Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of AutoIt3 scripts using mshta.exe as the parent process from suspicious or non-standard directories such as Temp, Downloads, or AppData. This behavior is indicative of an attempt to bypass application execution policies or obfuscate malicious script execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects potential process injection attempts by unidentified executable files originating from suspicious directories (AppData or Temp) targeting critical system or service processes (e.g., explorer.exe, svchost.exe). The rule monitors CreateRemoteThread events and excludes signed dotnet host processes, characteristic of Hannibal Stealer behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects instances where a process other than the legitimate Firefox browser executable loads the NSS (Network Security Services) libraries nss3.dll or mozglue.dll from the Firefox installation directory. This behavior is indicative of unauthorized attempts to decrypt saved browser credentials by interacting with Firefox-specific security modules, a technique commonly used by credential-stealing malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the presence of configuration markers associated with cryptocurrency clipboard-swapping malware. The rule monitors process command lines for specific flags (e.g., 'cclipper', 'clipboard_check_delay') and cryptocurrency wallet address dictionary keys, which are common indicators of malicious software designed to replace legitimate destination wallet addresses copied to the clipboard with attacker-controlled addresses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule detects the presence of the 'antiSNG' flag in command-line arguments of newly created processes. This flag is specific to the configuration of Hannibal Stealer, which uses it to perform anti-analysis checks, likely related to geofencing or environmental detection to evade sandbox or security analyst investigation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the execution of a potentially malicious, renamed AutoIT interpreter from a temporary directory, where the process command line or associated file activity involves a specific, obfuscated loader script (kojuyn.ini). The rule identifies behavioral patterns consistent with malware staging and execution, including the use of random filenames for both the interpreter and the script, characteristic of loaders using custom string deobfuscation and decryption routines.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
25 days ago
204
Detects the initialization of the SEE_MASK_NOZONECHECKS environment variable within a PowerShell process command line. Setting this variable to '1' is a known technique used to suppress Windows zone-based security prompts (Mark-of-the-Web) for downloaded files, facilitating the execution of potentially malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects a suspicious sequence of Microsoft-signed .NET binaries (regsvcs.exe, installutil.exe, msbuild.exe, aspnet_compiler.exe) spawned by a single parent process in a short timeframe. This behavior is indicative of an attacker cycling through multiple trusted binaries in a fallback strategy to bypass application allowlisting or endpoint protection controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects unauthorized modifications to the InprocServer32 registry key for the specific CLSID {2155fee3-2419-4373-b102-6843707eb41f}, a technique used by malware to achieve persistence by hijacking COM object instantiation to load a malicious DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the termination of 'wscript.exe' using 'taskkill.exe' or PowerShell 'Stop-Process'. This behavior is commonly used by malicious loaders to stop script-based execution after a payload has been staged or executed to minimize forensic artifacts and potential detection by defenders monitoring long-running processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the Windows Script Host (wscript.exe or cscript.exe) executing files with suspicious double extensions, specifically those mimicking PDF documents (e.g., .pdf.js) or utilizing the .jse extension. This pattern is commonly associated with fileless initial execution lures, often seen in ClickFix-style or VEIL#DROP campaigns designed to trick users into executing malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the use of .NET reflection APIs, such as Assembly.Load or Reflection.Emit, within PowerShell command lines. This technique is commonly used to load and execute malicious code entirely in memory, facilitating fileless malware execution and bypassing traditional disk-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
102
Detects network activity (DNS queries or direct IP communication) associated with 'ClickFix' social engineering attacks targeting users under the guise of an HBO Max update or repair utility. The rule includes indicators for known malicious domains and IP addresses while incorporating filters to minimize false positives from security scanners, threat intel feeds, and automated crawlers by analyzing User-Agent strings and network source addresses.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
004
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
102
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
202
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Page 285 of 1871