Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation of Windows services using sc.exe, powershell.exe, or cmd.exe that reference specific DLL files (winfsp-x64.dll or DukeQt.dll). This behavior is often associated with persistence mechanisms or DLL hijacking/side-loading techniques where a malicious service is configured to load a specific library.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
102
Detects the loading of known SparroWocky loader DLLs (winfsp-x64.dll or DukeQt.dll) into a process, followed by the absence of new executable file creation within the same process and time window. This behavior is indicative of in-memory execution techniques, such as Beacon Object File (BOF) loading, aimed at extending implant functionality without writing files to disk.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects process executions, file deletions, renames, and movements initiated by known SparroWocky malware files or suspicious DLLs (winfsp-x64.dll, DukeQt.dll). This monitors malicious lifecycle activity on endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
This rule detects the suspicious loading of known SparroWocky loader DLLs (winfsp-x64.dll or DukeQt.dll) into a process, followed by that same process loading graphics-related libraries (gdi32.dll, gdi32full.dll, or user32.dll) within a 10-minute window. This behavioral pattern is indicative of the backdoor's screen-capture capability, as these GDI/User32 modules are required for capturing screen content.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects a process loading known malicious DLLs (winfsp-x64.dll or DukeQt.dll) used by the FamousSparrow threat actor, followed by the creation or modification of a .dat file in the same process context. This pattern is indicative of the reflective loading of a backdoor payload without leaving the secondary binary on disk.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects the presence of known artifacts associated with the SparroWocky loader and backdoor, specifically identifying the file names 'winfsp-x64.dll' and 'DukeQt.dll', or files matching known SHA1 hashes of SparroWocky samples. The presence of these files on a host is a strong indicator of compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects anomalous thread execution call stacks indicative of the SparroWocky anti-forensic evasion technique. This method involves spoofing thread start addresses and call stacks by injecting or manually manipulating stack frames to include legitimate-looking system functions (e.g., BaseFlushAppcompatCacheWorker, BaseCheckVDMp) alongside malicious execution patterns involving NtDelayExecution and SleepEx to hide the true origin of code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Identifies instances of Google Chrome running on endpoints with version numbers below the threshold patched for CVE-2026-85046. This detection focuses on specific build numbers (e.g., 152.0.7977.82 for Windows/Linux) to identify potentially vulnerable browser installations in the environment.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
7023
Detects the execution of 'charmap.exe' from the Syswow64 directory where the process hierarchy indicates suspicious activity. The detection identifies a chain where PowerShell spawns 'conhost.exe', which in turn spawns a process from a temporary directory (interpreted as a renamed AutoIT executable) that then launches 'charmap.exe'. This pattern is indicative of a multi-stage obfuscated execution flow often used in malware dropper scenarios to bypass standard monitoring.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
26 days ago
105
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
26 days ago
305
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
205
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
26 days ago
105
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
308
Detects rapid deletion and creation cycles of the WD_SCAN object manager link, a behavioral pattern associated with a Time-of-Check-to-Time-of-Use (TOCTOU) exploit chain targeting Windows Defender (referenced as CVE-2026-69414). The rule monitors for at least three cycle events occurring within a 5-second window, specifically involving the 'WD_SCAN' object identifier.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
508
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
101
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
101
Detects suspicious use of Windows API functions (SetWindowsHookEx) often associated with keylogging, correlated with the presence of temporary staging files in common directories (e.g., Temp, AppData). The rule excludes known legitimate applications that frequently utilize system hooks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
101
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
101
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
101
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Page 286 of 1871