Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects unauthorized downloads of Tailscale VPN client binaries or related dependencies (such as wintun.dll) originating from a specific GitHub repository ('cphc811-ui'). Such activity is often associated with the Kothamine threat actor attempting to establish unauthorized remote access or command-and-control channels by provisioning VPN software on compromised hosts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects unauthorized downloads of Tailscale VPN client binaries or related dependencies (such as wintun.dll) originating from a specific GitHub repository ('cphc811-ui'). Such activity is often associated with the Kothamine threat actor attempting to establish unauthorized remote access or command-and-control channels by provisioning VPN software on compromised hosts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects unauthorized downloads of Tailscale VPN client binaries or related dependencies (such as wintun.dll) originating from a specific GitHub repository ('cphc811-ui'). Such activity is often associated with the Kothamine threat actor attempting to establish unauthorized remote access or command-and-control channels by provisioning VPN software on compromised hosts.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects unauthorized downloads of Tailscale VPN client binaries or related dependencies (such as wintun.dll) originating from a specific GitHub repository ('cphc811-ui'). Such activity is often associated with the Kothamine threat actor attempting to establish unauthorized remote access or command-and-control channels by provisioning VPN software on compromised hosts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000