Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects attempts to query or access the MachineGuid registry key located in HKLM\SOFTWARE\Microsoft\Cryptography. This registry key is commonly used to uniquely identify a Windows installation and is frequently targeted by malicious software to perform system identification or fingerprinting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects modifications, creation, or renaming of common cryptocurrency wallet files (e.g., wallet.dat, .wallet files) within known storage directories. This behavior is often associated with infostealers or malware attempting to exfiltrate or manipulate user financial assets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects presence of configuration markers associated with the Hannibal Stealer 'clipper' functionality. These markers (e.g., 'cclipper', 'clipboard_check_delay') are used by the malware to monitor the system clipboard and replace cryptocurrency wallet addresses with attacker-controlled addresses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects components of the LucidPawn malware family using DLL side-loading (e.g., index.exe loading DismCore.dll) or renaming DISM binaries within WindowsApps folders. The detection identifies these processes subsequently querying system locale or language registry keys, indicating a geo-targeting execution gate used to determine if the environment matches the intended target profile (specifically zh-TW).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects instances of the Hannibal Stealer module that attempt to masquerade as the legitimate 'CefSharp.BrowsersSubprocess.dll' by spoofing publisher metadata ('LLC Windows'). The detection triggers when this process is identified initiating network connections shortly after execution, which aligns with the malware's known behavior of performing geolocation-based checks before continuing activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects unauthorized access, modification, or creation of the FileZilla 'sitemanager.xml' configuration file by a process other than the legitimate 'filezilla.exe'. This is a common indicator of an adversary attempting to steal stored FTP credentials or modify connection configurations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
This rule monitors for outbound network connections to domains and IP addresses associated with known phishing, loader, and C2 infrastructure, including specific ClickFix patterns.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
18028
Detects the deletion of the Windows Application Event Log registry key. This action is a known technique used by adversaries to disable or tamper with event logging mechanisms to conceal malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the use of PowerShell to download the 'gitlab-runner-windows-amd64.exe' binary, potentially indicating unauthorized installation or deployment of automation agents using legitimate download sources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Page 297 of 1871