Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects execution or file presence associated with HOOKEDGE/HEADLACE malware. This rule uses a dual-approach: matching known malicious file hashes (SHA256) and monitoring for specific script files (bat, vbs, cmd) following a GUID-formatted naming convention typically used by the HOOKEDGE installer chain.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
002
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects the Kimsuky trojanized .NET installer OrionQuests-Setup.exe that decrypts embedded AES resource OrionSetup.payload.enc to drop a decoy OrionLauncher installer and malicious LNK file
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects known malicious files associated with Kimsuky (APT-C-55) Stella_Gary attack chain by MD5 hash: OrionQuests-Setup.exe installer, guide.url.lnk, test.bef_fri, and backdoor payload component
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects repeated, non-interactive requests to the Google Sheets Visualization API (gviz/tq) originating from common web browsers. This pattern is indicative of a malicious browser extension attempting to reconstruct or reinject payloads when a user visits specific targeted websites.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
30 days ago
806
The detection rule identifies network connections to 'dauntingmoon.online' specifically hitting '/api/verification/init' or '/api/verification/check' paths. It validates that both 'session' and 'link_id' query parameters are present in the request. This pattern is indicative of a specific adversary beaconing or command and control (C2) callback mechanism involving session-based authentication or handshake steps with a remote server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
305
Detects network connections initiated by common web browsers to a specific LinodeObjects domain or any subdomains within the linodeobjects.com infrastructure, which may indicate command and control communication or data exfiltration via legitimate cloud storage providers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
305
Detects user account logins following a recent MFA registration (within 1 to 30 days) combined with subsequent network activity that utilizes node.js applications to query the Microsoft Graph API, which may indicate account takeover or malicious persistence setup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
This rule detects successful user authentication events within the environment. It acts as a base filter to capture login success, which can be further refined with context such as IP addresses or usernames to monitor for anomalous login patterns, though it does not inherently provide detection of complex attacks like session token hijacking on its own.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects a successful authentication event where standard endpoint identification metadata (endpoint name and IP address) is absent. This often indicates logs originating from sources without proper endpoint telemetry integration or potential attempts to obfuscate the source of an authentication request.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects high-volume outbound network traffic (exceeding 100MB) generated by processes identifying as 'python-httpx' to non-internal IP addresses. This activity is often associated with automated data exfiltration using Python-based tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
This rule monitors DNS requests and network connections for activity targeting domains identified as malicious: 'gg-steelseries.com.cn' and 'org-bcut.com.cn'. These domains are often associated with command and control infrastructure or malware distribution, and their presence in network logs is a high-fidelity indicator of a potential compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
Detects executable file downloads initiated by common web browsers where the associated Zone.Identifier (Mark-of-the-Web) file lacks a ReferrerUrl. This pattern is often used by malware to conceal the source of a payload, potentially indicating a direct download or a hidden link redirection that bypassed standard referral tracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
000
This rule detects the creation of a scheduled task intended to run an executable named 'wsc_updata.exe' from a temporary directory, or identifies svchost.exe initiating a process from that location. Such behavior is indicative of potential persistence mechanisms where malicious actors attempt to run code from unauthorized or writable directories under the context of system processes or scheduled tasks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
205
This rule detects the creation of a scheduled task intended to run an executable named 'wsc_updata.exe' from a temporary directory, or identifies svchost.exe initiating a process from that location. Such behavior is indicative of potential persistence mechanisms where malicious actors attempt to run code from unauthorized or writable directories under the context of system processes or scheduled tasks.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
105
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
305
This rule detects instances where a process named 'wsc_updata.exe' executing from a Temp directory loads a library named 'wsc.dll'. This behavior is characteristic of DLL side-loading or DLL hijacking, where a malicious or potentially unwanted executable attempts to load a library from a user-writable directory to execute arbitrary code.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
105
Detects execution of a specific suspicious executable file masquerading in the Windows Temp directory, coupled with the access of an associated .ini configuration file. This behavior is indicative of AsyncRAT deployment, often involving initial execution or staging of configuration files within volatile user directories.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
101
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Page 344 of 1870