Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects activities associated with suspicious credential dumping and lateral movement tool usage, specifically targeting 'DumpIt.exe' for memory dumping, 'dokan.exe' for potential driver installation, and the creation of known suspicious files like 'memfix.zip' or 'Server.raw'. These actions are commonly indicative of post-exploitation credential harvesting and preparation for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
001
This rule detects persistence mechanisms involving the creation or modification of a specific Windows Registry Run key ('ComponentTask33Agent') within the HKEY_CURRENT_USER hive, or the execution of PowerShell commands targeting this specific registry value. This is indicative of malware, such as the ChainScript Node.js RAT, attempting to maintain access across user reboots by abusing standard Windows autostart configuration points.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
000
This rule detects persistence mechanisms involving the creation or modification of a specific Windows Registry Run key ('ComponentTask33Agent') within the HKEY_CURRENT_USER hive, or the execution of PowerShell commands targeting this specific registry value. This is indicative of malware, such as the ChainScript Node.js RAT, attempting to maintain access across user reboots by abusing standard Windows autostart configuration points.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
000
This rule detects potential persistence mechanisms and suspicious execution patterns associated with the ChainScript malware. It specifically monitors for the creation of scheduled tasks using PowerShell with indicators like 'StreamServiceSharedBridge.ps1' or 'ComponentTask33Agent', and the execution of VBScript-based agents via wscript.exe. It also flags tasks configured with specific execution time limits often associated with this malware's behavior.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
100
This rule detects potential persistence mechanisms and suspicious execution patterns associated with the ChainScript malware. It specifically monitors for the creation of scheduled tasks using PowerShell with indicators like 'StreamServiceSharedBridge.ps1' or 'ComponentTask33Agent', and the execution of VBScript-based agents via wscript.exe. It also flags tasks configured with specific execution time limits often associated with this malware's behavior.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
000
Detects EDRKiller.exe or WarsawKiller.exe binaries and the associated wsftprm.sys BYOVD driver used by The Gentlemen threat actor to terminate security product processes
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
000
Detects EDRKiller.exe or WarsawKiller.exe binaries and the associated wsftprm.sys BYOVD driver used by The Gentlemen threat actor to terminate security product processes
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
000
This rule detects potentially malicious process execution chains where VBScript or unknown/suspicious binaries (such as ProfileQuickHost.exe) are used to launch Node.js processes, specifically targeting JavaScript files or VBScript agents. This pattern is often associated with the execution of remote access trojans (RATs) or custom malware loaders.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
18 days ago
000
This rule detects the execution of mshta.exe with a command line referencing an HTA file, followed within 10 minutes by a network connection initiated by mshta.exe to a remote URL containing .js or .xml extensions. This behavior is indicative of mshta.exe being used as a proxy to execute remote malicious payloads, a common technique for fileless malware execution and defense evasion.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
104
Detects the creation of a hidden file named '.Outlook' within the user's AppData Roaming directory. This behavior is atypical for standard Outlook operations and may indicate malicious activity, such as configuration tampering, persistence mechanisms, or data staging by malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
304
This rule detects the execution of npm or node.js commands involving specific, potentially malicious package names or internal project naming patterns often associated with dependency confusion or supply chain attacks. It monitors npm/node CLI arguments for targeted library names or installation commands that deviate from standard organizational behavior.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects concurrent creation of a hexadecimal-named folder in the %TEMP% directory and a corresponding registry key in HKCU\SOFTWARE, both named with the same MD5 hash. This specific behavior is a known indicator of Casbaneiro (also known as Metamorfo) banking trojan infection, where the malware uses these locations to stage components and achieve persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
004
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects the execution of PowerShell with common obfuscation flags (-W Hidden, -nop, -nol) that attempt to load and execute a script directly from the user's local Temp directory. The detection specifically monitors for processes launched by command interpreters like cmd.exe or batch files, which is a common indicator of a malware dropper or stager.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
25 days ago
104
Detects the execution of PowerShell with common obfuscation flags (-W Hidden, -nop, -nol) that attempt to load and execute a script directly from the user's local Temp directory. The detection specifically monitors for processes launched by command interpreters like cmd.exe or batch files, which is a common indicator of a malware dropper or stager.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
25 days ago
004
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
25 days ago
004
This rule detects the execution or presence of batch files named 'Invoice Details.bat'. The use of such naming conventions in scripts is often a tactic employed in phishing campaigns to lure users into executing malicious code disguised as business-related documents.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
204
Detects network connections originating from browser processes to known JeetBot command and control (C2) infrastructure. The rule identifies suspicious C2 communication and, specifically, attempts at token exfiltration by monitoring for auth tokens in the URL of requests directed to known JeetBot hosts and Twitch-related infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
104
Detects code injection attempts targeting the Windows Media Network Sharing Service (wmpnetwk.exe), specifically monitoring for the loading of suspicious or common networking-related DLLs into this process. This behavior is indicative of an adversary attempting to mask malicious activity within a legitimate system process.
avatar
Thiru N@Iamthiru
avatar
Detections.ai Community
29 days ago
6012
Detects instances where a single process on a device performs a large number (more than 100) of file deletions or renames within a one-minute window. This behavior is indicative of potential data destruction, ransomware activity, or cleanup operations attempting to remove evidence of intrusion.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
25 days ago
104
This rule detects potential indicators of compromise related to the 'ATodaPotencia' campaign by monitoring email URL logs, process command-line arguments, and general device events for the string 'ATodaPotencia'. The rule searches across multiple data sources to identify where this specific handle or artifact appears within an environment.
avatar
F S@Fsdr
avatar
Detections.ai Community
25 days ago
204
Page 301 of 1871