Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
002
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
002
This rule detects unauthorized processes modifying the 'Secure Preferences' configuration file in Google Chrome or Microsoft Edge browser data directories. This activity often indicates an attempt by malicious software to hijack browser settings, such as forcing extensions or modifying security policies, which is a common precursor to credential theft or persistent malicious access.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
002
This rule detects unauthorized processes modifying the 'Secure Preferences' configuration file in Google Chrome or Microsoft Edge browser data directories. This activity often indicates an attempt by malicious software to hijack browser settings, such as forcing extensions or modifying security policies, which is a common precursor to credential theft or persistent malicious access.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
This rule detects unauthorized processes modifying the 'Secure Preferences' configuration file in Google Chrome or Microsoft Edge browser data directories. This activity often indicates an attempt by malicious software to hijack browser settings, such as forcing extensions or modifying security policies, which is a common precursor to credential theft or persistent malicious access.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
002
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
002
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
002
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
002
This rule monitors endpoint network events, file operations, and process executions for known malicious indicators (domains and file hashes) associated with Kremlin activity. It detects connections to suspicious remote domains and the existence or execution of specific malicious file hashes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
This rule monitors endpoint network events, file operations, and process executions for known malicious indicators (domains and file hashes) associated with Kremlin activity. It detects connections to suspicious remote domains and the existence or execution of specific malicious file hashes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
002
This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
002
This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
002
This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
002
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
Detects instances where the VLC Media Player process (vlc.exe) acts as the parent to common LOLBAS (Living Off the Land Binary and Script) executables such as cmd.exe, powershell.exe, and others. This pattern is often indicative of exploitation attempts or malicious activity where a compromised or trojanized application triggers secondary payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
305
Matches known Phantom Stealer MaaS infostealer sample hashes
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
003
Matches known Phantom Stealer MaaS infostealer sample hashes
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
003
Matches known Phantom Stealer MaaS infostealer sample hashes
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
103
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
103
Page 310 of 1871