Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
005
Detects Microsoft Defender (MsMpEng) performing scan or remediation actions against non-standard filesystem paths, specifically NT object-manager namespace paths or CLFS-driver-prefixed paths. This behavior is indicative of an exploitation attempt (e.g., CVE-2026-69414) where an attacker uses symbolic links and CLFS driver namespaces to redirect the Defender scanning engine to arbitrary files on the system, potentially allowing file reads as SYSTEM.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
1 month ago
5125
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
005
This rule monitors endpoint network events, file operations, and process executions for known malicious indicators (domains and file hashes) associated with Kremlin activity. It detects connections to suspicious remote domains and the existence or execution of specific malicious file hashes.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
005
This rule detects the execution of a specific batch file named 'Right-click to open Invoice Details.bat', or execution of a batch file matching a known malicious SHA256 hash associated with AsyncRAT distribution campaigns.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
25 days ago
106
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
107
Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
28 days ago
1014
This rule monitors endpoint network events, file events, and process executions for indicators associated with the Kamasers malware. It specifically looks for connections to known malicious C2 IP addresses and domains, as well as the presence or execution of files matching known malicious SHA256 hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
103
This rule detects non-browser processes initiating network connections to common file-sharing or cloud services (e.g., GitHub Gist, Telegram, Dropbox) followed by subsequent network activity from the same process within a 5-minute window. This behavior is indicative of potential command and control (C2) communication, payload retrieval, or data staging/exfiltration using legitimate web services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
003
Detects the execution of PowerShell commands initiated from a .lnk file that query system information related to virtualization technologies (e.g., VMware, VirtualBox, Hyper-V) or hardware details (e.g., BIOS, VideoController). This pattern is often used for environmental awareness or anti-sandbox/anti-analysis techniques by malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects access to sensitive browser credential storage files (Login Data, key4.db, logins.json) by unauthorized processes. This behavior is indicative of credential theft, where an adversary attempts to extract stored passwords from browser profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
103
Detects instances where a process named firefox.exe attempts to modify or create a registry run key, which is a common persistence technique, but the process file path does not correspond to the legitimate Mozilla Firefox installation directory. This behavior often indicates that an attacker is masquerading as a legitimate browser process to establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects files that contain a valid RTF file header but also contain signatures indicative of embedded non-RTF content such as PE executables, ZIP archives, or OLE objects. This technique is often used to masquerade malicious payloads as benign document files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
103
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
6024
This rule identifies the Stella_Gary modular C# backdoor framework, which has been attributed to the Kimsuky (APT-C-55) threat group. The rule functions by detecting specific naming conventions within the binary and the presence of .NET assembly loading capabilities combined with plugin management functionality, characteristic of this modular malware family.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
103
Detects the execution of PowerShell with suspicious command-line arguments (e.g., -enc, -nop, -windowstyle hidden) originating from an LNK file launched by explorer.exe. This pattern is commonly used by adversaries to execute obfuscated malicious payloads embedded within shortcut files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
This rule detects non-browser processes attempting to access sensitive web browser credential files, such as 'Login Data', 'logins.json', and 'key4.db'. Such activity is highly characteristic of credential-stealing malware (including BabylonRAT) attempting to exfiltrate stored passwords or session data from Google Chrome or Mozilla Firefox profiles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
Detects unauthorized processes attempting to access browser credential database files such as Login Data for Chromium-based browsers or logins.json and key4.db for Firefox. The rule filters out known browser processes to isolate potential credential harvesting or exfiltration activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
003
This rule detects PowerShell commands that utilize specific character array joining techniques (e.g., [char]nnnn -join '') often used to obfuscate malicious strings or bypass keyword-based security filters. This is a common tactic for evading detection when downloading or executing payloads.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
25 days ago
706
Detects the execution of PowerShell with common obfuscation or stealth-related flags (e.g., -enc, -nop, -w hidden) when initiated by CMD or from a LNK file, particularly when originating from Windows Explorer. This is a common pattern for malicious file execution and dropper activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
103
Page 252 of 1871