Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects evidence of the Alinubx.sys kernel driver being loaded or interacted with via its device interface using a specific IOCTL (0x222024). This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, effectively bypassing Windows Protected Process Light (PPL) protections.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects anomalous behavior within a Chrome renderer process involving the acquisition of SeDebugPrivilege, preceded by ALPC, WNF, or reflective DLL loading activities. This pattern is indicative of the BlueMoon (CVE-2026-85880) kernel privilege escalation exploit chain, where a compromised low-integrity renderer leverages kernel vulnerabilities to gain elevated privileges.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
7016
This rule detects the execution of 'vsdbg.exe', the Visual Studio Remote Debugger, from non-standard directories (e.g., Downloads, AppData, Temp, ProgramData) or in conjunction with the creation of 'vsdbg.dll' files. Adversaries may utilize this debugger for remote code execution or to bypass security controls by masquerading as a legitimate development tool.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
This rule detects successful logon events (Event ID 4624) or special logon events (Event ID 4648) with specific logon types (7: NetworkCleartext, 8: NewCredentials, 9: Network, 11: CachedInteractive) that occur within 24 hours of a user registration event on the same host. This pattern may indicate suspicious account usage shortly after account creation or registration on a device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of known Living-off-the-Land Binaries (LOLBins) such as finger.exe or curl.exe that are spawned by common Windows processes like explorer.exe or RuntimeBroker.exe. This behavior is often associated with adversaries attempting to download malicious payloads or stage tools within the environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
This rule detects the potential use of parent process spoofing (PPID spoofing) where a PowerShell process is spawned with 'explorer.exe' as its parent. This technique, often executed via the 'PROC_THREAD_ATTRIBUTE_PARENT_PROCESS' attribute in a 'CreateProcessW' call, is used by adversaries to mask the true origin of the PowerShell process and evade behavioral detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects post-exploitation shell activity spawned from the IIS worker process (w3wp.exe), narrowed to command lines carrying encoded/obfuscated PowerShell flags, remote-download cradles, or basic recon/persistence commands (whoami, certutil, bitsadmin, schtasks, reg add). This reduces noise from benign w3wp.exe-initiated automation while retaining the behavioral pattern seen in the Telerik UI for ASP.NET AJAX unauthenticated RCE chain (webshell/in-memory DLL execution dropping to a shell).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
305
Detects unauthorized access attempts to browser credential files (such as Login Data, key4.db, and cookies) by non-browser processes. This behavior is indicative of the Rapuncel infostealer, which harvests stored browser credentials after attempting to disable or bypass security solutions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects unauthorized access attempts to browser credential files (such as Login Data, key4.db, and cookies) by non-browser processes. This behavior is indicative of the Rapuncel infostealer, which harvests stored browser credentials after attempting to disable or bypass security solutions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the ClickFix social-engineering pattern where a user is tricked into pasting and executing a command, typically via the Windows Run dialog (explorer.exe), that triggers the command shell (cmd.exe or powershell.exe) to utilize finger.exe or curl.exe for downloading and staging malicious payloads like CastleRAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects unauthorized access to critical browser files such as cookies, login data, and local state files. These files contain sensitive information such as authentication cookies and stored credentials, which are primary targets for infostealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
101
Detects the execution of curl.exe by various script interpreters (cmd.exe, powershell.exe, wscript.exe, mshta.exe) or Windows Explorer. This pattern is commonly used by adversaries to download malicious payloads or intermediate loaders as part of an attack chain, such as deploying CastleLoader/CastleRAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the presence of the CastleLoader intermediate loader binary on disk, associated with the SloppyRAT infection chain. The rule identifies specific file content patterns, including hardcoded strings such as 'CastleLoader', 'CastleRAT', specific user-agents, and embedded Python code used for base64/zlib decoding of further payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the CastleRAT intermediate loader, which acts as a secondary stage before deploying SloppyRAT. The rule identifies the malicious payload by scanning for unique embedded strings, specific user-agent strings, and command-and-control (C2) communication patterns (domains and URI paths) within executable files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the loading or presence of the Alinubx.sys kernel driver, a malicious component used for Bring Your Own Vulnerable Driver (BYOVD) attacks. This driver facilitates the mass termination of security product processes (AV/EDR) by exposing a specific IOCTL (0x222024) to interface with kernel-mode process termination primitives (e.g., ZwTerminateProcess), often serving as a precursor to the deployment of stealers like Rapuncel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
701
Detects suspicious PE files that masquerade as Mozilla Firefox by using Firefox-related product names and metadata, but lack valid Mozilla Corporation code-signing signatures and are located within the ProgramData directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
This rule detects modifications to the Windows hosts file by unauthorized processes. The hosts file is often targeted by adversaries to redirect network traffic, intercept communications, or prevent access to security-related websites.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the use of PowerShell commands that reflectively load assemblies into memory, often associated with obfuscated or encoded payloads typically used in fileless malware execution and post-exploitation activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects the execution of PowerShell commands intended to gather system information, specifically targeting the discovery of security software (anti-virus/EDR) and virtualization/sandbox artifacts. This behavior is indicative of an attacker performing environment reconnaissance to identify defensive controls or to determine if the payload is executing within an analysis environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
102
Detects the execution of an LNK file that initiates a command chain resulting in an encoded PowerShell script. This behavior is indicative of malicious shortcut files often used in initial access to trigger multi-stage payloads, consistent with techniques observed in Kimsuky-linked infection chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
102
Detects the execution of a .lnk file that directly triggers a PowerShell process. This behavior is frequently associated with malicious shortcut files used in initial access and execution, such as those observed in Kimsuky (APT-C-55) infection chains where disguised installers drop LNK files that execute PowerShell scripts for anti-analysis and subsequent payload deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Page 277 of 1871