Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects suspicious persistence activity involving known tools or names that are often masqueraded. It looks for the creation of registry run keys or scheduled tasks using names associated with common tools ('Canon Configuration Reader', 'Stardock DeElevation Tool') when the initiating process is not located in the expected vendor-authorized directories. The rule specifically alerts on devices exhibiting these behaviors within a short time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
This rule detects suspicious persistence activity involving known tools or names that are often masqueraded. It looks for the creation of registry run keys or scheduled tasks using names associated with common tools ('Canon Configuration Reader', 'Stardock DeElevation Tool') when the initiating process is not located in the expected vendor-authorized directories. The rule specifically alerts on devices exhibiting these behaviors within a short time window.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
Detects the WAV-based loader staging technique: a RIFF/WAVE file carrying a high-entropy appended blob, or a companion DLL chain (rdCore.dll/WMPCL.dll/WPFLocalizeExtension.dll) referencing the hidden audio payload and the encrypted monitor.raw container used to unpack the final RAT
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects the WAV-based loader staging technique: a RIFF/WAVE file carrying a high-entropy appended blob, or a companion DLL chain (rdCore.dll/WMPCL.dll/WPFLocalizeExtension.dll) referencing the hidden audio payload and the encrypted monitor.raw container used to unpack the final RAT
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects the WAV-based loader staging technique: a RIFF/WAVE file carrying a high-entropy appended blob, or a companion DLL chain (rdCore.dll/WMPCL.dll/WPFLocalizeExtension.dll) referencing the hidden audio payload and the encrypted monitor.raw container used to unpack the final RAT
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
This rule detects potential DLL sideloading activity where legitimate, signed binaries (such as COTFileReadApp.exe or DeElevate64.exe) are executed from non-standard directories (e.g., AppData, Temp, Downloads) while loading specifically identified malicious or sideloaded DLLs. The detection identifies patterns where these binaries operate outside their expected vendor installation paths, indicating a likely attempt to hijack execution flow.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
This rule detects potential DLL sideloading activity where legitimate, signed binaries (such as COTFileReadApp.exe or DeElevate64.exe) are executed from non-standard directories (e.g., AppData, Temp, Downloads) while loading specifically identified malicious or sideloaded DLLs. The detection identifies patterns where these binaries operate outside their expected vendor installation paths, indicating a likely attempt to hijack execution flow.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
This rule detects potential DLL sideloading activity where legitimate, signed binaries (such as COTFileReadApp.exe or DeElevate64.exe) are executed from non-standard directories (e.g., AppData, Temp, Downloads) while loading specifically identified malicious or sideloaded DLLs. The detection identifies patterns where these binaries operate outside their expected vendor installation paths, indicating a likely attempt to hijack execution flow.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
This rule detects potential DLL sideloading activity where legitimate, signed binaries (such as COTFileReadApp.exe or DeElevate64.exe) are executed from non-standard directories (e.g., AppData, Temp, Downloads) while loading specifically identified malicious or sideloaded DLLs. The detection identifies patterns where these binaries operate outside their expected vendor installation paths, indicating a likely attempt to hijack execution flow.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
102
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
202
KQL Query from file: JivaChat Installer - Full Chain
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
202
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
202
Detects a file named dnsapi.dll created/modified outside System32/SysWOW64/WinSxS (the only legitimate locations for the real system DLL). Now requires the file to BOTH land in one of the known NeedyMantis sideload staging folders AND match the published 3448-byte spoofed-config size -- previously the size check alone could match unrelated dnsapi.dll copies anywhere on disk; requiring both signals together removes that bypass.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects a file named dnsapi.dll created/modified outside System32/SysWOW64/WinSxS (the only legitimate locations for the real system DLL). Now requires the file to BOTH land in one of the known NeedyMantis sideload staging folders AND match the published 3448-byte spoofed-config size -- previously the size check alone could match unrelated dnsapi.dll copies anywhere on disk; requiring both signals together removes that bypass.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
Detects a file named dnsapi.dll created/modified outside System32/SysWOW64/WinSxS (the only legitimate locations for the real system DLL). Now requires the file to BOTH land in one of the known NeedyMantis sideload staging folders AND match the published 3448-byte spoofed-config size -- previously the size check alone could match unrelated dnsapi.dll copies anywhere on disk; requiring both signals together removes that bypass.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects NeedyMantis' initial C2 beacon: an HTTP GET to /library/zip/ on port 443, anchored to the URI root, carrying a client-originated 'Set-Cookie:' header (clients normally send 'Cookie:', never 'Set-Cookie:' -- this direction reversal is the core anomaly and is near-impossible for legitimate traffic) alongside an explicit 'Upgrade: websocket' header. Matching the literal header text (not just header-name presence) and anchoring the URI removes generic WebSocket apps and any unrelated path containing '/library/zip/' as a substring.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects >=2 of the four NeedyMantis archive-extraction artifacts (encryptbase64.ps1, dnsapi.dll, ws2_32.dll, msvcrt140.dll) written by the same process within 60 seconds. Anchored to the known sideload staging directories (ProgramData/ProgramFiles subfolders used by the Poedit/curl/Vim/TightVNC/Office/Broadcom/Intel/NVIDIA-masquerading bundles) and excludes System32/SysWOW64, since ws2_32.dll and dnsapi.dll are legitimate system DLL names that would otherwise cause noise if matched by name alone anywhere on disk.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
Detects >=2 of the four NeedyMantis archive-extraction artifacts (encryptbase64.ps1, dnsapi.dll, ws2_32.dll, msvcrt140.dll) written by the same process within 60 seconds. Anchored to the known sideload staging directories (ProgramData/ProgramFiles subfolders used by the Poedit/curl/Vim/TightVNC/Office/Broadcom/Intel/NVIDIA-masquerading bundles) and excludes System32/SysWOW64, since ws2_32.dll and dnsapi.dll are legitimate system DLL names that would otherwise cause noise if matched by name alone anywhere on disk.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects >=2 of the four NeedyMantis archive-extraction artifacts (encryptbase64.ps1, dnsapi.dll, ws2_32.dll, msvcrt140.dll) written by the same process within 60 seconds. Anchored to the known sideload staging directories (ProgramData/ProgramFiles subfolders used by the Poedit/curl/Vim/TightVNC/Office/Broadcom/Intel/NVIDIA-masquerading bundles) and excludes System32/SysWOW64, since ws2_32.dll and dnsapi.dll are legitimate system DLL names that would otherwise cause noise if matched by name alone anywhere on disk.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000