Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects when common torrent client applications spawn a child process that is an executable. This behavior is often associated with the execution of malicious payloads delivered or masqueraded as files within torrent environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects modifications to the Windows 'Run' registry key intended to achieve persistence by launching potentially malicious executables named 'RuntimeSSH.exe' or 'winappx.exe'. Attackers often use these paths to ensure that their malicious code executes automatically upon user login.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects the loading of a module named 'MicDriver.dll' or the execution of a process named 'MicDriver.exe'. These filenames are potentially indicative of malicious activity using masquerading or attempts to hijack execution flow using filenames that resemble legitimate audio drivers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects potentially malicious script execution patterns, specifically targeting Windows Script Host (wscript.exe) invoking .vbs or .wsf files, and PowerShell execution involving suspicious command line arguments such as encoding (-enc), external URL downloading, or attempts to execute or archive files (Expand-Archive, WebClient DownloadFile).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the execution of a file named 'msedge.exe' residing within the C:\ProgramData\Microsoft\Windows\Telemetry\ directory. Microsoft Edge typically resides in 'C:\Program Files (x86)\Microsoft\Edge\Application\', making execution from the telemetry directory highly suspicious and indicative of potential process masquerading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects potentially malicious activity by monitoring for a specific executable file name ('msedge.exe') located in a non-standard path ('ProgramData'), as well as network connections to a known malicious IP address ('193.23.118.155') and DNS requests for a domain associated with suspicious activity ('deadhub.org').
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects the execution of a file with a suspicious media-themed filename (e.g., related to 1080p, BluRay, etc.) from a known BitTorrent client process, followed by an immediate network connection to a known malicious C2 IP address or domain within a 10-minute window. This behavior is indicative of a user downloading and executing a malicious file disguised as pirated media.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects the execution of a specific known malicious file (identified by MD5 hash A0B13781EDD7CFDAB13D79AFFF3C83C1) followed by an outbound network connection to a suspicious IP address (193.23.118.155) or domain (deadhub.org) within a 10-minute window. This behavior is indicative of a malicious loader establishing a command and control (C2) channel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the execution of known development, scripting, and administrative tools (e.g., Python, Node.js, GCC, Docker) from non-standard or unauthorized file paths. The rule leverages allowlists for process names, publishers, and trusted installation directories to identify potentially unauthorized usage of powerful tooling often abused by attackers for post-exploitation activities.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
103
This rule detects potential persistence and execution activity associated with the HEAVYGRAM implant. It monitors for registry value modifications in the Windows Run keys by known malicious file names, as well as process execution events where those same files are executed with command-line arguments typically used for registry manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the use of PowerShell to modify Microsoft Defender (MpPreference) settings by adding specific directories or files to the exclusion list. This behavior is frequently associated with adversaries attempting to evade security detection by ensuring malicious tools, staged payloads, or persistent files remain unscanned by the antivirus engine.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the execution of suspicious binaries that are spawned by known torrent clients or appear to masquerade as media files (e.g., using movie quality naming conventions like 1080p, Bluray). This rule identifies potential delivery of malicious payloads via P2P file sharing environments by looking for specific process patterns and filename indicators associated with file masquerading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects memory allocation operations in processes where the protection mask is set to PAGE_EXECUTE_READWRITE (0x40). This behavior is often associated with code injection techniques, where an adversary allocates memory with write and execute permissions to load or execute malicious payloads in memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects suspicious thread injection activities (CreateRemoteThreadApiCall, NtCreateThreadEx, or RtlCreateThread) or the loading of 'ntdll.dll' by specific potentially unauthorized binaries (e.g., RuntimeSSH.exe, smqdservice.exe, etc.) or within the 'ProgramData\Microsoft\Windows\Telemetry' directory. This often indicates reflective code injection or process tampering, excluding known legitimate Windows system processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects anomalous mass file enumeration, creation, deletion, and renaming activity within common system or temporary directories, indicative of the MovieReaper stage-4 file manager module. The rule monitors for the execution of command-line utilities (cmd.exe, powershell.exe) with specific file management arguments followed by a high volume of file system operations within a 5-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects execution of a process masquerading as msedge.exe located within the Windows Telemetry directory. This behavior is associated with the MovieReaper malware, specifically as a stage-3 payload activity following UAC bypass and persistence establishment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects a Delphi-compiled Windows Screen Saver (.scr) file acting as a dropper. The binary contains embedded RCDATA ZIP resources and utilizes Persian-language filenames related to academic or student-focused lures to trick victims into execution. This rule specifically identifies the presence of the dropper's strings and the Borland Delphi marker.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects sophisticated process injection behavior where malicious shellcode is mapped into RWX memory. The payload utilizes a Vectored Exception Handler (VEH) and deliberate 0xCC (breakpoint) instructions to intercept execution and redirect it into raw syscall stubs (e.g., NtProtectVirtualMemory). This technique is designed to bypass security product API hooking by avoiding standard calls to memory protection functions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects creation of .git-checker files in temporary directories, a pattern associated with potential malicious activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
Detects a Node.js process executing a JavaScript file that spawns a secondary Node.js child process, followed immediately by the creation or modification of Windows Run registry keys for persistence. This sequence is indicative of malicious npm package activity where a secondary, hidden payload is downloaded and configured to execute upon system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the GHAPPIER loader pattern: a top-level require('https').get() call to the primevector-app924560.vercel.app C2 that evals the response, disguised inside a large benign-looking JavaScript benchmark file
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
000
Page 303 of 1871