Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the execution of COM files located in the AppData\Local directory with a numeric filename and specific command-line arguments indicative of file transfer or proxying tools like curl/wget wrappers.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
28 days ago
104
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
107
This rule detects processes manually resolving API function addresses by traversing the Process Environment Block (PEB) Ldr structure or parsing module export tables. This technique is often used by malicious code to resolve Windows API functions dynamically without relying on standard LoadLibrary or GetProcAddress calls, effectively evading common API-hooking based monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
001
Detects processes registering a Vectored Exception Handler (VEH) while simultaneously performing memory write operations and thread context modifications. This behavior is highly indicative of advanced process injection techniques, such as using VEH as a redirection mechanism to execute raw syscalls or malicious shellcode within a target process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects indicators of the MovieReaper loader, specifically the downloading of shellcode fragments disguised as image assets from known malicious C2 infrastructure, and the masquerading of a malicious binary as 'msedge.exe' within the Windows Telemetry folder for persistence. The rule specifically targets the loader's behavior of using PEB Ldr traversal to resolve APIs and evade hooking-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects artifacts associated with the CRUDEEXCLUDE Delphi-based loader, which is used to deploy the HEAVYGRAM backdoor. The rule identifies a combination of Delphi indicators, anti-analysis sandbox connectivity checks, decoy message boxes, and attempts to modify Windows Defender exclusions for specific paths associated with the malware's activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects the HEAVYGRAM malware utilizing the Telegram Bot API to download file attachments, followed by the extraction of an archive using PowerShell to a masqueraded directory (C:\ProgramData\Kee_Pass), and the subsequent execution of a binary masquerading as KeePass.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
000
Detects instances where a Visual Studio Code (VS Code) extension host process launches potentially suspicious child processes, specifically command-line tools like cmd.exe, powershell.exe, or calc.exe, within 30 seconds of the extension host starting.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
000
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
000
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
000
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
000
Detects instances where a Visual Studio Code (VS Code) extension host process launches potentially suspicious child processes, specifically command-line tools like cmd.exe, powershell.exe, or calc.exe, within 30 seconds of the extension host starting.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects modifications or creation of the VS Code 'settings.json' file within a '.vscode' folder where the configuration includes 'workbench.startupEditor' and 'readme'. This pattern is frequently used in malicious extensions or malicious repository configurations to trick users into opening a malicious README file upon starting the editor, potentially leading to further compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects the installation of Visual Studio Code extensions via the command line interface using the Code.exe process. Adversaries may abuse VS Code extensions to achieve code execution or persistence by installing malicious .vsix files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
1011
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
2011
Page 342 of 1870