Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects instances where a Node.js process spawns another Node.js process to execute a JavaScript file located within the node_modules directory. This pattern is commonly observed when malware or malicious scripts attempt to execute payloads from within project dependencies, potentially hiding malicious activity within seemingly legitimate library paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
303
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
203
Detects the launch or execution of common remote access tools such as AnyDesk, TeamViewer, Quick Assist, or Microsoft Remote Assistance (msra.exe) on an endpoint, excluding instances where these tools act as the parent process. This rule serves as one component of a broader detection chain for potentially unauthorized remote access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects potentially malicious activity involving Node.js modules. It monitors for the deletion of specific 'sharedLoad.min.js' or 'extended' files within 'node_modules' directories, the execution of Node.js processes attempting file deletion operations (like 'unlink' or 'rm') within 'node_modules', and the creation or modification of JavaScript files within 'node_modules' that contain 'btree' references. This activity may indicate an attempt to tamper with application dependencies, inject malicious code, or remove artifacts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects the execution of AnyDesk within a 30-minute window of Microsoft Teams activity on the same device. This pattern is indicative of a vishing attack, where a malicious actor lures a victim into installing remote access software during a fake technical support session initiated via Teams.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects high-volume or systematic SharePoint search queries performed by a single user, specifically looking for indicators of data discovery activities such as searching for SharePoint sites, web structures, or iterating through document IDs which may suggest an adversary attempting to map or identify sensitive data within the environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects instances where a Node.js process spawns a child process, also running as node.exe, that attempts to execute a specific JavaScript file path (sharedLoad.min.js or its extended version). This behavior is characteristic of certain Node.js-based applications or potentially malicious scripts using shared loaders for modular execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects instances where the Node.js process (node.exe) is executed with a command-line argument referencing 'sharedLoad.min.js'. This is often used in web-based applications or potentially malicious obfuscated scripts, but may flag legitimate JavaScript automation tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
303
Detects the execution of the AnyDesk remote support application when initiated from a web browser (msedge.exe) or the Windows file explorer (explorer.exe). This pattern is often indicative of user-driven execution, potentially as part of a tech support scam or unauthorized remote access attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
303
Detects the installation of specific known malicious NPM packages (indexed-btree, btree-core, mutex-forge) or execution of npm install commands targeting these packages, which are indicative of software supply chain compromise attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects a Node.js process deleting specific core application files, such as 'index.js' or 'sharedLoad.min.js', located within 'node_modules' directories. This activity may indicate malicious tampering, package integrity compromise, or an adversary attempting to disrupt application functionality.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects instances where the legitimate remote desktop application AnyDesk (AnyDesk.exe) acts as the parent process to spawn a Windows command shell (cmd.exe) or execute a batch script (.bat). This behavior is often indicative of unauthorized remote access or the execution of malicious payloads by adversaries leveraging remote support tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects the modification of InProcServer32 registry keys within the user's Classes/CLSID hive to point to a file located in the AppData directory. This pattern is commonly used for COM hijacking to achieve persistence or execute arbitrary code under the user's context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects network traffic patterns indicative of Xray-core C2 tunnels using a spoofed 'dl.google.com' TLS SNI value. This activity is associated with the Aur0ra/Black Basta playbook, where Xray-core is sideloaded into legitimate processes to exfiltrate or tunnel traffic while mimicking Chrome browser TLS behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects network connections or DNS requests to domains specifically structured to impersonate MFA registration, passkey setup, or SSO login pages. These domain patterns are commonly associated with phishing campaigns intended to harvest credentials, session tokens, or bypass multi-factor authentication (AiTM phishing).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects the loading of wkspbroker.exe or radcui.dll modules from the Microsoft RemoteApp Gateway directory located within the user's AppData path. This behavior may indicate an attempt to utilize or manipulate Remote Desktop components from a non-standard or user-writable location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects a sequence of events where a user is targeted by an email bombing attack, subsequently receives an external or anonymous Microsoft Teams call, and finally launches a known remote access tool (e.g., AnyDesk, TeamViewer) on the same host within a one-hour window. This pattern is consistent with social engineering campaigns designed to trick users into providing remote access to their systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects the execution of AnyDesk or its installation from common user-writable directories (Downloads or AppData), as well as scenarios where a browser (msedge.exe) initiates an AnyDesk-related download. This is a common indicator of unauthorized remote access tool deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
Detects Node.js process executions that involve loading a suspicious JavaScript file named 'sharedLoad.min.js' or 'extended/sharedLoad.min.js'. The rule further flags instances where the process command line includes 'detached' and 'windowsHide' arguments, which are frequently used to execute Node.js scripts in the background without a visible window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects instances where a Node.js process (node.exe) attempts to execute native system discovery commands such as systeminfo, hostname, or wmic queries. This pattern is commonly observed in malicious Node.js applications or compromised environments attempting to gather system reconnaissance information.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects network connections or DNS queries made to suspicious domains that utilize MFA or credential-themed keywords (e.g., 'mfa', 'sso', 'passkey', 'register'). These domains are often used in phishing campaigns to impersonate authentication portals and harvest user credentials or MFA tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003