Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the delivery of Rapuncel infostealer via abnormally large ZIP archives that incorporate binary padding with junk DLL files (such as TitanStorage.dll or ProManager.dll). This technique is used to evade security scanners that have file size limitations. The rule tracks specific campaign filenames and junk file markers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
304
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
004
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
004
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
000
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
000
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
000
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
000
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
000
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
000
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
000
This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
000
This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
000
This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
000
This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
000
Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
000
Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
000
Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
000
This rule detects the execution of arbitrary commands via the Windows Subsystem for Linux (WSL) by monitoring process creation events where 'wsl.exe' is the executable. It specifically looks for command lines that include flags like '--exec' or '-e', or common shell commands and downloaders such as 'curl', 'wget', 'bash -c', 'sh -c', 'nc ', or 'ncat '. This activity can indicate an adversary leveraging WSL to execute malicious code or bypass security controls.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
104
Detects suspicious activities originating from CrowdStrike Falcon remediation processes (e.g., CSFalconService.exe, CSFalconContainer.exe). The rule identifies two distinct patterns: either a file operation (delete, modify, rename, quarantine, or restore) followed within 2 minutes by the loading of an unsigned or non-standard DLL, or the spawning of an elevated SYSTEM process from a non-SYSTEM parent process. This behavior is indicative of potential LPE (Local Privilege Escalation) abuse via the Falcon remediation engine, often referred to as FalconFlank-style exploitation.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
004
KQL Query from file: repeated-unauthenticated-post-to-elementor-pro-forms-endpoint-cve-2026-32475-pr.kql
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
004
Page 322 of 1871