Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects remote command execution using WMI by monitoring RPC calls to the IWbemServices interface (UUID {9556DC99-828C-11CF-A37E-00AA003240C7}). The rule specifically targets the ExecMethod operation (opnum 24) commonly used by tools like Impacket's wmiexec to execute Win32_Process.Create on remote targets. Filter for COMSPEC to increase fidelity for detecting wmiexec.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
28 days ago
205
Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects the creation of executable or script files within non-system directories that were initiated by the OneDrive sync process. This activity may indicate a user downloading malicious files via a compromised OneDrive account or a malicious payload being synced to the local system.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
19056
Detects suspicious modifications to browser 'Secure Preferences' files associated with known bypass techniques for extension integrity checks, coupled with browser process termination and subsequent relaunch using the --restore-last-session flag. This pattern is consistent with adversary activity attempting to inject malicious browser extensions by manipulating browser configuration files.
avatar
Thiru N@Iamthiru
avatar
Detections.ai Community
29 days ago
106
Detects anomalous child processes spawned by a Chrome renderer process. This behavior is often indicative of exploitation attempts, such as the BlueMoon exploit kit leveraging CVE-2026-85046, where a compromised renderer attempts to escape the sandbox or execute arbitrary code in the host process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
106
Detects anomalous child processes spawned by a Chrome renderer process. This behavior is often indicative of exploitation attempts, such as the BlueMoon exploit kit leveraging CVE-2026-85046, where a compromised renderer attempts to escape the sandbox or execute arbitrary code in the host process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
206
Detects the execution of REAgentC.exe with the /disable command-line argument. This utility is used to manage the Windows Recovery Environment (WinRE). Adversaries often disable WinRE to prevent system recovery and impede incident response, often as a prelude to data destruction or ransomware attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects the frequent clearing of specific Windows Event Logs using the built-in wevtutil.exe utility. Attackers often clear logs to hide evidence of post-exploitation activity such as credential access, lateral movement, or persistence installation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects instances where PowerShell or PowerShell ISE performs suspicious process injection activities, specifically targeting executables such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe, or utilizes specific remote thread/memory allocation functions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects PowerShell command lines that attempt to hide the console window by calling ShowWindowAsync from user32.dll while assigning a randomly generated GUID as the window title. This technique is used to evade detection by keeping malicious PowerShell activity invisible to the user, as seen in recent StealC infostealer loader chains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects the execution of the Windows Event Utility (wevtutil.exe) with the 'cl' (clear-log) command, specifically targeting multiple critical event logs simultaneously. This behavior is indicative of anti-forensic activity aimed at obfuscating post-compromise actions, as seen in the Settra ransomware campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects Git checkout operations executed by AI coding agent processes that specify a full 40-character commit hash or use 'FETCH_HEAD'. This behavior is indicative of potential supply chain attacks, specifically the 'Plugin4Shell' vulnerability, where malicious actors attempt to force the agent to checkout arbitrary, potentially malicious, repository references.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects the use of the 'wevtutil.exe' command to clear Windows Event Logs where the command specifies a misspelled event log name, 'Microsoft-Windows-Defender/Operational' instead of the correct 'Microsoft-Windows-Windows-Defender/Operational'. This specific spelling error is associated with the Settra ransomware and indicates an unsuccessful attempt to clear Windows Defender logs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects Git commands initiated by AI coding agent processes that perform a checkout of a specific 40-character SHA hash or a FETCH_HEAD reference. This behavior is potentially indicative of a supply chain attack where an AI plugin agent is being instructed to swap code components or load specific, potentially malicious, commit versions from a remote repository.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects .NET malicious payloads associated with the StealC info-stealer by identifying anti-debugging and anti-analysis routines. The rule specifically looks for the usage of System.Diagnostics.Debugger methods (IsAttached, IsLogging), native debugger presence checks (IsDebuggerPresent, CheckRemoteDebuggerPresent), and Environment.FailFast usage, often in combination with obfuscation markers like ConfuserEx.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects .NET malicious payloads associated with the StealC info-stealer by identifying anti-debugging and anti-analysis routines. The rule specifically looks for the usage of System.Diagnostics.Debugger methods (IsAttached, IsLogging), native debugger presence checks (IsDebuggerPresent, CheckRemoteDebuggerPresent), and Environment.FailFast usage, often in combination with obfuscation markers like ConfuserEx.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects the creation of a specifically named shortcut (.lnk) file in the Windows Startup directory, a common persistence mechanism used by StealC/ClickFix malware variants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Page 335 of 1871