Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Detects StealC-related .NET payload protected with ConfuserEx, requiring the sample-specific mutex string, AES key material, and multiple anti-debugging indicators together to avoid matching benign ConfuserEx-obfuscated applications
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Detects StealC-related .NET payload protected with ConfuserEx, requiring the sample-specific mutex string, AES key material, and multiple anti-debugging indicators together to avoid matching benign ConfuserEx-obfuscated applications
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects StealC-related .NET payload protected with ConfuserEx, requiring the sample-specific mutex string, AES key material, and multiple anti-debugging indicators together to avoid matching benign ConfuserEx-obfuscated applications
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects StealC-related .NET payload protected with ConfuserEx, requiring the sample-specific mutex string, AES key material, and multiple anti-debugging indicators together to avoid matching benign ConfuserEx-obfuscated applications
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects instances where explorer.exe initiates cmd.exe with suspicious command-line patterns often associated with malicious script execution or evasion. These include caret-based obfuscation, mixed-case PowerShell invocations, or base64-like blobs, alongside indicators of common malicious file paths or execution policy bypass flags.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects known PowerShell dropper and embedded StealC payload binaries used in the ClickFix infection chain via exact SHA256 hash equality only
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects unauthorized processes attempting to modify, create, or rename sensitive browser files (Login Data or Cookies) belonging to Google Chrome or Microsoft Edge. The rule filters out known browser processes and looks for suspicious initiating processes characterized by unsigned code or execution from common staging areas like Temp folders.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects the loading of the 'gdrv.sys' driver, which is a known vulnerable driver often used in 'Bring Your Own Vulnerable Driver' (BYOVD) attacks to facilitate privilege escalation to kernel mode.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
001
Detects the execution of reagentc.exe with the /disable command-line argument, which is used to disable the Windows Recovery Environment (WinRE). Adversaries use this technique to inhibit system recovery and prevent users or automated systems from restoring the operating system to a known good state after an attack, such as data destruction or encryption.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
101
Detects the loading of the 'gdrv.sys' driver, which is a known vulnerable driver often used in 'Bring Your Own Vulnerable Driver' (BYOVD) attacks to facilitate privilege escalation to kernel mode.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
001
Detects the use of the built-in Windows 'cipher.exe' utility with the '/w' flag, which is used to securely overwrite free space on a disk, a technique often used by adversaries for anti-forensics or data destruction to prevent file recovery. The rule specifically alerts on execution from command-line environments (cmd.exe) where the command output is redirected to null, often used to hide the progress or output of the wiping process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
001
Detects the execution of diskpart.exe using a script file (via the /s parameter) where the parent process is not a standard system utility. This behavior is often indicative of attackers using diskpart to automate disk operations, such as clearing volume shadowing or modifying disk configurations, during post-exploitation activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
001
Detects attempts to clear Windows event logs using administrative tools like wevtutil.exe, PowerShell, or through the detection of mass log-clear audit events (such as Event IDs 1102 and 104) occurring in a rapid burst. This activity is often used by adversaries to hide evidence of post-compromise actions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
001
This rule detects potential ransomware activity by correlating three distinct events: the execution of a suspicious, potentially obfuscated binary (matching a specific naming pattern of _win64.exe) from an untrusted location (e.g., Temp, AppData, Downloads), followed by a high volume of file modifications or renames with specific ransomware-related extensions (.locked), and the dropping of a known ransom note file (RESTORE_FILES.txt) within a short 15-minute time window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Page 299 of 1871