Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects anomalous child processes spawned by the Microsoft Exchange IIS worker process (w3wp.exe). This activity is often observed during post-exploitation phases of vulnerabilities like ProxyLogon (CVE-2021-26855), where attackers attempt to gain code execution by spawning command shells or administrative tools from the web server process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects the creation or modification of a browser extension 'manifest.json' file that requests both 'declarativeNetRequest' and 'contentScripts' permissions. These permissions are frequently associated with browser-based session hijacking, traffic redirection, and unauthorized data injection, common in malicious extensions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects the installation of a rogue root certificate into the operating system's trust store. This is a common technique used by adversaries to perform TLS/SSL interception (Adversary-in-the-Middle) by establishing a chain of trust for malicious proxy traffic. The rule identifies suspicious use of Windows 'certutil' to add certificates to the 'Root' store, macOS keychain certificate management commands, and indicators associated with 'Localcertificate.zip' payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects various persistence methods associated with NetSupport Manager, a legitimate remote management tool often abused by threat actors. The rule monitors for the installation of NetSupport components (specifically client32.exe) in Windows registry run keys, Winlogon configuration, service creation, and keyboard filter drivers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects instances of the Comet AI agent (comet.exe) accessing files on the local filesystem outside of expected directories such as the browser's download directory, application profile, or temporary folder. This behavior is indicative of a compromised or malicious agent attempting to exfiltrate or interact with arbitrary local files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects components associated with the SparroWocky trident loader, specifically targeting side-loaded DLLs (DukeQt.dll or winfsp-x64.dll) and .dat data containers that contain a specific magic value (0x11328712) and RC4 strings, indicating in-memory payload decryption and mapping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects a process re-launching itself with a specific command-line argument format (a single 's' character followed by a numeric session ID). This behavior is characteristic of the SparroWocky malware, which enumerates user sessions and spawns a new backdoor instance under a different session using CreateProcessAsUserW after duplicating the target session's token.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects the Chrome process attempting to programmatically modify the Windows CapabilityAccessManager ConsentStore registry keys for microphone or webcam access. This behavior is indicative of unauthorized programmatic access to system audio/video peripherals, often associated with browser-based AI agent hijacking or malicious extensions attempting to bypass user interaction requirements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects high-frequency loading of core Windows GDI libraries (gdi32.dll, gdi32full.dll, user32.dll) by the ProcAuditManager.exe process, which is indicative of screen capture activity associated with the SparroWocky malware's persistence and data exfiltration capabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
This rule detects repeated PowerShell executions using 'Start-Process' with the 'RunAs' verb and hidden window styles. The detection specifically looks for high-frequency occurrences of these commands within a tight 18-25 second window on the same host, which is characteristic of certain automated execution or privilege escalation attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects instances where a process is created with a session ID that differs from its parent process, which is indicative of token manipulation or impersonation techniques like those observed in SparroWocky. The rule looks for cross-session process creation using the CreateProcessAsUserW API or specific command-line argument patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects a multi-stage PowerShell execution pattern often associated with 'ClickFix' or similar social engineering lures, where a base64-encoded or obfuscated command is used to invoke malicious network downloads (IEX, WebClient, DownloadString). The rule further correlates these execution patterns with potential persistence mechanisms, specifically monitoring modifications to Windows startup locations or Run keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
This rule detects the installation or operation of browser extensions that request overly broad host permissions (e.g., all URLs) or specifically target popular AI services (like Gemini, Copilot, or Claude). It also monitors the use of the declarativeNetRequest API to interact with these same AI service domains, which is a technique used by malicious extensions to intercept or manipulate web traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
This rule detects anomalous, high-frequency actions performed by browser extensions that lack concurrent user interaction events (such as keyboard input, clicks, or gestures). It monitors for automated browser API calls or prompts originating from web browsers like Chrome, Edge, and Opera that exhibit potential malicious behavior, such as silent data collection, navigation, or unauthorized scripting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects the execution of NetSupport Manager's 'client32.exe' process. This remote administration tool is frequently abused by threat actors for unauthorized persistence and remote control after being delivered via malicious payloads such as Google Apps Scripts in phishing campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects reflective memory mapping and reflective code loading activities consistent with the SparroWocky payload. The rule identifies suspicious memory configurations, specifically executable and writable (RWX) memory regions that are not backed by a corresponding file on disk, often associated with memory-only execution techniques. It also monitors for execution artifacts related to NtMapViewOfSection or reflective loading keywords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects reflective memory mapping and reflective code loading activities consistent with the SparroWocky payload. The rule identifies suspicious memory configurations, specifically executable and writable (RWX) memory regions that are not backed by a corresponding file on disk, often associated with memory-only execution techniques. It also monitors for execution artifacts related to NtMapViewOfSection or reflective loading keywords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects DLL side-loading of 'winfsp-x64.dll' or 'DukeQt.dll' by legitimate signed executables from non-standard directories. This behavior is associated with the FamousSparrow threat actor's 'SparroWocky' trident loader scheme, which leverages side-loading to execute malicious payloads in the context of trusted processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects DLL side-loading of 'winfsp-x64.dll' or 'DukeQt.dll' by legitimate signed executables from non-standard directories. This behavior is associated with the FamousSparrow threat actor's 'SparroWocky' trident loader scheme, which leverages side-loading to execute malicious payloads in the context of trusted processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
This rule detects various persistence mechanisms associated with the NetSupport Manager remote access tool. It monitors for the creation of services, scheduled tasks, registry modifications (such as Run keys, Winlogon Notify packages, and keyboard filter drivers), and process executions related to NetSupport Manager (specifically client32.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects a suspicious multi-stage PowerShell execution pattern where an initial process utilizing obfuscated arguments (e.g., -EncodedCommand) launches a secondary PowerShell process that performs network operations indicative of downloading and executing a remote payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Page 289 of 1871