Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
This rule monitors the Windows Application event log for critical Microsoft SQL Server (MSSQL) events. It detects server crashes, access violations, stack overflows, and high-severity (20+) errors. These events often indicate severe database corruption, underlying system instability, or potential exploitation attempts targeting the database engine.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
005
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
205
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
105
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
001
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
104
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
avatar
Arnold Chan@slaz
Defender - KQL
26 days ago
104
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
avatar
Arnold Chan@slaz
Defender - KQL
26 days ago
104
Detects the execution of BloodHound/SharpHound reconnaissance tools and the presence of their generated output files (ZIP or JSON format) on a host. This rule monitors both the process creation events associated with the tool's execution and file creation events indicative of data staging or collection output.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
104
Detects the execution of BloodHound/SharpHound reconnaissance tools and the presence of their generated output files (ZIP or JSON format) on a host. This rule monitors both the process creation events associated with the tool's execution and file creation events indicative of data staging or collection output.
avatar
Arnold Chan@slaz
Defender - KQL
26 days ago
104
Detects the use of obfuscated PowerShell commands that utilize .NET [Convert]::FromBase64String combined with character replacement string manipulation, a common technique to hide malicious payloads from simple static analysis.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
203
Detects obfuscated PowerShell commands that utilize XOR operations combined with byte array manipulation and common file writing methods. This pattern is frequently used by malicious scripts to deobfuscate and drop payloads to disk.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Detects the execution of PowerShell with common obfuscation flags (-W Hidden, -nop, -nol) that attempt to load and execute a script directly from the user's local Temp directory. The detection specifically monitors for processes launched by command interpreters like cmd.exe or batch files, which is a common indicator of a malware dropper or stager.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Detects the creation or execution of suspicious .bat files within the Windows Startup folder, often coupled with command-line arguments involving .ini files. This behavior is indicative of persistence mechanisms where adversaries leverage the startup folder to ensure malicious scripts run upon user logon.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
203
Detects suspicious execution of files located in the AppData Local Temp directory initiated by PowerShell or using PowerShell-specific hidden window arguments. This behavior is commonly associated with dropper scripts or malware staging execution from a user's temporary folder.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
003
Detects the creation or modification of a file with a specific randomized name ('nloemfbihmhm') in the temporary directory, followed by the execution of a process identified as AutoIt from the same directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
003
This rule detects the process 'charmap.exe' establishing an outbound network connection to a known AsyncRAT command-and-control (C2) IP address and port. This behavior is indicative of process injection where the legitimate Windows Character Map utility is utilized as a host process for malicious AsyncRAT payload execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Page 315 of 1871