Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects network activity associated with the Psychedelic Stealer malware command-and-control (C2) communication patterns. The rule identifies specific API endpoints used for task polling, heartbeat pings, check-ins, and task acknowledgement, as well as connections to a known malicious C2 infrastructure, all characterized by the presence of a specific 'X-API-Key' header.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to delete volume shadow copies, clear backup catalogs, or disable system recovery features, which is a common behavior of ransomware before encrypting files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule detects scenarios where common web browsers (e.g., chrome.exe, msedge.exe) spawn known living-off-the-land (LotL) binaries (e.g., powershell.exe, wscript.exe, mshta.exe) with command-line arguments indicative of malicious activity, such as base64-encoded strings, hidden window flags, or remote script invocation (IEX/Invoke-Expression). This pattern is frequently used in drive-by download or phishing delivery chains where an initial payload is triggered directly from a browser context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
301
This rule detects a single host performing a high volume of connection attempts to internal IP addresses across standard management and file-sharing ports (SMB 445, RDP 3389, WinRM 5985) within a 5-minute window. Such behavior is characteristic of network scanning or reconnaissance activities performed by adversaries attempting to identify targets for lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
This rule detects processes other than known web browsers (Chrome, Edge, Firefox, Brave, Opera) accessing sensitive browser-related files (Login Data, Cookies, Web Data) and initiating an external network connection within 15 minutes. This behavior is highly characteristic of credential and session cookie theft, often utilized by info-stealing malware for subsequent session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
102
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects the use of the sc.exe command-line utility to stop or disable the Microsoft Defender Antivirus service (WinDefend). This activity is often associated with ransomware, such as Nova ransomware, to bypass security controls prior to malicious encryption or data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects attempts by malicious software to inhibit system recovery by deleting Volume Shadow Copies. The rule monitors for the execution of vssadmin.exe with deletion flags or wmic.exe with shadowcopy deletion commands combined with non-interactive flags, which are common indicators of ransomware preparation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects attempts by malicious software to inhibit system recovery by deleting Volume Shadow Copies. The rule monitors for the execution of vssadmin.exe with deletion flags or wmic.exe with shadowcopy deletion commands combined with non-interactive flags, which are common indicators of ransomware preparation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
201
Detects unauthorized processes accessing the 'ConsoleHost_history.txt' file across user profiles. This behavior is indicative of ransomware operators or malicious actors attempting to harvest stored credentials, tokens, or sensitive command-line history before performing lateral movement or privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects the use of PsExec to remotely execute binaries on target hosts, a technique observed in The Gentlemen ransomware lateral movement phase when domain controller access is unavailable. The rule identifies psexec.exe process creation with common flags (-s, -d, -c) while filtering out common administrative parent processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects the use of PowerShell Set-MpPreference commands to disable multiple Microsoft Defender security features, including real-time monitoring, behavioral scanning, and threat detection actions. This activity is consistent with ransomware behavior, such as Nova or The Gentlemen families, attempting to neutralize endpoint protection before proceeding with malicious actions like file encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
201
Detects the use of PowerShell to modify Microsoft Defender exclusion paths by adding root drive letters or temporary directory paths. This behavior is indicative of defense evasion techniques often employed by ransomware families, such as Nova or Gentlemen, to prevent the scanning of files immediately prior to encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
301
Detects lateral movement activities associated with The Gentlemen ransomware group. The rule monitors for the execution of PowerShell scripts named 'deploy_gpo.ps1' from the %TEMP% directory, PowerShell interactions with the NETLOGON share for malware distribution, creation of ScheduledTasks.xml via PowerShell (a common GPO manipulation technique), and the subsequent enforcement of policy changes using 'gpupdate /force' invoked by scripting engines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects attempts to terminate security-related processes (AV/EDR) using common administrative tools including taskkill.exe, wmic.exe, and PowerShell Stop-Process. This behavior is frequently observed during the pre-encryption phase of ransomware attacks, such as Nova and Gentlemen, to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
201
Detects lateral movement activities associated with The Gentlemen ransomware group. The rule monitors for the execution of PowerShell scripts named 'deploy_gpo.ps1' from the %TEMP% directory, PowerShell interactions with the NETLOGON share for malware distribution, creation of ScheduledTasks.xml via PowerShell (a common GPO manipulation technique), and the subsequent enforcement of policy changes using 'gpupdate /force' invoked by scripting engines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects the specific sequence of administrative utilities used by Gentlemen ransomware to seize control of files before encryption. This involves using 'takeown.exe' to claim ownership, 'icacls.exe' to grant full access to the Everyone group, and 'attrib.exe' to remove read-only file attributes, a common precursor to mass file encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects the mass termination of security, backup, database, and virtualization services and processes. The rule monitors for the use of 'taskkill', 'sc', and 'net stop' commands, targeting a list of processes and services often associated with pre-encryption cleanup activities by ransomware actors to neutralize security tools and data access controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
201
Detects the creation of hidden administrative shares (ending in $) mapped to local directories (e.g., C:\Temp) with unrestricted 'Everyone' or 'ANONYMOUS LOGON' permissions. This technique is used by the Gentlemen ransomware to stage malicious binaries for lateral movement and subsequent encryption across the network. The rule monitors for 'net share' commands with specific permission grants, 'icacls' operations modifying access for anonymous users, and registry changes to 'NullSessionShares' configurations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects the creation of scheduled tasks using schtasks.exe initiated by command shells where the task command points to files residing in non-standard or user-writable directories such as \Users\Public\, \PerfLogs\, or \ProgramData\. This pattern is frequently utilized by malware loaders like SocGholish, GootLoader, and various ransomware strains to achieve persistence following initial compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101