Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
106
Detects suspicious activity related to the Windows Subsystem for Linux (WSL), such as installing new distributions (especially penetration testing ones like Kali), importing custom images, or executing commands non-interactively. Attackers may use WSL to run malicious Linux binaries, hide artifacts, and evade defenses.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
106
Detects the execution of known GoCaracal malware samples, identified by specific file hashes or staging file paths, occurring in conjunction with low-level keyboard hook installations using SetWindowsHookEx. This behavior is indicative of active keylogging activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
206
Detects a pattern of multiple failed authentication attempts (brute force) from an external IP address followed by a successful authentication event on remote access services such as RDP, VPN, or NTLM. The rule filters for non-private IP addresses and flags successes occurring outside of standard business hours.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
1006
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
006
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
006
This rule detects modifications to Windows Registry persistence keys (Run and RunOnce) associated with specific suspicious filenames ('cplsupport.exe', 'wtass.exe'), as well as modifications to specific Synapse agent configuration registry keys. These patterns are often associated with persistence mechanisms or unauthorized software configuration changes.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
006
Detects the execution of an executable file located within the Windows Temp directory structure via the command prompt (cmd.exe). This pattern is commonly associated with the execution of downloaded payloads, droppers, or staged malware that are moved to temporary directories to evade initial detection.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
106
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
606
This rule detects instances where a process named 'wsc_updata.exe' executing from a Temp directory loads a library named 'wsc.dll'. This behavior is characteristic of DLL side-loading or DLL hijacking, where a malicious or potentially unwanted executable attempts to load a library from a user-writable directory to execute arbitrary code.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
206
Detects browser navigation events where the target URL is a locally generated 'blob:' URI that includes keywords associated with common credential harvesting targets (e.g., login, Microsoft 365, DocuSign). Adversaries use blob URIs to render phishing content directly from memory, which can help bypass certain static URL reputation filters and email security gateways.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
4010
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
21 days ago
001
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
000
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
000
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
Detects usage of the 'gem' command (install, build, push, publish) that includes naming patterns or specific command strings associated with the GemStuffer supply chain compromise campaign. This targets attempts to introduce malicious dependencies into the environment using RubyGems.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
002
Detects the execution of Ruby or Yard processes where specific command-line arguments (e.g., --load) are used to invoke potentially malicious Ruby script files like evil.rb, loader.rb, or script.rb. This pattern is indicative of an adversary leveraging existing legitimate tools to execute arbitrary script code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
002
Detects known malicious SilverFox payloads by comparing the file hash against a list of known SHA256 signatures associated with the malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Page 307 of 1871