Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
003
Detects the use of the native Windows utility cipher.exe with the /w flag executed from the command prompt. The /w switch instructs cipher to remove data from available unused disk space, which is a technique often used by threat actors to hinder forensic recovery of deleted files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the use of wevtutil.exe to clear the Microsoft-Windows-Defender/Operational event log, which is often done by adversaries to remove evidence of security software activity or detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of diskpart.exe using a script file (/s) launched from an atypical parent process. Diskpart is a powerful disk management utility that can be abused for staging or data destruction; invoking it via scripts from processes other than standard management shells (cmd, powershell, explorer) or services may indicate malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects execution of AI coding assistants or CLI tools (such as Claude, Gemini, Copilot, etc.) that are attempting to access sensitive local configuration, credential, or authentication files, including SSH keys, AWS credentials, and browser cookies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects repository activity involving the 'FETCH_HEAD' reference, which often indicates automated fetching, local caching, or potential attempts to manipulate or inspect the state of a Git repository during reconnaissance or post-exploitation activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects instances where AI-assisted coding tools or command-line wrappers (e.g., Claude, Copilot, Gemini) execute Git commands (clone, checkout, fetch) involving a commit hash. This behavior may indicate automated or AI-assisted code retrieval and manipulation, which could be part of an adversary's workflow for reconnaissance or downloading malicious code repositories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
This rule detects PowerShell command lines that include .NET API calls typically used for anti-debugging and anti-analysis evasion, such as 'Debugger.IsAttached', 'Debugger.IsLogging', 'CheckRemoteDebuggerPresent', and 'Environment.FailFast'. These checks are common in malicious loaders and implants to determine if the process is being analyzed or monitored, allowing the malware to modify its behavior accordingly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of the MeshAgent remote management tool when renamed to 'mvtcs.exe'. This technique is often used by adversaries to maintain persistent remote access while evading basic file-name based detections.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the use of the [Reflection.Assembly]::Load method within PowerShell command lines. This method is often abused by attackers to reflectively load malicious .NET assemblies directly into memory, bypassing disk-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the creation of a .lnk shortcut file within the Windows Startup folder, which is a common persistence mechanism. The detection logic also flags the usage of WScript.Shell and CreateShortcut methods, which are frequently abused by scripts (e.g., VBScript or PowerShell) to programmatically establish this persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the use of PowerShell commands that perform decryption (AES-256-CBC) and decompression (Gzip) of data, followed by the reflective loading of a .NET assembly into memory using [Reflection.Assembly]::Load. This behavior is indicative of fileless malware execution where a payload is hidden in an obfuscated or compressed format and unpacked at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects unauthorized processes attempting to access sensitive browser files, including Login Data (passwords) and Network/Cookies databases for Chrome, Edge, and Firefox. These files are primary targets for credential dumping and session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects PowerShell instances performing suspicious memory operations like thread injection (e.g., VirtualAllocEx, WriteProcessMemory, CreateRemoteThread) targeting common processes such as csc.exe, browser processes (chrome.exe, msedge.exe), and system processes like SearchIndexer.exe. This activity is indicative of malicious code injection often used in stealth execution and credential harvesting campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the use of the native Windows utility cipher.exe with the /w flag. This command is designed to overwrite free disk space with random data to sanitize it and make previously deleted files irrecoverable. While this is a legitimate administrative feature, adversaries may utilize it as a form of anti-forensics or to perform data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of the Windows Diskpart utility using a script file, as indicated by the /s command-line argument. This behavior is often associated with malicious actors attempting to perform destructive operations such as removing recovery partitions to inhibit system recovery during ransomware attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the use of the native Windows utility cipher.exe with the /w flag. This command is designed to overwrite free disk space with random data to sanitize it and make previously deleted files irrecoverable. While this is a legitimate administrative feature, adversaries may utilize it as a form of anti-forensics or to perform data destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of the 'reagentc.exe' utility with the '/disable' argument. This command is used to disable the Windows Recovery Environment (WinRE), which is a common post-compromise activity performed by ransomware and other malware to prevent system recovery and hinder incident response efforts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
201
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Page 294 of 1871