Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where processes associated with Claude or Codex modify or create files within a plugin directory without a preceding legitimate installation or session command (such as 'install' or 'plugin add'). This behavior may indicate unauthorized plugin installation, persistence establishment, or malicious code injection into the development environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
This rule monitors for any process execution event captured by the EDR solution. It serves as a catch-all for recording process creation telemetry.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
001
This rule detects the creation or modification of registry keys within the RunOnce path in both HKEY_CURRENT_USER and HKEY_LOCAL_MACHINE. These keys are commonly abused by adversaries to achieve persistence, as programs referenced in them execute automatically upon the next user logon or system start.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule detects the creation of a synchronization mutex with a specific naming pattern ('Global\EVOLUTION') often used by malware families to ensure only a single instance of the malicious process runs on the infected host. The rule monitors DeviceEvents for 'MutexCreated' or 'MutexEvent' and parses the synchronization object name to identify this specific indicator.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule monitors for file creation or existence patterns in the user's Local Temp directory that are commonly associated with infostealer malware, specifically looking for naming conventions like 'evo_cl_*.exe', 'evo_db_*.db', or the presence of a 'stolen.zip' file within subdirectories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects instances where Outlook (OUTLOOK.EXE) spawns an executable named 'ai.exe' with a command line containing a 16+ character hexadecimal string, followed closely (within 10 minutes) by a Microsoft Edge (msedge.exe) process execution acting as a network utility. This pattern is indicative of a potential phishing-initiated attack where a malicious payload is executed and subsequently leverages browser components for network communication or C2 activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the execution of ConfigurationRemotingServer.exe initiated by winget.exe. This could indicate usage of the Windows Package Manager to facilitate remote configuration or management tasks, which warrants investigation for potential unauthorized use or process manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule detects network upload operations (HTTP POST or similar requests ending in '/upload') to a specific external IP address (2.26.126.50). It specifically monitors for processes other than common web browsers, and filters for connections where significant data volume (greater than 10KB) is transferred or the data size is unknown.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
001
This rule detects network upload operations (HTTP POST or similar requests ending in '/upload') to a specific external IP address (2.26.126.50). It specifically monitors for processes other than common web browsers, and filters for connections where significant data volume (greater than 10KB) is transferred or the data size is unknown.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
101
This rule detects the use of 'winget' or 'ConfigurationRemotingServer.exe' to execute Windows Configuration DSC (Desired State Configuration) files, specifically targeting the invocation of 'PSDscResources/Script' resources, 'SetScript', 'TestScript', or 'GetScript' operations. This technique may be leveraged by attackers to execute arbitrary code or maintain persistence through the configuration management framework.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects successful network connections initiated by the ConfigurationRemotingServer.exe process. This binary is associated with Windows configuration remoting services and may be used for remote administrative tasks or unauthorized remote management activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule monitors outbound network traffic for the inclusion of a Windows-style hostname pattern (e.g., 'DESKTOP-XXXXXX'), which is often used by stealer malware or RATs to identify victim machines during C2 communication. It explicitly excludes Microsoft licensing traffic to reduce false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule detects potential malware delivery by correlating network visits to known malicious domains used for lure distribution with subsequent large file downloads (.zip files >= 100MB) in typical user download or temporary folders within a short time window. This pattern is characteristic of campaigns leveraging social engineering and file-based evasive techniques (such as padding to bypass static analysis) to distribute malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
001
This rule detects two suspicious activities: first, the execution of 'conhost.exe' with a headless command line argument containing 'cmd /c echo' and either a '.tmp' file reference or a suspicious base64-like encoded string, initiated by explorer.exe or cmd.exe. Second, it identifies the presence of '.lnk' shortcut files within common user-writable directories such as Downloads, Desktop, or Public folders, which is a common indicator of staging or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule detects network upload operations (HTTP POST or similar requests ending in '/upload') to a specific external IP address (2.26.126.50). It specifically monitors for processes other than common web browsers, and filters for connections where significant data volume (greater than 10KB) is transferred or the data size is unknown.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
001
This rule detects the presence of files and folders associated with the Rapuncel infostealer malware. It monitors DeviceFileEvents for specific SHA256 hashes known to be malicious, as well as specific file names related to data exfiltration and log collection (e.g., 'browser_decryption.log', 'sends.log'), and the creation of files within folders containing 'Filegraber'.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
001
This rule monitors process creation events for suspicious activity, specifically detecting two patterns: 1) The creation of a scheduled task named 'OneDrive KeepAlive' using schtasks.exe, which is indicative of persistence mechanisms masquerading as legitimate software, and 2) Execution of the 'taskhostw.exe' binary with command-line arguments 'exec' and 'hide', which is a common indicator of the NirCmd utility being renamed and used for stealthy execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule detects persistence attempts via Component Object Model (COM) hijacking. It identifies a specific process 'December_blob.exe' creating or modifying registry keys associated with COM CLSIDs (specifically InprocServer32) and simultaneously dropping or utilizing a file named 'hvcsrv.dll' within an 'IdentityNexusIntegration' directory. This combination of registry modification and file system activity suggests the registration of a malicious COM object to achieve execution persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects instances where Windows Terminal (WindowsTerminal.exe) is launched by Explorer and immediately spawns a shell process (PowerShell, PWSH, or CMD), specifically excluding devices that have recorded recent RunMRU registry history. This pattern may indicate suspicious or non-interactive execution by an adversary attempting to bypass traditional shell history tracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule detects attempts to query or access the MachineGuid registry key located in HKLM\SOFTWARE\Microsoft\Cryptography. This registry key is commonly used to uniquely identify a Windows installation and is frequently targeted by malicious software to perform system identification or fingerprinting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Page 296 of 1871