Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where AI coding assistants (such as Claude, Copilot, or Gemini) are used as parent processes to execute specific git commands, including 'git rev-parse HEAD' or 'git checkout'. This can indicate automated or adversary-driven repository interaction initiated by an AI tool, potentially for source code theft, reconnaissance, or malicious automation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of PowerShell with encoded commands that are unusually long (over 300 characters). Adversaries often use Base64 encoding to obfuscate malicious PowerShell scripts, and long encoded strings are a strong indicator of non-interactive or automated command execution, such as during the initial stage of an attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
102
This rule detects suspicious process injection activity directed at Chrome or Edge browser processes, followed immediately by file access to sensitive browser data files like 'Login Data' or 'Cookies'. This pattern is indicative of an adversary attempting to steal credentials or session cookies from a user's web browser memory and disk storage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of diskpart.exe with command-line arguments using the /s flag, triggered by processes originating from unconventional locations such as Perflogs or Documents, or by executables ending with _win64.exe. Diskpart is a command-line disk partitioning utility that can be abused for credential dumping, data staging, or destructive activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects suspicious Git activity or file modifications within the plugin directories of various AI coding assistants (such as Claude, Codex, Copilot, or Gemini). This may indicate an attempt to inject malicious code or persistence mechanisms into the local environment via untrusted plugins.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of the 'wevtutil.exe' utility to clear Windows Event Logs. This is a common technique used by adversaries to disrupt logging and evade detection of their actions on a host. The rule specifically monitors for the 'cl' (clear-log) command applied to sensitive operational channels, triggering when multiple clearing operations are detected within a 5-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects instances where Windows Explorer (explorer.exe) spawns PowerShell with heavily obfuscated command lines, characterized by caret-obfuscation and execution policy bypass flags. This pattern is characteristic of ClickFix social engineering, where a user is tricked into pasting malicious commands into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
202
This rule detects PowerShell command lines that include .NET API calls typically used for anti-debugging and anti-analysis evasion, such as 'Debugger.IsAttached', 'Debugger.IsLogging', 'CheckRemoteDebuggerPresent', and 'Environment.FailFast'. These checks are common in malicious loaders and implants to determine if the process is being analyzed or monitored, allowing the malware to modify its behavior accordingly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of the [Reflection.Assembly]::Load method within PowerShell command lines. This method is often abused by attackers to reflectively load malicious .NET assemblies directly into memory, bypassing disk-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the creation of a .lnk shortcut file within the Windows Startup folder, which is a common persistence mechanism. The detection logic also flags the usage of WScript.Shell and CreateShortcut methods, which are frequently abused by scripts (e.g., VBScript or PowerShell) to programmatically establish this persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of PowerShell commands that perform decryption (AES-256-CBC) and decompression (Gzip) of data, followed by the reflective loading of a .NET assembly into memory using [Reflection.Assembly]::Load. This behavior is indicative of fileless malware execution where a payload is hidden in an obfuscated or compressed format and unpacked at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects unauthorized processes attempting to access sensitive browser files, including Login Data (passwords) and Network/Cookies databases for Chrome, Edge, and Firefox. These files are primary targets for credential dumping and session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of the native Windows utility cipher.exe with the /w flag. This command is designed to overwrite free disk space with random data to sanitize it and make previously deleted files irrecoverable. While this is a legitimate administrative feature, adversaries may utilize it as a form of anti-forensics or to perform data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of the native Windows utility cipher.exe with the /w flag. This command is designed to overwrite free disk space with random data to sanitize it and make previously deleted files irrecoverable. While this is a legitimate administrative feature, adversaries may utilize it as a form of anti-forensics or to perform data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of the 'reagentc.exe' utility with the '/disable' argument. This command is used to disable the Windows Recovery Environment (WinRE), which is a common post-compromise activity performed by ransomware and other malware to prevent system recovery and hinder incident response efforts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects instances of PowerShell being launched directly from Windows Explorer (explorer.exe) using suspicious command-line arguments. This pattern is commonly associated with malicious scripts, remote access trojans, or fileless execution techniques where an adversary executes code through shell-based file interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
302
Detects the execution of the Windows cipher.exe utility with the /w flag, which is used to overwrite deleted data on a disk to prevent forensic recovery. This is a common technique used by adversaries to perform data destruction or cover their tracks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
102
Detects the execution of 'reagentc.exe' with the '/disable' flag, which is used to disable the Windows Recovery Environment (WinRE). Adversaries often perform this action as part of an attempt to inhibit system recovery during ransomware operations or other destructive attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
202
Detects obfuscated PowerShell commands bypassing execution policy to download or execute 'configuration.ps1' or communicate with known malicious infrastructure associated with the ClickFix campaign. The rule specifically looks for caret-based obfuscation, bypass switches, and known IOCs in the command line.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects instances where PowerShell attempts to inject code into legitimate processes (such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe) using direct syscalls NtAllocateVirtualMemoryRemote or NtSetContextThreadRemote, indicating potential process injection activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of the Windows cipher.exe utility with the /w flag, which is used to overwrite free space on a volume to permanently delete data, a common technique for anti-forensics and data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Page 260 of 1871