Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
102
Detects the use of PowerShell to modify Windows Defender exclusions by adding the 'C:\' drive root as an exclusion path. This technique, which can be executed via 'Add-MpPreference', 'Set-MpPreference', or 'Invoke-CimMethod', effectively disables real-time scanning across the entire system drive and is often employed by adversaries to hide malicious activity from antivirus detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
102
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
Detects the execution of PowerShell or PowerShell ISE with command line arguments indicative of suspicious activity, such as the use of GZipStream for payload decompression, AesManaged for payload decryption, or in-memory assembly loading via Reflection.Assembly or EntryPoint.Invoke, often associated with fileless malware execution or obfuscated script runners.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the execution of WScript via a scheduled task named 'MicrosoftEdgeUpdateTaskCore'. This pattern is often used to masquerade malicious activity by using the name of a legitimate Microsoft Edge update process to execute scripts silently (using //B //Nologo).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects instances where WScript or CScript (Windows Script Host) initiate child processes like PowerShell or Conhost, specifically when those child processes contain command line arguments referencing environment variable access pattern 'GetEnvironmentVariable' for 'Kv' keys. This pattern is commonly associated with retrieving stored configuration or sensitive data using script-based wrappers to execute logic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
This rule detects potentially malicious behavior where common scripting processes such as PowerShell, WScript, or CScript interact with sensitive memory-related APIs (e.g., VirtualProtect, GetProcAddress, LoadLibrary) or monitor modules (amsi.dll, clr.dll). This pattern is often indicative of reflective loading, memory injection, or attempts to bypass security controls like AMSI.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the presence of PNG image files containing a specific steganographic marker embedded within the iTXt metadata chunk, often used by the LausivLoader malware for C2 communication or payload delivery. The rule looks for the specific marker 0xFF89AD4A or known C2 indicators (yapw.life, stego_zrgaixkku8.png) within PNG files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the presence of PNG image files containing a specific steganographic marker embedded within the iTXt metadata chunk, often used by the LausivLoader malware for C2 communication or payload delivery. The rule looks for the specific marker 0xFF89AD4A or known C2 indicators (yapw.life, stego_zrgaixkku8.png) within PNG files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
This rule detects unauthorized memory modification of ntdll.dll, specifically targeting the EtwEventWrite function, by identifying processes writing to memory regions with execution-permission flags (e.g., PAGE_EXECUTE_READWRITE). This behavior is characteristic of adversaries attempting to blind Event Tracing for Windows (ETW) telemetry, often following suspicious .NET assembly loading (such as Assembly.Load) typical of malware loaders like LausivLoader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects attempts to modify Microsoft Defender settings, such as adding file path exclusions via PowerShell, Registry manipulation, or Scheduled Tasks, as well as disabling Tamper Protection. These actions are commonly used by attackers to evade security monitoring by hiding malicious files or disabling protective features.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the creation, renaming, or modification of a file named 'FitnessMonitor.exe' within the Windows Startup folder. This behavior is indicative of an attempt to establish persistence by ensuring the executable runs automatically upon user login.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the addition of a 'DailyFitnessTracker' registry entry into the 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' key. This is a common persistence technique where programs are configured to execute automatically upon user login, utilizing either 'reg.exe' or PowerShell 'New-ItemProperty' to modify the registry.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the creation or renaming of files within the '\ProgramData\doxc' directory, and correlates this with the execution of 'mklink /H' commands that point to that directory. This behavior is indicative of an adversary establishing persistence or hiding files by creating hard links.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
This rule detects the execution of a command shell (cmd.exe) that is launched via or involving a batch file ('config.bat' or other .bat files), followed by the deletion of '.lnk' files. This pattern is commonly associated with cleanup activities performed by malicious scripts or malware attempting to remove traces or shortcuts after execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the creation or renaming of files within the '\ProgramData\doxc' directory, and correlates this with the execution of 'mklink /H' commands that point to that directory. This behavior is indicative of an adversary establishing persistence or hiding files by creating hard links.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Page 262 of 1871