Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
003
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
003
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
903
Detects a suspicious sequence of events where msiexec.exe is launched by explorer.exe, subsequently spawning a suspended chrome.exe process. This is followed by the creation of a 'PavokwiLoader.exe' file in a 'Temp\modules' directory and the establishment of persistence by setting the 'Load' value within the 'HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows' registry key to execute the dropped loader.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
This rule detects a suspicious process execution chain where a Chrome browser process launches cmd.exe, which subsequently spawns a setup executable (setup.exe or setup.tmp), leading to the execution of 7za.exe or a Python script/artifact. This pattern is indicative of a multi-stage malware execution chain, often involving the extraction or execution of payloads dropped via web-based sources.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
This rule detects when the Node.js runtime process (node.exe) initiates the Windows command interpreter (cmd.exe) with the '/c' flag, which is commonly used to execute commands or scripts. This behavior is frequently associated with malicious Node.js activity, such as Remote Access Trojans (RATs) or web shells, which may use the shell to execute system-level operations or bypass typical application constraints.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
15 days ago
003
Detects a suspicious execution chain where a command shell (cmd.exe) launched by explorer.exe uses curl.exe to download an MSI file from Azure Blob Storage, followed immediately by the installation of that MSI using msiexec.exe. This pattern is indicative of common malware delivery techniques, such as those observed with the RVTools.lnk delivery chain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
This rule detects suspicious activity where a node.exe process, often associated with a node-pty terminal emulation, launches common Windows command-line shells (cmd.exe, powershell.exe) from specific file paths or directories. This behavior is indicative of a Node.js-based Remote Access Trojan (RAT) or shell spawning mechanism being used to establish command and control or persistence on a Windows host.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
15 days ago
103
This rule detects potential screen capture activity performed by either a suspicious executable (SearchTrustedRuntimeSvc.exe) that mimics a screen capture tool or a PowerShell script invoked by Node.js using .NET drawing libraries. This behavior is indicative of unauthorized information gathering, common in remote access trojans (RATs).
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
15 days ago
003
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
15 days ago
003
Detects the execution of PowerShell with command-line arguments that suggest programmatically capturing or redirecting console output using ScriptBlock techniques (Create, Console, In, ReadToEnd). This pattern is often associated with obfuscated script execution, in-memory payloads, or attempts to bypass logging by capturing output via .NET streams.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
Detects instances where Python interpreters (python.exe or pythonw.exe) are executed from a subdirectory within ProgramData that matches a 32-hex character pattern, initiated by the 7zip archive utility (7za.exe). This pattern is indicative of a self-extracting archive or malicious installer unpacking and executing Python scripts in a stealthy, non-standard location.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
This rule detects rundll32.exe executing a DLL from the ProgramData directory and subsequently establishing five or more outbound network connections to external IP addresses over non-standard ports (excluding 80 and 443) within a one-hour window. This behavior is indicative of a potential malware beaconing or data staging activity using a proxy binary to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
This rule detects a malicious execution chain starting with an MSI file being launched by explorer.exe from user-downloaded folders. The installer spawns chrome.exe, drops a specific loader file (e.g., PavokwiLoader.exe or Loader.exe) into the %LOCALAPPDATA%\Temp\modules\ directory, and establishes persistence via the HKCU 'Load' registry value pointing to that location.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
This rule monitors for the execution or presence of files matching a specific set of known malicious MD5 hashes within the environment. It leverages DeviceFileEvents and DeviceProcessEvents logs to identify if these specific files are being accessed or executed on managed endpoints.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
103
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
002
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
102
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
13 days ago
002
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
102
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
302
This rule monitors network traffic and DNS queries to identify endpoints attempting to connect to known cryptocurrency scam domains. It correlates data from DeviceNetworkEvents and DnsEvents to capture both direct network connections and DNS resolution attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
003