Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000