Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of common command-line utilities used for network reconnaissance and discovery, such as arp, nbtstat, net, and ping. These commands are frequently used by adversaries to map network infrastructure, identify active hosts, and discover shared resources on a target network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects execution of command-line tools (cmd.exe or .bat files) triggered by Windows Explorer, where the process command line or parent command line references a shortcut (.lnk) file or specific naming conventions like 'doxc.bat' or 'config.bat'. This pattern is frequently used in phishing attacks to execute malicious payloads disguised as legitimate files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
This rule detects unauthorized persistence attempts by monitoring for the creation of a registry value named 'DailyFitnessTracker' under the HKEY_CURRENT_USER Run key. It triggers when 'reg.exe' is used to add the key, PowerShell is used to set the registry property, or when a general registry event indicates the creation of this specific key. This behavior is indicative of a persistence mechanism designed to launch a potentially malicious or unwanted program upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the creation of hard links on a Windows system using utilities such as mklink or fsutil. Specifically, this rule identifies scenarios where a malicious executable located in %APPDATA% is linked to a backdoor binary stored in C:\ProgramData\, a technique used by adversaries to mask the true file path and evade security controls or detection mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
201
Detects the creation of files within the 'SystemFolder32' or 'System Folder32' directory under the user's Local AppData path, a known behavioral pattern for payload staging used by the Transparent Tribe threat actor.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects instances where Windows Explorer spawns cmd.exe to execute specific batch files (doxc.bat or config.bat), a behavior often associated with Transparent Tribe (APT36) activity involving malicious LNK shortcuts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that masquerade as legitimate Microsoft Edge or OneDrive update tasks. This behavior is associated with APT36 (Transparent Tribe) and their use of modular malware to establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects malicious scheduled task creation using names associated with Microsoft Edge updates, or the execution of PowerShell commands that utilize encoded arguments and known APT36 download cradles, indicating an attempt to establish persistence or retrieve secondary payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects malicious scheduled task creation using names associated with Microsoft Edge updates, or the execution of PowerShell commands that utilize encoded arguments and known APT36 download cradles, indicating an attempt to establish persistence or retrieve secondary payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects network discovery activities including ICMP sweeps, ARP cache checks, and SMB share/session enumeration, which are common tactics used for internal reconnaissance by the threat group APT36 (Transparent Tribe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the creation of hard links using 'mklink /H' targeting specific paths in ProgramData or linking to specific executable paths in AppData. This behavior is often indicative of adversaries attempting to perform file system manipulation for persistence, defense evasion, or masquerading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
This rule detects the execution of RUSTYMOVE, a tool associated with the Transparent Tribe (APT36) threat group, which is used for propagation via removable media. It monitors for the specific executable 'Automata-20.exe', the presence of specific task-related command line arguments, the dropping of suspicious file paths, and PowerShell-based enumeration of connected USB/removable drives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the execution of the RUSTYSHADE Rust-based backdoor, observed during Operation RapidRust, associated with the threat group APT36 (Transparent Tribe). The rule monitors for the specific 'DriverInstaller.exe' filename, known malicious file hashes, and suspicious command-line patterns involving PowerShell-based downloads of 'DriverInstaller.zip' from Backblaze cloud storage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the addition of a 'DailyFitnessTracker' entry to the HKCU Windows Registry Run key, which is a technique used by Golang-based RATs to establish persistence. The rule monitors both 'reg.exe' command-line operations and PowerShell 'New-ItemProperty' cmdlets targeting this specific registry path.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the execution of HTSPnew.Exe with specific command-line arguments indicative of KRSID ransomware operations, such as configuration flags for paths, batch processing, and dry-run modes. The use of these flags with this specific executable name is a strong indicator of malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the creation of files with the name 'README_KRSID.Txt', which is a hallmark behavior of the KRSID ransomware strain used to leave ransom notes on compromised systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
Page 264 of 1871