Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of cmd.exe with command-line arguments typical of self-deleting batch scripts. The pattern includes a delay (timeout /t 2) followed by a file deletion command (del), often used to remove temporary scripts or malicious artifacts after execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the creation of threads where the entry point or call stack is associated with 'kernel32.dll' but originates from memory regions that are unbacked by a file on disk (i.e., 'unbacked', 'unknown') or have a null return address. This pattern is highly indicative of reflective code injection or manual shellcode execution, where an adversary attempts to execute code within a legitimate Windows process without a corresponding file-backed image.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the execution of a process named 's.exe' (or similar match) with a command-line argument consisting of a single character 's' followed by a digit. This pattern is commonly associated with malicious usage or obfuscation, where 's.exe' might be a renamed utility or a malicious artifact attempting to masquerade or execute specific tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the installation or update of browser extensions that utilize 'declarativeNetRequest' or 'webRequest' APIs in conjunction with 'content_scripts' and either broad URL access ('all_urls') or access to sensitive web domains (e.g., Google Gemini, Microsoft Copilot, Perplexity, Claude). This combination is highly indicative of extensions designed for data interception, credential theft, or unauthorized web traffic manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
101
Detects instances where the Chrome browser process accesses camera or microphone hardware, or invokes media device APIs, potentially indicating unauthorized audio or video recording.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects rapid, repetitive state change operations (such as think, act, or mode changes) occurring within the Microsoft Edge browser context when interacting with Microsoft domains. This behavior is indicative of automated browser interactions, such as those performed by botnets, automated testing frameworks, or potentially malicious browser automation scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects potentially malicious attempts to import certificates into the Windows certificate store using command-line tools like certutil or direct modification of the registry. This behavior is frequently associated with attackers attempting to establish persistence, bypass certificate validation, or install rogue trust anchors for man-in-the-middle operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects instances where common web browsers (Chrome, Edge, Firefox, Safari) or related desktop applications spawn shell interpreters (PowerShell on Windows, bash/zsh/sh on macOS) with command-line arguments indicative of malicious activity, such as base64-encoded payloads, hidden windows, or remote script downloading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects potentially unauthorized installation of root certificates on Windows and macOS systems. Attackers use this technique to bypass security warnings, establish adversary-in-the-middle capabilities, or inspect encrypted traffic by adding their own certificates to the system's trust store.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects the loading of specific DLLs (winfsp-x64.dll or dukeqt.dll) by processes from locations outside of the standard Windows System32 or SysWOW64 directories. This behavior is indicative of DLL side-loading, where an adversary attempts to execute malicious code by placing a rogue DLL in a path where a legitimate application might attempt to load it, or by intentionally side-loading it alongside an executable.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects browser-based processes (Chrome, Opera, Edge) making network requests to AI and cloud service domains (Google Gemini, Claude, Opera). This rule monitors for potentially unauthorized or excessive browser communication with these services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the creation of compressed archive files (zip, rar, 7z, dat) followed by a significant network upload (exceeding 5MB) on the same host within a 30-minute window, which is indicative of staging and exfiltrating collected data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects instances where the Google Chrome browser process interacts with files or registry keys associated with audio and video capture devices, such as cameras and microphones. This may indicate unauthorized use of media peripherals by the browser process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the loading of specific DLLs ('winfsp-x64.dll' or 'DukeQt.dll') where the module path is empty or null. This behavior is indicative of potential memory-only execution or process injection (e.g., reflective loading), as the module is not associated with a valid file on disk.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects the presence of known synchronization objects (mutexes, events, or shared memory) associated with SparroWocky malware, identified via Microsoft Defender DeviceEvents and DeviceProcessEvents telemetry. The rule monitors for these specific markers in process creation, remote thread creation, and named pipe events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule identifies potential SparroWocky malware payload files by detecting a specific custom header (0x11328712 in both little-endian and big-endian format) used for identifying encrypted .dat files that contain embedded RC4 keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects a process loading English (.en-US) MUI resource files from the C:\Windows\System32\en-US\ directory when the initiating process is located outside of standard system directories (System32, SysWOW64, Program Files). This behavior is indicative of a masquerading or camouflage technique where a malicious executable attempts to mimic a legitimate system process by loading its localized resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects remote thread creation where the start function address is identified as 'AnimateWindow'. This behavior is associated with the SparroWocky technique, which uses thread execution hijacking by pointing the thread start address to legitimate UI-related Windows APIs to mask the actual malicious entry point, thereby evading traditional detection mechanisms that monitor for suspicious thread start addresses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule monitors for indicators of code execution anomalies commonly associated with process injection, ROP (Return-Oriented Programming) chains, or memory manipulation. It specifically looks for spoofed call stacks, return address validation failures, suspicious API usage in common thread initialization routines, and ROP gadgets within critical modules like kernel32.dll.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects potential masquerading activity where an executable is signed by 'Discord Inc' or 'Lenovo' but the image path does not correspond to expected legitimate installation directories or filenames. It flags processes that claim a trusted publisher identity while residing in suspicious or unexpected locations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects ClickFix-style activity where a web browser or common application launcher spawns a terminal or PowerShell process to execute obfuscated, copied, or piped commands. This behavior often indicates a social engineering attack where a user is tricked into manually executing a malicious command script.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Page 317 of 1871