Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
002
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects instances where a process named msedge.exe is running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a common location used by attackers to hide malicious executables by masquerading them as legitimate browser processes, particularly when the process command line includes arguments like 'preview' or 'thumbnail' which are often used to blend in with background system activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects instances where a process named msedge.exe is running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a common location used by attackers to hide malicious executables by masquerading them as legitimate browser processes, particularly when the process command line includes arguments like 'preview' or 'thumbnail' which are often used to blend in with background system activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects instances where a process named msedge.exe is running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a common location used by attackers to hide malicious executables by masquerading them as legitimate browser processes, particularly when the process command line includes arguments like 'preview' or 'thumbnail' which are often used to blend in with background system activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Page 273 of 1871