Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the execution of 'mshta.exe' loading an .hta file containing specific suspicious terms ('VLC', 'Presentation', 'Denver'), followed by the spawning of child processes such as 'wscript.exe', 'cscript.exe', 'powershell.exe', 'cmd.exe', or 'wmic.exe'. This pattern is frequently used to proxy execution of malicious scripts via legitimate Windows binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This pattern can indicate suspicious activity where a legitimate updater process is being misused or abused to spawn additional malicious code or side-load components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects the presence of a 7-Zip library file ('7z.dll') located within a specific 'Traiolx Custom Utils' directory. The rule flags this file based on known malicious file hashes (MD5 or SHA256) or its specific file path. This is indicative of an adversary placing custom or potentially malicious tools on a system for archive manipulation or data staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of a specific Visual Basic script named 'Telegram_Private_Call_Session.vbs' by Windows scripting utilities (wscript.exe, cscript.exe) or the Microsoft HTML Application host (mshta.exe). This pattern is often associated with the execution of malicious scripts disguised as legitimate communication application components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of a PowerShell script named 'lightlife.ps1'. The rule flags instances where this specific script is invoked with bypass execution policies or when it is initiated by script hosts like wscript.exe or mshta.exe, which are common patterns for obfuscated or secondary script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by using reflection to modify the 'amsiInitFailed' field within the 'AmsiUtils' class. This technique is commonly used by malicious scripts to disable AMSI scanning during their execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, no profile, encoded command) initiated by wscript.exe or mshta.exe. This pattern is commonly used by adversaries to execute obfuscated malicious payloads while proxying the execution through legitimate Windows utilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects suspicious PowerShell command lines that utilize both 'Invoke-Expression' (iex) and 'Invoke-RestMethod' (irm), often used to download and execute code directly from remote sources. The rule specifically monitors for known indicators like specific IP addresses, file paths, or the concurrent use of these cmdlets in a single command line.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects attempts to disable PowerShell Script Block Logging via registry modification or by using the Set-ItemProperty command. Disabling this security feature prevents visibility into the actual contents of executed PowerShell scripts, which is a common tactic used by adversaries to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects attempts to disable PowerShell Script Block Logging via registry modification or by using the Set-ItemProperty command. Disabling this security feature prevents visibility into the actual contents of executed PowerShell scripts, which is a common tactic used by adversaries to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects outbound HTTP POST requests to a specific URL pattern (/board/fckeditor/userfiles/editor/board.php) associated with the Chinotto backdoor used by the APT37 threat group. The rule monitors for a specific Chrome user agent and a 'token=' cookie value, indicating a potential C2 check-in.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the creation of scheduled tasks using schtasks.exe that are configured to run every minute, specifically targeting command lines associated with known suspicious processes like 'codeflush.exe' or potentially masqueraded music library tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects the execution of common command-line or scripting tools (cmd.exe, powershell.exe, wscript.exe, cscript.exe, ftp.exe) or .lnk file handling triggered by explorer.exe immediately following the mounting of a VHD or VHDX file. This behavior is indicative of an attacker mounting a malicious virtual disk image and executing payloads contained within it.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects Python processes (python.exe, python3.exe, pythonw.exe) loading native library files (.pyd or .so) followed by file access to sensitive browser credential and cookie storage locations (e.g., Login Data, Cookies, Local State). This pattern is characteristic of infostealer activity, where a Python script uses a native module to decrypt or extract browser-stored credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects file creation, renaming, or deletion events within the Recycle Bin directory involving suspicious filenames or PDF files, which may indicate an adversary attempting to hide, stage, or delete evidence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule monitors for suspicious network traffic to SMTP services and specific external email addresses, as well as process command lines containing these indicators. Additionally, it tracks email events involving specific sender, recipient, and subject indicators which may be indicative of unauthorized communication or data exfiltration attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects a sequence of multiple process injection-related API calls (VirtualAlloc, WriteProcessMemory, CreateRemoteThread) initiated by a process. This rule monitors for patterns indicating cross-process memory manipulation which is commonly used to inject malicious code into other processes. It specifically looks for API calls interacting with kernel32.dll and filters out known Microsoft security products.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects high-volume account existence checks targeting the Microsoft Teams API. The rule identifies anomalous authentication attempts characterized by the use of outdated Electron/Chrome user-agent strings associated with the TeamFiltration tool, specifically targeting the Microsoft Teams API AppId (1fec8e78-bce4-4aaf-ab1b-5451cc387264).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
101
Detects two distinct suspicious activities on Android devices: the manual installation of an APK file using the 'pm' tool with specific flags, and the modification of security-sensitive settings to enable accessibility services via the 'settings' command. Both patterns are commonly associated with malicious Android applications or post-compromise activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
007
Detects outbound network traffic attempting to interact with a specific Polygon smart contract address using eth_call. This behavior is indicative of the EtherHiding technique, where adversaries leverage blockchain infrastructure as a dead-drop resolver for command-and-control (C2) operations to bypass traditional network defenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects anomalous, high-volume activity in Jira, such as mass ticket viewing, searching, exporting, or attachment downloading, which is often characteristic of unauthorized data exfiltration or reconnaissance. The detection triggers when an account exceeds thresholds of 200 issue-related actions or 8 attachment downloads within a 7-day period.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003