Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule detects persistence mechanisms involving the creation or modification of Windows Registry Run keys, the creation of scheduled tasks, or the execution of specific binaries (COTFileReadApp.exe, DeElevate64.exe) associated with potentially unauthorized activity, specifically tracking strings related to 'Canon Configuration Reader' or 'Stardock DeElevation Tool'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
202
Detects a credential-theft pattern associated with Psychedelic Stealer where a process accesses the 'Login Data' file of common Chromium-based browsers, followed shortly by a network connection to a known stealer exfiltration API endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
This rule detects the creation of a new Windows service using common administrative tools like sc.exe or PowerShell's New-Service cmdlet that masquerades as the legitimate Windows Time service (w32time). The rule specifically flags service creation commands that use relevant service names but point to non-standard, suspicious executable paths or configurations, potentially indicating persistence or malicious activity by RemotePanel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
202
Detects the loading of spoofed system DLLs (dnsapi.dll or ws2_32.dll) from non-system directories, followed by network beaconing to suspicious domains associated with the NeedyMantis malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the execution of taskkill.exe to terminate known security software processes, when the command is initiated from sqlservr.exe or via a command shell child process of sqlservr.exe. This activity is a common post-exploitation step after abusing xp_cmdshell to neutralize defenses before deploying further payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the use of certutil.exe to decode files located within directories associated with the MSSQL service account (e.g., AppData, ServiceProfiles). This behavior is characteristic of an attack chain where an adversary uses SQL Server's xp_cmdshell to stage and decode a malicious payload from a base64-encoded file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects unauthorized file deletion activity performed directly by a Node.js process acting as a ChainScript RAT. The RAT uses a bundled node.exe process, operating within specific masquerading directories in the user profile, to execute file system operations such as recursive deletion without spawning child processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
1014
Detects the creation of Windows services that reference file paths often associated with NeedyMantis malware sideloading activities. These paths typically involve directories inside ProgramData or ProgramFiles where benign executables are used to sideload malicious DLLs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the first-stage loader DLL associated with the NeedyMantis actor, which masquerades as the WinSparkle.dll component used in Poedit software. This rule uses a specific SHA256 file hash to identify this malicious component.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the execution of a specific, tampered version (12.5.1) of the DAEMON Tools Lite installer, which has been identified as a distribution vector for malicious activity linked to Storm-3069.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the creation of persistence mechanisms through both Registry Run keys and Scheduled Tasks within a one-hour window, specifically targeting names indicative of masquerading as legitimate update or helper components.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
101
Detects execution of various reconnaissance commands commonly used by Remote Access Trojans (RATs) to profile a target host. This includes querying security product status (AV/Defender), enumerating domain controllers, network adapters, port scanning, and gathering system hardware and software inventory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects instances where a Python process spawns a command-line shell (cmd.exe, powershell.exe, or bash) within 15 seconds of starting, while executing common reconnaissance or utility commands. This behavior is indicative of malicious code executing at import-time, a technique often associated with supply chain compromises in Python packages.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
9 days ago
102
This rule detects potential persistence via Python environment variable manipulation (PYTHONPATH) followed by suspicious network activity from a child process of python.exe. It specifically looks for the modification of the PYTHONPATH environment variable using PowerShell on Windows or shell configuration files on Unix-like systems, followed by a python.exe-initiated network connection (like curl) to external domains, which may indicate the execution of a malicious sitecustomize.py hook.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
9 days ago
002
Detects attempts to redirect Python package resolution away from the default PyPI index. This is achieved by monitoring pip CLI arguments (--index-url, --extra-index-url), environment variables (PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, PIP_CONFIG_FILE), or the creation/modification of pip configuration files (pip.conf, pip.ini). Such activity is often associated with software supply chain attacks where an adversary attempts to force the installation of malicious packages from a controlled repository.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
9 days ago
102
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
101
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
001
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
101
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
101
Detects PowerShell commands that load images (JPG/PNG) and parse their pixel data for encoded payloads. This technique, often associated with Invoke-PSImage, uses steganography to hide malicious scripts within image files, which are then extracted using GDI+ methods (GetPixel) or byte manipulation and executed in-memory via IEX or assembly reflection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
Detects suspicious command execution patterns (such as PowerShell encoded commands, IEX, or cmd.exe) being stored or accessed within the Windows Registry 'TypedPaths' key, which is used by Windows Explorer to track recently accessed paths. Adversaries may attempt to use this location to execute payloads via user-triggered interactions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
Page 30 of 1866