Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
001
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
001
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
001
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
001
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects the execution of signed, Microsoft-publisher binaries that are located in typically user-writable or suspicious directories (e.g., AppData, ProgramData, Temp, Users) when initiated by cmd.exe or powershell.exe with an argument indicating a batch file reference. This pattern is indicative of potential masquerading or living-off-the-land techniques where a signed binary is moved or executed from an unconventional location to bypass security controls or execution policies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule detects the execution of the Xray proxy utility (xray-core) when launched by the RemoteApp workspace broker process (wkspbroker.exe) or located within the RemoteApp Gateway application data folder. This behavior is indicative of an adversary using proxy tools to facilitate command-and-control communication or network traffic tunneling via trusted remote access infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the modification of InProcServer32 registry keys within the user's Classes/CLSID hive to point to a file located in the AppData directory. This pattern is commonly used for COM hijacking to achieve persistence or execute arbitrary code under the user's context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the 'sharedLoad.min.js' loader script associated with the malicious 'indexed-btree' npm package family. This script utilizes X25519 ECDH for key exchange and AES-256 decryption to retrieve and execute a second-stage payload hosted on a Sepolia smart contract.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the execution of Node.js processes where the command line contains references to specific strings potentially associated with malicious packages or libraries often used in supply chain attacks or obfuscated payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects file removal, write, or rename operations performed by the Node.js process within the 'node_modules' directory, specifically targeting sensitive files like 'sharedLoad.min.js' or paths containing 'extended' or 'btree'. This behavior is indicative of potential malicious activity related to software supply chain compromise or unauthorized modification of dependencies within a Node.js application environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Page 249 of 1871