Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects unauthorized attempts to disable or stop critical Windows Update services (wuauserv, UsoSvc, uhssvc, WaaSMedicSvc) via command line tools or service configuration changes. This behavior is indicative of defense evasion by malware such as Silver Fox/Gh0st RAT, aimed at preventing security updates or disabling security-related service monitoring.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
1 month ago
13130
This rule detects PowerShell processes spawned directly or indirectly by LNK files that include command-line arguments indicative of anti-analysis, anti-VM, or reconnaissance techniques. These include querying for specific WMI classes (e.g., Win32_Process, Win32_ComputerSystem), checking for virtualization artifacts (e.g., 'virtualbox', 'vmware', 'qemu', 'sandboxie'), or querying security and hardware information (e.g., 'antivirusproduct', 'securitycenter2', 'getmac').
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the use of .NET reflection methods (such as Assembly.Load or LoadFrom) within command-line arguments of processes frequently abused for secondary execution (e.g., rundll32.exe, regsvr32.exe) when initiated by common scripting or execution engines like PowerShell, cmd.exe, or mshta.exe. This pattern is indicative of fileless malware execution or reflective assembly loading commonly used to bypass traditional signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the loading of the 'user32.dll' library into a process named 'firefox.exe' where the process is either unsigned or executing from a suspicious location like 'ProgramData'. This pattern is consistent with the behavior of BabylonRAT, which masquerades as the Firefox browser to perform keylogging by hooking system APIs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule detects instances of a process named 'firefox.exe' that is executing from a directory other than the standard 'Mozilla Firefox' program folders. When this masquerading process loads critical system DLLs like 'kernel32.dll' or 'ntdll.dll', it flags potential dynamic API resolution activity commonly associated with BabylonRAT and similar malware that attempts to hide its capabilities by resolving system functions at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule monitors network connections and DNS queries directed towards Microsoft's OAuth device code authorization endpoints ('/common/oauth2/deviceauth' or '/device'). This flow is frequently abused by adversaries to perform device code phishing, allowing them to gain access to a victim's account without requiring the user's password or bypassing traditional MFA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the execution of OrionQuests-Setup.exe, a .NET-based executable identified as a malicious installer used by the Kimsuky (APT-C-55/BabyShark) threat group. The rule flags PE files that match the specific filename and contain both .NET framework indicators and references to LNK files, suggesting the dropper mechanism for initial stage infection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the execution of PowerShell with suspicious command line flags (such as hidden windows, bypass execution policies, or encoded commands) where the parent process is a shortcut (.lnk) file. This is a common technique used by attackers to execute malicious scripts via phishing or social engineering, where a user is tricked into clicking a malicious link file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the execution of a process named 'firefox.exe' that is running from a path other than the standard Mozilla Firefox installation directory. This is a common technique used by malware to masquerade as a legitimate web browser.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the use of .NET reflection assembly loading techniques (e.g., Assembly.Load, [Reflection.Assembly]::Load) within the command line arguments of known LOLBAS (Living Off the Land Binary and Script) processes. This behavior is frequently associated with fileless malware execution or the loading of malicious assemblies directly into the memory space of trusted Windows binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule detects processes named 'firefox.exe' running from locations other than the standard Mozilla Firefox installation directories. This behavior is often indicative of an adversary attempting to masquerade malicious activity by using a legitimate browser process name.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects unauthorized write, modification, or rename operations performed on the Windows hosts file (C:\Windows\System32\drivers\etc\hosts) by processes that are not typically authorized for such activity, such as standard system processes (svchost, services, etc.).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the use of .NET reflection assembly loading techniques (e.g., Assembly.Load, [Reflection.Assembly]::Load) within the command line arguments of known LOLBAS (Living Off the Land Binary and Script) processes. This behavior is frequently associated with fileless malware execution or the loading of malicious assemblies directly into the memory space of trusted Windows binaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects unauthorized processes attempting to access browser credential database files such as Login Data for Chromium-based browsers or logins.json and key4.db for Firefox. The rule filters out known browser processes to isolate potential credential harvesting or exfiltration activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule detects processes named 'firefox.exe' running from locations other than the standard Mozilla Firefox installation directories. This behavior is often indicative of an adversary attempting to masquerade malicious activity by using a legitimate browser process name.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects unauthorized write, modification, or rename operations performed on the Windows hosts file (C:\Windows\System32\drivers\etc\hosts) by processes that are not typically authorized for such activity, such as standard system processes (svchost, services, etc.).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects execution, file writing, or network activity associated with the process named 'Stella_Gary', which may indicate the retrieval or use of malicious plugin modules.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the creation or registration of scheduled tasks that masquerade as Google Chrome updates but point to non-standard executable paths. This is a common technique used by malware to establish persistence by mimicking legitimate software update tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule detects the execution of 'OrionQuests-Setup.exe' triggered via a shortcut (.lnk) file. It correlates file creation events involving .lnk files with subsequent process creation events for the specified executable to track potential user execution or masquerading attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the execution of PowerShell with common obfuscation or stealth-related flags (e.g., -enc, -nop, -w hidden) when initiated by CMD or from a LNK file, particularly when originating from Windows Explorer. This is a common pattern for malicious file execution and dropper activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule detects the execution of 'OrionQuests-Setup.exe' triggered via a shortcut (.lnk) file. It correlates file creation events involving .lnk files with subsequent process creation events for the specified executable to track potential user execution or masquerading attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Page 348 of 1870