Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors various logs (device network events, Entra ID sign-ins, cloud application events, and email events) for any interaction with a predefined list of indicator IP addresses identified as being associated with malicious actor egress traffic.
avatar
F S@Fsdr
avatar
Detections.ai Community
26 days ago
305
Detects persistence attempts related to the NetSupport Manager remote access tool by monitoring modifications to Windows Registry keys associated with run keys, Winlogon notification packages, and services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
102
This rule detects potentially malicious file access patterns by the executable 'comet.exe'. It alerts when this process accesses sensitive files or directories associated with credentials, configuration files, or sensitive browser data, while explicitly excluding benign locations such as Chrome data folders and temporary directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
102
Detects the execution of a hidden PowerShell process that subsequently spawns a child process using the 'Start-Process' cmdlet with the '-Verb RunAs' argument within a short time window. This pattern is commonly associated with attempts to bypass User Account Control (UAC) or execute processes with elevated privileges silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
102
Detects the execution of 'client32.exe', which is the executable associated with NetSupport Manager, a legitimate remote management software often abused by adversaries to establish persistence and provide remote interactive access to compromised systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
602
Detects the execution or loading of specific components (winfsp-x64.dll, DukeQt.dll) associated with the SparroWocky malware framework, or suspicious image load events lacking a defined module path that typically precede reflective mapping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects the execution of PowerShell commands that utilize both obfuscation techniques (such as Base64 encoding or 'FromBase64String') and remote payload retrieval or memory execution methods (such as 'IEX', 'DownloadString', or 'Invoke-WebRequest'). This combination is a classic indicator of malicious PowerShell activity designed to download and execute second-stage payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
This rule detects Windows PE executables that are digitally signed with code-signing certificates attributed to 'Discord Inc.' or 'Lenovo'. It performs a negative check to verify that the file metadata (such as internal names or company strings) does not match legitimate software from these vendors. This is intended to identify potential abuse of stolen certificates by adversaries to bypass security controls and masquerade as trusted software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
This rule detects the creation, modification, or renaming of a browser extension's 'manifest.json' file, which is a critical configuration file for browser extensions. It correlates this file activity with simultaneous or subsequent network requests to common web-based productivity or email services (e.g., Google, Microsoft, Perplexity). This combination of file modification in an extension directory and network activity to sensitive domains may indicate the installation of a malicious browser extension designed for session hijacking or unauthorized data collection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects instances where a process named 'comet.exe' (or 'comet') accesses sensitive file system locations such as Documents, Desktop, Pictures, or system directories like /etc/ or C:\Windows\. This rule excludes known-legitimate installation and application directories associated with Comet software to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects persistent, periodic network communication patterns to remote IPs on common ports (443, 8080) that deviate from known administrative remote access tools. The rule identifies processes communicating with a consistent, low-frequency interval, which is highly indicative of automated Command and Control (C2) beaconing behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects remote thread creation attempts (via CreateRemoteThread or NtCreateThreadEx) where the associated module path is empty or null, which is a common indicator of process injection techniques attempting to execute code without a backing file on disk.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects the creation of a 'manifest.json' file within a directory path containing 'Extensions' by common web browsers, followed by an immediate file access event from a non-standard browser location within one hour of the installation. This pattern is indicative of the installation of a potentially malicious or sideloaded browser extension followed by anomalous file activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects the execution of an executable file where the command line matches a specific pattern of a single character argument (e.g., '.exe s'). This behavior is frequently associated with malicious tools attempting to perform actions with minimal command-line footprints or potential process injection/tampering patterns when executed by a different user than the initiating process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects evidence of anti-forensic activities associated with the SparroWocky toolset. The rule monitors for the removal of the 'ProcAuditManager' service, deletion of the 'SnapCart' registry key, and the execution of a self-deleting batch script used to remove forensic artifacts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects threads created using CreateThread or CreateRemoteThread where the start address resolves to the AnimateWindow function in user32.dll. This technique is often used by malware, such as those leveraging the MinHook library, to disguise the true entry point of injected code by redirecting thread execution through a legitimate Windows API function (hooking).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects signs of NetSupport Manager (client32.exe) establishing multiple persistence mechanisms simultaneously or in quick succession, including Windows service creation, Winlogon helper registration, Registry Run key modification, scheduled task creation, and keyboard filter driver installation. This behavior is indicative of unauthorized use of remote access tools to maintain persistence on a host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
402
Detects forged thread call stacks by identifying processes that spoof legitimate thread entry points such as RtlUserThreadStart and BaseThreadInitThunk in kernel32.dll, a technique commonly associated with advanced thread execution hijacking methods like SilentMoonwalk or StackMoonwalk.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
202
Detects the installation or update of browser extensions that possess both 'declarativeNetRequest' and 'content_scripts' permissions, while also requesting host permissions for major AI assistant or trusted vendor domains (e.g., google.com, gemini.google.com, copilot.microsoft.com, claude.ai). This specific combination of permissions is characteristic of the BragJack attack chain used to redirect network traffic and hijack AI browser agent sessions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
102
Detects the allocation of executable memory regions (RWX or EXECUTE_READ) that are not backed by a file on disk (i.e., anonymous memory). This behavior is a common indicator of process injection, shellcode execution, or fileless malware techniques where code is injected into a process and executed directly from memory without a corresponding file on disk.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects instances where PowerShell attempts to execute an external process with elevated privileges using 'Start-Process -Verb RunAs' combined with hidden window flags. The rule specifically looks for evidence that the targeted executable was recently initiated or exists in the context of the PowerShell operation, potentially indicating a UAC bypass attempt or malicious elevation of privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
102
Page 288 of 1871