Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where a new executable file (.exe) is written to the file system following a download event. The rule specifically looks for scenarios where the download URL ends in .exe or is a direct download link, while flagging cases where the referrer is empty or missing, often indicative of direct downloads from C2 infrastructure or scripts rather than user-initiated browser navigation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
102
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
202
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
002
Detects download or installation attempts of specific trojanized versions (2.35 and 2.36) of the Admin Menu Editor Pro plugin, which were distributed via a compromised update channel on adminmenueditor.com.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
002
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
001
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
001
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
001
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
001
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
001
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule detects a multi-stage malicious behavior chain: the execution of a suspected loader (identified by hash or specific mutex), followed by network communication to a known C2 domain or IP, and concluded by the placement of a file in the Windows Telemetry folder (typically mimicking msedge.exe). The events are correlated within a short time window (2 hours between each stage) on the same device.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
101
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
001
Page 308 of 1871