Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects a multi-stage infection chain associated with RedFlick, involving the delivery of VHDX files or PDF attachments. The rule correlates malicious activities such as SSH-based tool download (using PermitLocalCommand), PowerShell-based PDF decoding/extraction, PowerShell VHDX disk mounting, and silent MSI installation from remote URLs. It monitors for these activities within user-writable directories like Downloads or Temp.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
002
This rule detects potential post-compromise activity related to a campaign using MSP360-masqueraded installers and ScreenConnect remote access tools. It performs an IOC sweep across device file events for known malicious file hashes (associated with installers and post-compromise utilities) and device network events for connections to known malicious domains used for command and control.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
002
Detects instances where the Windows command shell (cmd.exe) is used to execute 'dotnet --list-runtimes' with output redirected to sensitive locations (e.g., NUL, temp folders, or text/log files). This pattern is often observed during post-exploitation activities by RMM agents or unauthorized processes attempting to profile the .NET environment while hiding their command output.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
002
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
002
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
002
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
002
Detects the installation sequence of the CosmicPulse (YESROBOT) backdoor, characterized by a registry value write under HKCU\Software\Classes\.mollis followed by the execution of a Python 3.8 bootstrapper from a non-standard, suspicious directory such as AppData, ProgramData, or Temp.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
002
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
104
Detects the loading of an unsigned or untrusted kernel driver followed by the termination of known security (AV/EDR) processes within a 10-minute window. This behavioral pattern is indicative of 'Bring Your Own Vulnerable Driver' (BYOVD) exploitation often used by ransomware actors to bypass endpoint security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
702
Detects the execution of common enumeration tools and commands often associated with ransomware-precursor behavior. This includes the use of AdFind, dsquery, net.exe, and nltest for domain account, group, and trust discovery, as well as the execution of BloodHound/SharpHound collection activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
202
Detects the execution of known Active Directory reconnaissance tools, specifically AdFind and SharpHound/BloodHound. These tools are commonly used by adversaries to enumerate domain objects, users, computers, groups, and trusts, which are essential precursors to further lateral movement and privilege escalation within a domain environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
Detects the execution of known administrative or reconnaissance tools (such as netscan, PsExec, or nmap) that have been renamed or relocated outside of standard directories like C:\Windows\System32 or Program Files, matching TTPs observed in INC Ransom operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects a suspicious pattern where a high volume of security, backup, or antivirus services and processes are terminated on a host in a short time window, followed by extensive file modification activity. This behavior is highly indicative of pre-encryption preparations by ransomware, specifically patterns observed by the Everest group, intended to neutralize defenses and prevent restoration before encrypting files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
504
Detects a sequence of events indicative of Bring Your Own Vulnerable Driver (BYOVD) exploitation. The rule correlates the creation of a new service with kernel-mode drivers, the loading of a signed driver, and the subsequent termination or disabling of common EDR security processes within a short timeframe, suggesting the exploitation of the driver to bypass EDR defenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
004
Detects potential 'ClickFix' activity where a browser or file explorer process initiates a shell (e.g., cmd, powershell, osascript) with command arguments indicative of remote script execution, obfuscated commands, or web-based payload downloading. This pattern matches known social engineering tactics that entice users to copy-paste malicious code into a system shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
204
Detects instances where explorer.exe (the Windows Shell) launches common scripting or command-line binaries with suspicious arguments often associated with 'ClickFix' social engineering attacks. These attacks involve tricking users into copying and pasting obfuscated PowerShell, mshta, or curl commands into the Windows Run dialog to execute malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
004
Detects the use of PowerShell commands to modify file timestamps (CreationTime, LastWriteTime, LastAccessTime) on web application directories and configuration files, a technique often used by attackers to hide modifications made to webshells or malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
001
Detects PowerShell execution that modifies the 'jquery.mousewheel-3.0.6.pack.js' file while simultaneously attempting to timestomp file metadata or utilizing specific obfuscation markers identified in webshell deployment patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
001
Detects repeated attempts to perform IIS 8.3 tilde short-filename enumeration. This reconnaissance technique exploits the legacy DOS 8.3 file naming convention to identify the existence and naming of files or directories on a Microsoft IIS web server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
001
Detects the 'ClickFix' social engineering pattern where a user is tricked into opening a terminal (Windows Terminal, PowerShell, or PowerShell ISE) and pasting a command. The rule specifically alerts on commands originating from explorer.exe that invoke web download utilities to fetch .zip archives, which are commonly associated with the Lorem Ipsum Loader initial access infection chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
001
Page 29 of 1866