Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the use of the Windows 'net' or 'net1' utility to connect to the hidden 'IPC$' inter-process communication share. This behavior is often associated with lateral movement, reconnaissance, or establishing authenticated sessions to remote systems for further malicious activity, such as remote command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
This rule logs the execution of 'UBPUpdater.exe'. While the purpose of this binary is not inherently malicious, tracking its execution can be useful for auditing software updates or identifying unauthorized applications running on the system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
This rule monitors network traffic to GitHub API endpoints and categorizes the activity based on APT36's known operational window (weekdays, 04:00-11:00 UTC). Traffic patterns deviating from this schedule are flagged as anomalous, helping to identify potential C2 communication outside of established threat actor activity windows.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects instances where a process named UBP.Exe spawns a child process named HTSPnew.Exe, specifically when both binaries reside within the same directory path containing 'UBP'. This behavior may indicate an application-specific pattern or potentially malicious execution where one component of a suite invokes another.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects instances where cmd.exe or wscript.exe are executed from explorer.exe or via a .lnk file, which is a common pattern for initial access and execution of malicious payloads, often seen in spearphishing scenarios involving obfuscated or disguised files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
This rule detects potential ransomware activity by monitoring for specific file naming patterns associated with known ransom notes (.krsid, README_KRSID.Txt) and the execution of suspicious processes (HTSPnew.Exe, UBPUpdater.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects execution of processes associated with QuasarRAT or references to its configuration files, originating from or involving files and processes named 'UBPUpdater.exe' or 'UBPPatch.Psh'. Also identifies network connections via FTP or involving configuration files ('config.Ini') initiated by these specific processes, which may indicate malicious activity, command and control, or data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
This rule detects potentially malicious file manipulation activities, such as renaming, moving, copying, or deleting files, specifically when involving targeted filenames (e.g., 'GymTraniningShedule.exe') or locations (e.g., 'SystemFolder32'). The detection monitors for suspicious command-line arguments executed by 'cmd.exe' or 'conhost.exe' and cross-references them with file deletion events involving '.lnk' files or specific application artifacts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the use of mklink.exe or cmd.exe with mklink arguments to create symbolic links associated with specific file paths (ProgramData\doxc) or specific suspicious filenames (hzwzucr_widsisa.exe). This behavior is often associated with malware persistence or evasion, where adversaries link malicious binaries to disguise their location or execution source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the execution of PowerShell commands containing indicators of AMSI or ETW unhooking (e.g., references to amsi.dll, AmsiScanBuffer, EtwEventWrite, or VirtualProtect). This activity is commonly associated with attackers attempting to bypass endpoint security telemetry and antimalware scanning mechanisms prior to executing malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
003
This rule detects the installation or modification of ScreenConnect services on Windows endpoints. It monitors for the creation of services using 'sc.exe', process commands related to ScreenConnect setup executables, or registry modifications and service installations associated with specific ScreenConnect identifiers, often indicative of unauthorized remote management software installation.
avatar
Vignesh Keshavan@illusion07
avatar
Detections.ai Community
26 days ago
104
Detects the Stella_Gary .NET backdoor loader used by Kimsuky/APT-C-55, identified by managed-layer reflective assembly loading strings (loader.Program.Main, AssemblyResolve callback, Stella_Gary.Program.Main)
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
Detects the Stella_Gary .NET backdoor loader used by Kimsuky/APT-C-55, identified by managed-layer reflective assembly loading strings (loader.Program.Main, AssemblyResolve callback, Stella_Gary.Program.Main)
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
001
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
001
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
001
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
001
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
001
This rule monitors for network connections, firewall traffic, and Entra ID authentication events involving known malicious IP addresses (the 'Wall of Shame'). The rule specifically flags interactions occurring over common VPN ports, suggesting potential unauthorized access or persistence attempts via VPN services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
26 days ago
104
Detects network connection events to known domains and subdomains associated with the SilkParasite threat actor. The rule specifically monitors for connections to specific parent domains (natcommunzu.com, kginfocom.com, mfa-uz.com) and subdomains utilizing service-oriented naming patterns (e.g., mail, service, help, storage, support, microsoft, post) commonly used by this actor for command and control infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
001
Page 313 of 1871