Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
000
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects PowerShell command execution that uses bitwise XOR operations combined with the .NET [IO.File]::WriteAllBytes method. This pattern is commonly used by malware, such as AsyncRAT, to deobfuscate and drop secondary payloads or modules onto the file system during execution.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
001
This rule detects potential persistence mechanisms where a suspicious batch file (.bat) is placed within the Windows Startup folder and subsequently executed using command-line arguments that include specific file extensions like .exe and .ini. This behavior is indicative of malware, such as remote access trojans (RATs), attempting to maintain persistence upon system reboot.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
001
Detects suspicious service installation patterns involving WmiPrvSE, common in lateral movement techniques.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
106
Detects a network connection to potentially malicious infrastructure or non-standard ports following a request to ipify.org, which is commonly used for external IP reconnaissance by malware and C2 frameworks.
avatar
Renata Cardoso@rcardososec
avatar
Detection & Hunting Community
1 month ago
15060
Page 345 of 1870