Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
201
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
001
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
006
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
001
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
201
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
This rule detects potentially malicious activity by monitoring the execution of Python interpreters or specific suspicious executable names from within the C:\ProgramData directory. The detection logic focuses on processes launching from directories associated with configuration or data storage folders, often used by malware for staging or execution to avoid detection. It specifically flags Python execution involving certain suspicious file or argument strings, and the launch of named executables (e.g., RuntimeSSH.exe, smqdservice.exe) located in specific ProgramData subdirectories.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
This rule detects potentially malicious activity by monitoring the execution of Python interpreters or specific suspicious executable names from within the C:\ProgramData directory. The detection logic focuses on processes launching from directories associated with configuration or data storage folders, often used by malware for staging or execution to avoid detection. It specifically flags Python execution involving certain suspicious file or argument strings, and the launch of named executables (e.g., RuntimeSSH.exe, smqdservice.exe) located in specific ProgramData subdirectories.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
This rule detects potentially malicious activity by monitoring the execution of Python interpreters or specific suspicious executable names from within the C:\ProgramData directory. The detection logic focuses on processes launching from directories associated with configuration or data storage folders, often used by malware for staging or execution to avoid detection. It specifically flags Python execution involving certain suspicious file or argument strings, and the launch of named executables (e.g., RuntimeSSH.exe, smqdservice.exe) located in specific ProgramData subdirectories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
Page 333 of 1871