Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
IOC sweep against network telemetry for confirmed BengalSEO/MayaBot campaign infrastructure: the Hostmaza backend IP (5.101.140.80), Matomo tracking domains (stats.us3.org, us3.my), named MayaBot C2 domains (cus.cam, dll.lat, us99.org), and the ~170-domain Traffic Distribution System redirector fleet used to funnel victims to payload delivery. The source intel report contains no file hashes (MD5/SHA1/SHA256) -- only IPs, domains, and URLs -- so this sweep is IP/domain-only. Note the much larger corpus of single-use lure-page domains (~1,000 additional indicators) is excluded as too high-churn for static embedding.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
IOC sweep against network telemetry for confirmed BengalSEO/MayaBot campaign infrastructure: the Hostmaza backend IP (5.101.140.80), Matomo tracking domains (stats.us3.org, us3.my), named MayaBot C2 domains (cus.cam, dll.lat, us99.org), and the ~170-domain Traffic Distribution System redirector fleet used to funnel victims to payload delivery. The source intel report contains no file hashes (MD5/SHA1/SHA256) -- only IPs, domains, and URLs -- so this sweep is IP/domain-only. Note the much larger corpus of single-use lure-page domains (~1,000 additional indicators) is excluded as too high-churn for static embedding.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
IOC sweep against network telemetry for confirmed BengalSEO/MayaBot campaign infrastructure: the Hostmaza backend IP (5.101.140.80), Matomo tracking domains (stats.us3.org, us3.my), named MayaBot C2 domains (cus.cam, dll.lat, us99.org), and the ~170-domain Traffic Distribution System redirector fleet used to funnel victims to payload delivery. The source intel report contains no file hashes (MD5/SHA1/SHA256) -- only IPs, domains, and URLs -- so this sweep is IP/domain-only. Note the much larger corpus of single-use lure-page domains (~1,000 additional indicators) is excluded as too high-churn for static embedding.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects the use of rundll32.exe to execute comsvcs.dll's MiniDump functionality against the LSASS process, a common technique for dumping credentials. The rule includes behavioral correlation by identifying the same user account executing this pattern on multiple devices within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects the use of rundll32.exe to execute comsvcs.dll's MiniDump functionality against the LSASS process, a common technique for dumping credentials. The rule includes behavioral correlation by identifying the same user account executing this pattern on multiple devices within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects a potential process hollowing technique where 'Finalized.dll' (loaded from unconventional locations like a ComponentsFolder or System32) is used to spawn 'clspack.exe' in a suspended state from a non-standard path (e.g., AppData\Microsoft). This sequence indicates an attempt to mask malicious execution under a legitimate process name.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
IOC hunt for the HEAVYGRAM/CRUDEEXCLUDE campaign: matches known SHA256 file hashes (first-stage malware, implant, RAR/ZIP artefacts) via DeviceFileEvents and DeviceProcessEvents, plus known-malicious domains/staging infrastructure by parsed hostname across network connections, process command lines, and file origin URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
208
Detects activity associated with the 'BlueKit' session relay tool, which uses the rrweb library to capture and replay user session interactions. This rule identifies web browser network events involving rrweb-related scripts occurring within 10 minutes of a successful user sign-in, indicating a potential Adversary-in-the-Middle (AiTM) phishing attack where credentials and session cookies are being captured.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
002
Detects attempts to modify, disable, or query Microsoft Defender configuration settings or status using legitimate Windows management tools (PowerShell/WMI) by processes other than authorized Defender executables (MsMpEng.exe, MpCmdRun.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
106
This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
102
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002