Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
