Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation or renaming of specific files ('windowSysUpdates.txt' or 'GymTraniningShedule.exe') within the user's Local AppData directory or its 'SystemFolder32'/'System Folder32' subdirectories. This behavior is indicative of potential malicious activity, such as staged malware persistence or disguised payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the use of PowerShell to enumerate system disks, volumes, and partitions, specifically targeting removable media identifiers. This behavior is commonly associated with reconnaissance activities where an adversary attempts to identify attached storage devices for potential data staging or exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the execution of processes named 'DriverInstaller.exe' or 'Automata-20.exe', the invocation of cmd.exe as a child process of these executables, or network requests originating from these processes to GitHub API and raw content endpoints. This pattern is indicative of potential initial access, tool staging, or malicious payload retrieval.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects modifications to the Windows Registry 'Run' key or execution of commands via reg.exe or PowerShell that attempt to create or modify a persistence entry named 'DailyFitnessTracker'. This technique is commonly used by malware to ensure execution upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the creation or modification of scheduled tasks using the 'schtasks.exe' utility, specifically looking for indicators associated with persistence mechanisms such as task names or commands like 'StandAloneOneDriveUpdater-2626' and 'Automata-20.exe'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
This rule detects potentially malicious command patterns involving PowerShell and the Windows Task Scheduler. It identifies suspicious uses of Microsoft Edge update task names, PowerShell commands executing encoded scripts, and specific external download patterns associated with potential dropper or downloader activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects potential command and control (C2) beaconing activity to GitHub repository API endpoints. The rule monitors for a high frequency of requests to specific file names commonly associated with C2 payloads (e.g., command.txt, results.txt, heartbeat.txt) and employs statistical analysis to identify consistent, non-random connection patterns that deviate from expected business usage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the execution of LNK files that launch cmd.exe to execute batch script files (e.g., .bat). This pattern is frequently used in malicious infection chains, such as those leveraged by Transparent Tribe (APT36), where ISO or ZIP archives contain LNK files masquerading as document files to trick users into executing malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects malicious LNK files associated with the Transparent Tribe (APT36) campaign, which are designed to execute concealed batch scripts (e.g., doxc.bat, config.bat) via cmd.exe. These files are typically disguised as documents (resumes, details) to facilitate the deployment of secondary payloads like CrimsonRAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects persistence mechanisms used by a Golang RAT, specifically targeting the creation of a 'DailyFitnessTracker' registry value in the HKCU Run key using reg.exe or PowerShell, and the placement of 'FitnessMonitor.exe' into the Windows Startup folder.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects execution of shell commands by cmd.exe in conjunction with the creation or modification of 'command.txt' or 'results.txt' files, which are indicative of the RUSTYSHADE backdoor's C2 synchronization behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects execution of APT36's RUSTYSHADE backdoor, typically delivered via a DriverInstaller executable or zip file, and specifically tracks downloads from Backblaze B2 storage buckets using PowerShell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the establishment of persistence by the RUSTYMOVE malware through the creation of a scheduled task via PowerShell. The rule specifically looks for a command line containing both 'Register-ScheduledTask' and the specific masqueraded name 'StandAloneOneDriveUpdater-2626', which mimics a legitimate OneDrive update process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects potential CrimsonRAT backdoor binaries on Windows systems by identifying characteristic obfuscated ASISFH command tokens, embedded C2 infrastructure strings, and specific dropper file artifacts associated with Transparent Tribe (APT36).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the execution of PowerShell commands by the RUSTYMOVE tool intended to enumerate external removable storage devices (USB, SD, MMC, IEEE1394). The rule monitors for the concurrent use of Get-Volume, Get-Partition, and Get-Disk cmdlets with specific BusType filtering patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects malicious scheduled task creation using names intended to mimic Microsoft Edge update tasks. The rule identifies suspicious process activity including the spawning of conhost.exe with headless flags, PowerShell commands with encoded arguments, and attempts to fetch external scripts from the known malicious typosquatted domain indiatodays.org, all of which are characteristic of APT36 (Transparent Tribe) activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects a Golang-based remote access trojan (RAT) attributed to the Transparent Tribe (APT36) threat group. The rule identifies the malware based on distinctive fitness-themed C2 API endpoints, specific function names, hardcoded authentication secrets, and embedded Go runtime markers, while also monitoring for associated persistence registry keys and file paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the execution of a process named 'UBP.Exe' located within a 'UBP-Asset' directory at the root of a drive. This behavior is associated with the KRSID ransomware distribution campaign, which impersonates Union Bancaire Privée to lure victims into executing the fraudulent binary.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the historical HPlus HTS fraud infrastructure chain. The rule monitors for the reading of a configuration file named 'config.Ini', followed by an outbound FTP connection (port 21), and the subsequent launch of an executable, which is indicative of a Quasar RAT deployment sequence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the KRSID Rust-based ransomware binary by matching against known file hashes or by identifying specific command-line arguments and embedded file/log indicators commonly used by the malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects ISO or ZIP archive files containing a specific combination of a LNK file named 'My Resume.pdf.lnk' and a 'doxc' directory. This specific file structure is associated with Transparent Tribe (APT36) activity used to deliver malicious payloads via social engineering lures.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Page 312 of 1871