Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects unauthorized processes attempting to modify, create, or rename sensitive browser files (Login Data or Cookies) belonging to Google Chrome or Microsoft Edge. The rule filters out known browser processes and looks for suspicious initiating processes characterized by unsigned code or execution from common staging areas like Temp folders.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects unauthorized processes attempting to modify, create, or rename sensitive browser files (Login Data or Cookies) belonging to Google Chrome or Microsoft Edge. The rule filters out known browser processes and looks for suspicious initiating processes characterized by unsigned code or execution from common staging areas like Temp folders.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects unauthorized processes attempting to modify, create, or rename sensitive browser files (Login Data or Cookies) belonging to Google Chrome or Microsoft Edge. The rule filters out known browser processes and looks for suspicious initiating processes characterized by unsigned code or execution from common staging areas like Temp folders.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Detects known PowerShell dropper and embedded StealC payload binaries used in the ClickFix infection chain via exact SHA256 hash equality only
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Detects known PowerShell dropper and embedded StealC payload binaries used in the ClickFix infection chain via exact SHA256 hash equality only
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects known PowerShell dropper and embedded StealC payload binaries used in the ClickFix infection chain via exact SHA256 hash equality only
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects instances where explorer.exe initiates cmd.exe with suspicious command-line patterns often associated with malicious script execution or evasion. These include caret-based obfuscation, mixed-case PowerShell invocations, or base64-like blobs, alongside indicators of common malicious file paths or execution policy bypass flags.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Detects instances where explorer.exe initiates cmd.exe with suspicious command-line patterns often associated with malicious script execution or evasion. These include caret-based obfuscation, mixed-case PowerShell invocations, or base64-like blobs, alongside indicators of common malicious file paths or execution policy bypass flags.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
001
Page 298 of 1871