Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
101
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Detects unexpected child processes spawned from directories associated with AI coding agent plugins (e.g., Claude Code, Copilot, Codex, Gemini CLI). This activity could indicate post-exploitation behavior, such as Plugin4Shell, where a malicious plugin auto-update facilitates remote code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
201
Detects instances where explorer.exe spawns cmd.exe or powershell.exe with command-line arguments indicative of obfuscated execution, such as encoded commands, hidden window styles, or bypass flags. This pattern is consistent with ClickFix social engineering attacks where users are deceived into manually executing malicious commands via the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects instances where explorer.exe spawns cmd.exe or powershell.exe with command-line arguments indicative of obfuscated execution, such as encoded commands, hidden window styles, or bypass flags. This pattern is consistent with ClickFix social engineering attacks where users are deceived into manually executing malicious commands via the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
101
Detects the creation of an LNK file in the Windows Startup directory, a common technique used to achieve persistence by executing a specific program or script upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
101
Detects PowerShell attempts to perform remote process injection into potentially suspicious or sensitive processes (csc.exe, chrome.exe, msedge.exe, SearchIndexer.exe) by searching for command line arguments indicating the usage of Windows memory allocation or thread context manipulation APIs such as NtAllocateVirtualMemoryRemote and NtSetContextThreadRemote.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
101
Detects successful user authentication events originating from an external source IP address. This rule is intended to identify remote logins that can be correlated with RMM (Remote Monitoring and Management) activity or other remote access patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
101
Detects the use of AI assistant command-line interfaces (such as Claude, GitHub Copilot, or Gemini) to execute git checkout commands with specific commit hashes or references like FETCH_HEAD. This behavior may indicate an attempt to use automated AI tooling to stage or interact with repository code, which could be part of an automated exfiltration or unauthorized code modification attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
101
This rule detects the creation or pushing of a local Git branch where the branch name matches the pattern of a 40-character SHA-1 or 64-character SHA-256 hash. This behavior is indicative of the Plugin4Shell exploitation technique, where attackers create branches named after specific commit SHAs to bypass security checks on self-hosted Git services like Bitbucket by pinning them to unintended commits.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
601
Detects the execution of a local git force-push operation, which is a technique used by an adversary to overwrite existing repository tags or branches during a software supply chain compromise or repository takeover scenario.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
101
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects the presence of the known vulnerable GIGABYTE driver (gdrv.sys) used in Bring Your Own Vulnerable Driver (BYOVD) attacks to bypass security controls and facilitate kernel-mode execution, as associated with Settra ransomware campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects execution of long, obfuscated command strings initiated by Windows Explorer, often indicative of the 'ClickFix' social engineering technique where users are tricked into copying and pasting malicious commands into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects the creation of shortcut files (.lnk) within the current user's Startup folder using Windows command line utilities or scripts that leverage the WScript.Shell COM object. This behavior is indicative of an adversary establishing persistence to ensure malicious payloads execute upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Detects unauthorized processes attempting to access sensitive browser data files, specifically 'Login Data' (passwords) and 'Cookies' for Google Chrome and Microsoft Edge. The rule excludes the browser applications themselves and their update processes to minimize noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
Page 295 of 1871