Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation of a scheduled task using 'schtasks.exe' configured to run as the SYSTEM account for a one-time execution. This behavior is often associated with persistence mechanisms or privilege escalation attempts where an adversary seeks to execute malicious code in a high-privileged context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule detects the use of 'taskkill.exe' to terminate critical services, including security software (MsMpEng.exe), database processes (sql.exe, oracle.exe, sqlservr.exe), and common user applications (outlook.exe, onedrive.exe). This behavior is characteristic of the DragonForce ransomware, which disables protective services and applications before encryption to minimize interference and ensure successful file locking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects unauthorized modification of the registry path 'HKCU\Software\Classes\ms-settings\Shell\Open\command'. This registry key is commonly hijacked by the 'fodhelper.exe' UAC bypass technique, where an attacker writes a malicious command to be executed with elevated privileges when the OS triggers the ms-settings protocol handler.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the CRPx0 ransomware technique of unhooking ntdll.dll in memory. This is achieved by reading the ntdll.dll file from disk and overwriting the in-memory .text section with a clean, unhooked version to bypass EDR monitoring and execute direct syscalls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects modifications to the Windows RunMRU registry key that include suspicious strings such as 'powershell', 'curl', or long base64-encoded sequences. This behavior is indicative of the 'ClickFix' technique, where users are socially engineered to paste and execute malicious commands directly into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of PowerShell encoded commands that result in the installation of known remote monitoring and management (RMM) software. This pattern is indicative of attackers, specifically those associated with Ransom Busters or similar affiliates, establishing persistent remote access to compromised systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the creation of a Windows scheduled task configured to execute as the SYSTEM account using a one-time execution trigger. This combination is frequently used by adversaries for post-exploitation activities, such as lateral movement or persistence, as it allows for a single, immediate execution of a malicious payload with high-level privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of the SoftPerfect Network Scanner tool (netscan.exe), which is often used by adversaries for reconnaissance to identify active hosts, open ports, and services within a network.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the termination of critical processes, including security software (MsMpEng.exe), database services (sql.exe, oracle.exe, sqlservr.exe), and office productivity applications (excel.exe, outlook.exe, winword.exe). The sudden termination of these processes can indicate unauthorized attempts to disable security controls, disrupt database operations, or interfere with end-user activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects files containing specific structural footers (537 bytes) and RSA key generation strings commonly associated with ransomware encryption. The footer indicates the use of RSA-4096 to encrypt files, with modes for full, striped, or header-only encryption patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule monitors Microsoft Teams communications for keywords related to passkey or Single Sign-On (SSO) configuration, which are common themes in social engineering and credential harvesting attacks. It correlates these messages with Windows logon events (Event ID 4624) for the sender to identify potentially compromised accounts or active phishing attempts originating from within the environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects DNS resolution requests for graph.microsoft.com initiated by a python interpreter (python.exe, python3.exe, or pythonw.exe). This activity may indicate a script or custom tool communicating with Microsoft Graph API, which is frequently used for data collection, exfiltration, or cloud service interaction in adversarial campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects DNS resolution requests to 'graph.microsoft.com' on endpoint devices. This is intended to act as a precursor indicator for potential Microsoft 365 or Azure environment enumeration and discovery activities, which would typically involve subsequent API calls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Page 272 of 1871