Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the creation of a registry value named 'SnapCart' within the Windows Run keys. Adversaries use Run keys to ensure that malicious programs execute automatically upon user login or system startup, establishing persistence on the compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
This rule detects high-frequency, sub-second screen capture activity typically associated with malwares utilizing screen scraping to exfiltrate changed screen regions. It specifically monitors API calls related to graphical interface manipulation (BitBlt, GDI) and screen capture events, triggering when the frequency of these calls reaches a consistent, rapid interval.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects in-memory execution and stack-spoofing activities associated with the SparroWocky BOF loader (RunCOFF). It monitors for suspicious remote thread creation (EventCode 8), process access with highly permissive access masks (EventCode 10), and the loading of specific suspect DLLs (EventCode 7) that are indicative of this technique.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects network communication to known malicious infrastructure associated with the GRAYRABBIT malware campaign. The rule correlates TCP connections on port 443 to the domain 'mail.uaiubifas.top' with process events attempting to discover system and user information (GetAdaptersAddresses, gethostname, GetUserNameA), which is characteristic of the malware's initial beaconing behavior.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
25 days ago
103
Detects network communication to known malicious infrastructure associated with the GRAYRABBIT malware campaign. The rule correlates TCP connections on port 443 to the domain 'mail.uaiubifas.top' with process events attempting to discover system and user information (GetAdaptersAddresses, gethostname, GetUserNameA), which is characteristic of the malware's initial beaconing behavior.
avatar
Ankit Mehta@Secvyn
Defender - KQL
25 days ago
103
Detects the spawning of cmd.exe from 7z.exe, which is characteristic of the GRAYRABBIT malware sideloading chain where 7z.exe is used to load malicious DLLs (e.g., boy.dll, core.dll) that subsequently initiate an interactive reverse shell.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
25 days ago
103
Detects the spawning of cmd.exe from 7z.exe, which is characteristic of the GRAYRABBIT malware sideloading chain where 7z.exe is used to load malicious DLLs (e.g., boy.dll, core.dll) that subsequently initiate an interactive reverse shell.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
25 days ago
103
Detects child processes spawned by 7z.exe when it is executed from the 'C:\Users\Public\Documents\' directory. This is consistent with the behavior of the GRAYRABBIT backdoor, where a trojanized 7z.dll or boy.dll is sideloaded into the 7z.exe process to facilitate silent arbitrary process execution.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
25 days ago
003
Detects child processes spawned by 7z.exe when it is executed from the 'C:\Users\Public\Documents\' directory. This is consistent with the behavior of the GRAYRABBIT backdoor, where a trojanized 7z.dll or boy.dll is sideloaded into the 7z.exe process to facilitate silent arbitrary process execution.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
25 days ago
103
Detects anomalous behavior indicative of the GRAYRABBIT shellcode which uses manual module walking and hash-based API resolution to load 'urlmon.dll' dynamically, followed shortly by an outbound network connection to a known malicious staging IP. This pattern reflects an evasion technique designed to avoid static import table analysis.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Detects child processes spawned by 7z.exe when it is executed from the 'C:\Users\Public\Documents\' directory. This is consistent with the behavior of the GRAYRABBIT backdoor, where a trojanized 7z.dll or boy.dll is sideloaded into the 7z.exe process to facilitate silent arbitrary process execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Detects potential data exfiltration activity associated with the GRAYRABBIT threat actor, where a local file is accessed or modified by a process shortly before or after that same process initiates a network connection to a known GRAYRABBIT C2 endpoint over port 443.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Detects the spawning of cmd.exe from 7z.exe, which is characteristic of the GRAYRABBIT malware sideloading chain where 7z.exe is used to load malicious DLLs (e.g., boy.dll, core.dll) that subsequently initiate an interactive reverse shell.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Detects behavior indicative of the GRAYRABBIT malware, specifically identifying network connections to known command-and-control (C2) infrastructure (mail.uaiubifas.top) followed within a short time window (10 minutes) by reflective in-memory module loading activities within the same process. This pattern suggests the delivery and execution of a plugin or additional malicious payload without writing the binary to disk.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
103
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
Detects potential exploitation of CVE-2025-3248 in Langflow by identifying suspicious inbound network traffic targeting the /api/v1/validate/code endpoint, correlated with subsequent python child processes containing base64 decoding and execution primitives such as eval, exec, or subprocess.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
Detects the creation of mutexes or named pipes containing the string 'SALITY', which is a characteristic indicator of the Sality malware family.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
005
This rule detects potential credential dumping attempts targeting the Local Security Authority Subsystem Service (LSASS) process. It identifies suspicious file execution based on a blocklist of known credential dumping utility hashes, unauthorized OpenProcess calls to lsass.exe with specific access rights, and the creation of process memory dump files (e.g., .dmp, .dump) correlated with an lsass.exe access event.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
22 days ago
001
This rule detects potential DLL side-loading activity by identifying when known malicious file hashes are loaded by a specific set of executable files that are commonly abused for side-loading, or when these executables are executed from locations outside of their standard, verified installation directories.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
22 days ago
001
This rule detects potential DLL side-loading activity by identifying when known malicious file hashes are loaded by a specific set of executable files that are commonly abused for side-loading, or when these executables are executed from locations outside of their standard, verified installation directories.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
22 days ago
001
Page 318 of 1871