commodity malware or potentially unwanted software (Alinubx, CcProtect, nvfsflt64, NvFsFilter). This activity is often indicative of persistence mechanisms or driver-based malicious components being registered on the host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects suspicious process injection, module loads, or thread creation events where a web browser process (chrome.exe or msedge.exe) is the target, excluding known legitimate browser-related processes or sub-components like the elevation service.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
This rule detects potential security software tampering by identifying the loading of a specific driver (Alinubx.sys) followed by the termination or interference of common security agent processes within a short timeframe. This behavior is indicative of an adversary attempting to disable endpoint protection using a Bring Your Own Vulnerable Driver (BYOVD) or malicious driver approach.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the loading of the hostfxr.dll module, the presence of the DLLMemLoader string in command lines, or the execution of python or pythonw processes. These patterns are often associated with the loading of malicious assemblies or execution via scripting environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the execution of the legacy 'finger.exe' network utility with suspicious command-line arguments. The finger protocol is an outdated service that provides information about users on a system; adversaries may abuse this utility to perform network reconnaissance, identify user accounts, or gather system-level information.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the loading of the System.Management.Automation.dll (PowerShell assembly) by processes other than standard PowerShell executable files. This behavior often indicates an attempt to execute PowerShell code from a non-standard process, potentially to bypass security controls or obfuscate malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the execution of network utilities like finger.exe or curl.exe (with download parameters) initiated by a command shell (cmd.exe, powershell.exe, or pwsh.exe). This pattern is often used by adversaries for reconnaissance or downloading malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the execution of Python processes where command line arguments indicate the use of the DLLMemLoader agent or related indicators like 'hostfxr' or specific hex strings. This activity is often associated with the loading of malicious DLLs or secondary stages in an attack chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden window, download strings, or invocation commands) initiated by Windows Explorer. This is a common pattern for malicious scripts or droppers attempting to execute code covertly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects when a high volume of distinct security-related processes or services are terminated on a single host within a 2-minute window. This behavior is strongly indicative of an adversary attempting to disable endpoint protection software as part of a post-compromise defensive evasion effort.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects creation of a token.cmd file in AppData followed by its execution via cmd.exe within a 5-minute window.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects creation of a token.cmd file in AppData followed by its execution via cmd.exe within a 5-minute window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects a process that deletes its own executable or script file within a short time window after launch, which is a technique used by some implants.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects a process that deletes its own executable or script file within a short time window after launch, which is a technique used by some implants.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
001
Detects a process that deletes its own executable or script file within a short time window after launch, which is a technique used by some implants.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects instances where a parent Node.js process spawns a child Node.js process using a command line structure often associated with malicious npm packages. These packages frequently attempt to execute loader scripts in a detached or background manner to evade detection while maintaining persistence or performing malicious operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects suspicious PowerShell commands involving node.js, hidden window styles, and file downloads or transfers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects suspicious PowerShell commands involving node.js, hidden window styles, and file downloads or transfers.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
001
Detects suspicious PowerShell commands involving node.js, hidden window styles, and file downloads or transfers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects creation of a token.cmd file in AppData followed by its execution via cmd.exe within a 5-minute window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Page 247 of 1871