Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects the HEAVYGRAM malware utilizing the Telegram Bot API to download file attachments, followed by the extraction of an archive using PowerShell to a masqueraded directory (C:\ProgramData\Kee_Pass), and the subsequent execution of a binary masquerading as KeePass.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
000
Detects instances where a Visual Studio Code (VS Code) extension host process launches potentially suspicious child processes, specifically command-line tools like cmd.exe, powershell.exe, or calc.exe, within 30 seconds of the extension host starting.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
000
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
000
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
000
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
000
Detects instances where a Visual Studio Code (VS Code) extension host process launches potentially suspicious child processes, specifically command-line tools like cmd.exe, powershell.exe, or calc.exe, within 30 seconds of the extension host starting.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects modifications or creation of the VS Code 'settings.json' file within a '.vscode' folder where the configuration includes 'workbench.startupEditor' and 'readme'. This pattern is frequently used in malicious extensions or malicious repository configurations to trick users into opening a malicious README file upon starting the editor, potentially leading to further compromise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects the installation of Visual Studio Code extensions via the command line interface using the Code.exe process. Adversaries may abuse VS Code extensions to achieve code execution or persistence by installing malicious .vsix files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
1011
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
2011
Detects execution and file activity associated with the XRed backdoor, which masquerades as 'Synaptics.exe' by running from the non-standard 'C:\ProgramData\Synaptics\' directory instead of authorized system paths.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
27 days ago
003
This rule detects suspicious command executions (e.g., whoami, downloadstring, iex, registry modifications) initiated by processes associated with the CrowdStrike Falcon agent. It also correlates these executions with the loading of unsigned or unverifiable DLLs by the same Falcon processes within a 5-minute window, which may indicate attempts to tamper with or masquerade as the security agent.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
16038
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
IOC hunt for the HEAVYGRAM/CRUDEEXCLUDE campaign: matches known SHA256 file hashes (first-stage malware, implant, RAR/ZIP artefacts) via DeviceFileEvents and DeviceProcessEvents, plus known-malicious domains/staging infrastructure by parsed hostname across network connections, process command lines, and file origin URLs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
IOC hunt for the HEAVYGRAM/CRUDEEXCLUDE campaign: matches known SHA256 file hashes (first-stage malware, implant, RAR/ZIP artefacts) via DeviceFileEvents and DeviceProcessEvents, plus known-malicious domains/staging infrastructure by parsed hostname across network connections, process command lines, and file origin URLs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Page 343 of 1871