Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects the execution of PowerShell or Command Prompt processes that attempt to bypass execution policies while performing file downloads from suspicious domains (mnl.ac) or IP addresses (149.255.35.135). It also flags the use of common web-request cmdlets (Invoke-WebRequest, IWR, DownloadString, DownloadFile) to fetch scripts named 'configuration.ps1'. The rule includes detection for obfuscated commands using caret (^) symbols often used to evade keyword-based security filters.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
This rule detects the execution of PowerShell or Command Prompt processes that attempt to bypass execution policies while performing file downloads from suspicious domains (mnl.ac) or IP addresses (149.255.35.135). It also flags the use of common web-request cmdlets (Invoke-WebRequest, IWR, DownloadString, DownloadFile) to fetch scripts named 'configuration.ps1'. The rule includes detection for obfuscated commands using caret (^) symbols often used to evade keyword-based security filters.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
102
Detects the creation or execution of script files (.lnk) within the Windows Startup folder initiated by script hosts (wscript.exe or cscript.exe) that contain suspicious command-line arguments indicative of malicious activity, such as PowerShell obfuscation or encoded commands.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
202
Detects the use of fsutil.exe to create a hardlink pointing to files within a user's AppData directory, specifically involving a folder named 'doxc'. This behavior is often associated with file manipulation to bypass security controls or masquerade malicious files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the use of cmd.exe to execute copy commands involving specific batch files (doxc.bat or config.bat) or suspicious file paths, which may indicate malicious file staging or automated data collection behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects behavior indicative of KRSID ransomware, characterized by mass file renaming to the .krsid extension and the creation of a 'ransomware-silent.Log' file. The detection specifically correlates this activity with the absence of vssadmin shadow copy deletion commands, which is an atypical behavior for most ransomware families, thereby serving as a distinguishing heuristic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects the use of PowerShell to perform recursive file/directory enumeration within sensitive user profile directories (Desktop, Documents, Downloads, Pictures, OneDrive) immediately followed by a network connection over port 443. This behavior is indicative of potential data staging and exfiltration activity performed by a malicious script or threat actor.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
101
Detects the presence of QuasarRAT-related processes combined with the creation of known log filenames associated with its keylogging functionality.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects persistence attempts via registry run key modifications or additions, specifically targeting the 'DailyFitnessTracker' value. The rule monitors both direct registry operations (value setting, key creation) and process-based modifications performed by reg.exe or PowerShell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
001
Detects attempts to clear Windows event logs using administrative tools like wevtutil.exe, PowerShell, or through the detection of mass log-clear audit events (such as Event IDs 1102 and 104) occurring in a rapid burst. This activity is often used by adversaries to hide evidence of post-compromise actions.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
22 days ago
102
Detects attempts to clear Windows event logs using administrative tools like wevtutil.exe, PowerShell, or through the detection of mass log-clear audit events (such as Event IDs 1102 and 104) occurring in a rapid burst. This activity is often used by adversaries to hide evidence of post-compromise actions.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
22 days ago
102
Detects the loading of the 'gdrv.sys' driver, which is a known vulnerable driver often used in 'Bring Your Own Vulnerable Driver' (BYOVD) attacks to facilitate privilege escalation to kernel mode.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
22 days ago
702
This rule detects potential ransomware activity by correlating three distinct events: the execution of a suspicious, potentially obfuscated binary (matching a specific naming pattern of _win64.exe) from an untrusted location (e.g., Temp, AppData, Downloads), followed by a high volume of file modifications or renames with specific ransomware-related extensions (.locked), and the dropping of a known ransom note file (RESTORE_FILES.txt) within a short 15-minute time window.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
This rule detects potential ransomware activity by correlating three distinct events: the execution of a suspicious, potentially obfuscated binary (matching a specific naming pattern of _win64.exe) from an untrusted location (e.g., Temp, AppData, Downloads), followed by a high volume of file modifications or renames with specific ransomware-related extensions (.locked), and the dropping of a known ransom note file (RESTORE_FILES.txt) within a short 15-minute time window.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule detects the presence, installation, or execution attempts of the known vulnerable GIGABYTE driver (gdrv.sys). Monitoring for this specific driver is a common practice to identify attempts to perform 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, which can be used for kernel-mode code execution and privilege escalation.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule detects the presence, installation, or execution attempts of the known vulnerable GIGABYTE driver (gdrv.sys). Monitoring for this specific driver is a common practice to identify attempts to perform 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, which can be used for kernel-mode code execution and privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects host-enumeration activities performed by PowerShell processes, including anti-virus queries, system information gathering, network configuration checks, and file/drive enumeration, specifically when correlated with suspicious outbound network connections to common task-runner C2 infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Detects a sequence of PowerShell commands consistent with the VelvetCake reconnaissance module, including enumeration of antivirus software via SecurityCenter2, system information, IP configurations, running processes, recent files, and drive mapping within a short timeframe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Detects instances where the Zoom installer process (zoominstaller.exe) initiates potentially suspicious child processes such as cmd.exe, powershell.exe, or scripting hosts (wscript.exe, cscript.exe) that are executing script files within a short timeframe. This behavior is indicative of a potential installer hijack or malicious payload execution attempting to leverage the context of a legitimate software installer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Detects a sequence of PowerShell commands consistent with the VelvetCake reconnaissance module, including enumeration of antivirus software via SecurityCenter2, system information, IP configurations, running processes, recent files, and drive mapping within a short timeframe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Detects a multi-stage malware execution pattern consistent with VelvetCake activity. This includes staging text-based files in C:\Users\Public, downloading PowerShell scripts to temporary directories, executing the script via PowerShell, and subsequently deleting both the staged text files (except for specific allowed filenames) and the payload script.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Page 265 of 1871