Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects >=2 of the four NeedyMantis archive-extraction artifacts (encryptbase64.ps1, dnsapi.dll, ws2_32.dll, msvcrt140.dll) written by the same process within 60 seconds. Anchored to the known sideload staging directories (ProgramData/ProgramFiles subfolders used by the Poedit/curl/Vim/TightVNC/Office/Broadcom/Intel/NVIDIA-masquerading bundles) and excludes System32/SysWOW64, since ws2_32.dll and dnsapi.dll are legitimate system DLL names that would otherwise cause noise if matched by name alone anywhere on disk.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects the NeedyMantis main-component handshake: an HTTP GET to port 443 with a User-Agent that is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end) and an explicit 'Upgrade: websocket' header, marking the HTTPS-to-WebSocket protocol switch used before the RC4 key exchange. Restricting to port 443 and requiring an exact (not substring) UA match removes generic WebSocket apps and any traffic where 'firefox/21.0' merely appears inside a real, longer browser UA string.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects the NeedyMantis main-component handshake: an HTTP GET to port 443 with a User-Agent that is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end) and an explicit 'Upgrade: websocket' header, marking the HTTPS-to-WebSocket protocol switch used before the RC4 key exchange. Restricting to port 443 and requiring an exact (not substring) UA match removes generic WebSocket apps and any traffic where 'firefox/21.0' merely appears inside a real, longer browser UA string.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Detects the NeedyMantis main-component handshake: an HTTP GET to port 443 with a User-Agent that is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end) and an explicit 'Upgrade: websocket' header, marking the HTTPS-to-WebSocket protocol switch used before the RC4 key exchange. Restricting to port 443 and requiring an exact (not substring) UA match removes generic WebSocket apps and any traffic where 'firefox/21.0' merely appears inside a real, longer browser UA string.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects egress to the NeedyMantis C2 domain corp.tripswithengine[.]com across three vantage points: TLS SNI (port 443), DNS resolution, and HTTP Host header. Each content match is anchored to the start of its buffer ('startswith') so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') cannot match — only this exact domain or a genuine subdomain of it triggers.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects egress to the NeedyMantis C2 domain corp.tripswithengine[.]com across three vantage points: TLS SNI (port 443), DNS resolution, and HTTP Host header. Each content match is anchored to the start of its buffer ('startswith') so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') cannot match — only this exact domain or a genuine subdomain of it triggers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects egress to the NeedyMantis C2 domain corp.tripswithengine[.]com across three vantage points: TLS SNI (port 443), DNS resolution, and HTTP Host header. Each content match is anchored to the start of its buffer ('startswith') so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') cannot match — only this exact domain or a genuine subdomain of it triggers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000