Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
102
Detects the use of tasklist.exe combined with process filtering (findstr) to identify common debugger names such as 'dbg.exe', 'x64dbg.exe', 'windbg.exe', or 'ollydbg.exe'. This technique is a known evasion tactic employed by the Kimsuky threat group (and others) to check for the presence of analysis tools before continuing execution of malicious batch scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the creation of a scheduled task named 'OneDrive KeepAlive' or a task set to execute every 5 minutes, in conjunction with the execution of 'taskhostw.exe' containing 'exec hide' in its command line. This pattern is indicative of the Kimsuky threat group using a renamed version of the NirCmd utility to maintain persistence and execute commands silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the suspicious copying of the Windows certutil.exe binary to an alternate location (e.g., /Users/Public/Downloads/) followed by execution with decoding or caching flags. This behavior is indicative of an adversary attempting to use certutil as a LOLBin to decode or reassemble malicious payloads, a tactic frequently observed in Kimsuky-related LNK malware campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects unauthorized access to common browser credential and cookie files by processes other than standard web browsers. This activity is a common indicator of credential harvesting malware or unauthorized data collection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects PowerShell command execution containing specific strings associated with the Veil framework XOR decoding routine, including a hardcoded key and the use of the -bxor operator for payload deobfuscation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects instances where WScript.exe or CScript.exe spawn PowerShell.exe as a child process. The rule specifically looks for command-line arguments indicative of policy bypass (-ExecutionPolicy Bypass) and remote payload retrieval (Invoke-WebRequest, DownloadString), which is a common pattern in obfuscated JavaScript-based infection chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the use of .NET reflection APIs (specifically System.Reflection.Assembly::Load) within PowerShell script blocks. This technique allows for the dynamic loading of .NET assemblies into memory, often to execute obfuscated or encrypted payloads without writing them to disk, which is a common tactic for bypassing file-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the use of PowerShell Stop-Process being used to terminate common scripting and .NET-related processes, a behavior associated with the Veil#Drop loader to clear potential conflicts or interference from legitimate host processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the use of [ScriptBlock]::Create() within PowerShell command lines. This method allows for the dynamic construction and execution of arbitrary PowerShell code entirely in memory, a technique often used by fileless malware and frameworks like Veil#Drop to evade disk-based detection mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the potential creation or execution of malicious JavaScript files that masquerade as PDF or other common documents using double extensions (e.g., .pdf.js). This behavior is often associated with file-based loaders where the operating system masks the true file extension. The rule also triggers when these files are explicitly launched via Windows Script Host (wscript.exe or cscript.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule aggregates vulnerability data from Microsoft Defender for Endpoint (Threat and Vulnerability Management) over the last 7 days. It groups vulnerable devices by CVE ID and severity level, providing an overview of known software weaknesses currently present across the fleet.
avatar
Ali AlEnezi@site
avatar
Detections.ai Community
26 days ago
305
Detects the presence of a specific malicious _socket.pyd Python module associated with LegionLoader dropped into non-standard directories like 'Traiolx Custom Utils'. The detection leverages file path patterns and known file hashes of the malicious component.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the execution of mshta.exe with command-line arguments that reference VLC-themed filenames or presentations. This behavior is indicative of a malicious HTA file being used as a lure to drop the Lightlife RAT loader, leveraging the mshta.exe utility to bypass standard application execution controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects modifications to Windows Registry Run keys that execute PowerShell scripts named 'Update.ps1' with hidden window and bypass execution policy flags. This pattern is consistent with Lightlife RAT persistence mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the execution of PowerShell with a combination of flags commonly used to hide malicious activity: -NoProfile, -WindowStyle Hidden, and -EncodedCommand. This combination is frequently used by adversaries to execute obfuscated code silently, bypassing user visibility and script analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the execution of wscript.exe as a child process of mshta.exe, specifically when the wscript.exe command line contains references to .vbs or .js files. This behavioral pattern is often associated with malicious HTA files using mshta.exe as a proxy to execute secondary script payloads, a technique commonly leveraged for initial access and execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects PowerShell execution commands attempting to disable Antimalware Scan Interface (AMSI) by reflectively accessing System.Management.Automation.AmsiUtils. This is a common technique used by attackers to execute malicious scripts while avoiding detection by security software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the execution of the Lightlife RAT via a PowerShell script named 'lightlife.ps1'. The rule monitors for processes running from the LOCALAPPDATA directory, the use of PowerShell with execution policy bypass and hidden window style, or execution triggered via common scripting hosts like wscript.exe or mshta.exe combined with PowerShell download cmdlets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects Python compiled bytecode (.pyc) files that have been renamed to .cat, a common Windows Security Catalog extension. This is a masquerading technique often used by backdoors to evade detection and facilitate malicious loader execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the registration of the gitlab-runner Windows service as a custom Event Log provider under the Application registry key. This registry modification occurs during the installation of the GitLab Runner service. When observed on endpoints not intended for CI/CD operations, this activity may indicate an adversary is installing a GitLab Runner for use as a C2 implant.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Page 283 of 1871