Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
102
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
000
Detects a potential destructive activity pattern involving the staging of a payload in a non-standard directory (utilizing a directory name with a trailing space) followed by a burst of file deletions on the same device. This behavior is indicative of a secondary destructive payload execution, often associated with disk-wiping malware.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
000
Detects a potential destructive activity pattern involving the staging of a payload in a non-standard directory (utilizing a directory name with a trailing space) followed by a burst of file deletions on the same device. This behavior is indicative of a secondary destructive payload execution, often associated with disk-wiping malware.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
000
Detects a suspicious sequence of activity involving persistence via Registry Run keys (specifically targeting SMQDService or winappx entries) followed by modifications to Microsoft Defender configuration (adding exclusions via PowerShell) within a two-hour window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
000
Detects a suspicious sequence of activity involving persistence via Registry Run keys (specifically targeting SMQDService or winappx entries) followed by modifications to Microsoft Defender configuration (adding exclusions via PowerShell) within a two-hour window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
000
This rule detects modifications to Windows 'Run' registry keys, specifically monitoring for the creation or value setting of keys associated with known suspicious or persistence-related names such as 'SMQDService' or 'winappx'. These registry keys are frequently used by attackers to maintain persistence by ensuring malicious code executes automatically upon user login.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
18 days ago
000
This rule detects modifications to Windows 'Run' registry keys, specifically monitoring for the creation or value setting of keys associated with known suspicious or persistence-related names such as 'SMQDService' or 'winappx'. These registry keys are frequently used by attackers to maintain persistence by ensuring malicious code executes automatically upon user login.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
000
This rule detects modifications to Windows 'Run' registry keys, specifically monitoring for the creation or value setting of keys associated with known suspicious or persistence-related names such as 'SMQDService' or 'winappx'. These registry keys are frequently used by attackers to maintain persistence by ensuring malicious code executes automatically upon user login.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
18 days ago
000
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
000
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
This rule detects outbound network connections from processes to known public cloud object storage providers (vultrobjects.com, storjshare.io, backblazeb2.com). These domains have been associated with the 'CHOSEN BRICK' threat actor's secondary data exfiltration paths for stolen assets such as screenshots, audio, and browser/email data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
This rule detects modifications to Windows 'Run' registry keys, specifically monitoring for the creation or value setting of keys associated with known suspicious or persistence-related names such as 'SMQDService' or 'winappx'. These registry keys are frequently used by attackers to maintain persistence by ensuring malicious code executes automatically upon user login.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects a suspicious sequence of activity involving persistence via Registry Run keys (specifically targeting SMQDService or winappx entries) followed by modifications to Microsoft Defender configuration (adding exclusions via PowerShell) within a two-hour window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects a potential destructive activity pattern involving the staging of a payload in a non-standard directory (utilizing a directory name with a trailing space) followed by a burst of file deletions on the same device. This behavior is indicative of a secondary destructive payload execution, often associated with disk-wiping malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects the creation of specific mutexes associated with the CHOSEN BRICK malware shortly after establishing persistence via Windows Run registry keys. This behavior indicates a potentially malicious process initializing its single-instance guardrail on a compromised host.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects files written to a non-standard path containing a deliberate trailing space after 'Windows' (e.g., 'C:\Windows \SysWOW64') combined with the creation of a registry run key for persistence. This pattern is associated with the CHOSEN BRICK threat activity to hide and maintain persistence for secondary payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Detects specific malicious processes (smdqservice.exe, winappx.exe) or suspicious paths associated with the CHOSEN BRICK malware suite writing image files (png, jpg, jpeg, bmp) to sensitive system directories. This activity typically precedes the exfiltration of sensitive desktop capture data to C2 infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
This rule detects the addition of Microsoft Defender exclusions via PowerShell cmdlets (Add-MpPreference, Set-MpPreference) or direct Registry key modifications, occurring within two hours of a new autorun persistence entry being created on the same device. This behavior is indicative of a persistence-then-evasion sequence often used to ensure malicious tools remain undetected.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
000
Page 284 of 1871