Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects PowerShell commands that enumerate system, security, or virtualization-related artifacts. It specifically looks for the usage of WMI and PowerShell cmdlets (e.g., Get-Process, Get-WmiObject) to query for known analysis tools, debuggers, or virtualization software strings, which is a common behavior of malware attempting to identify and evade sandbox or analyst environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the creation of scheduled tasks that contain the string 'Google Chrome Update' in the command line, but are not associated with the legitimate GoogleUpdate.exe binary. This is a common technique used by malware to establish persistence by masquerading as a legitimate update process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule searches for any process, image load, or file events containing the string 'Stella_Gary' within file names, folder paths, or process command lines. This is a generic hunting rule typically used to identify artifacts, indicators, or files associated with a specific entity or project codename.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule searches for any process, image load, or file events containing the string 'Stella_Gary' within file names, folder paths, or process command lines. This is a generic hunting rule typically used to identify artifacts, indicators, or files associated with a specific entity or project codename.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects instances of 'firefox.exe' executing from locations other than the standard Mozilla installation directories, such as AppData, Temp, Downloads, or ProgramData. Additionally, the rule validates if the binary is digitally signed by Mozilla. This behavior is indicative of a masquerading attempt, where an attacker runs a malicious executable disguised as Firefox.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects instances of 'firefox.exe' executing from locations other than the standard Mozilla installation directories, such as AppData, Temp, Downloads, or ProgramData. Additionally, the rule validates if the binary is digitally signed by Mozilla. This behavior is indicative of a masquerading attempt, where an attacker runs a malicious executable disguised as Firefox.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the use of PowerShell to reflectively load .NET assemblies into memory, often associated with fileless malware execution. The rule monitors for common reflection-based methods (e.g., Assembly.Load, [System.Reflection.Assembly]) in conjunction with encoded command patterns or script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects instances where a process named firefox.exe, executing from the ProgramData directory, is used to establish persistence via Windows Registry Run keys or to create scheduled tasks/services. This behavior is indicative of a malicious process masquerading as the legitimate Firefox browser to maintain persistence on a host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects unauthorized processes attempting to access sensitive web browser files (login data, cookies, configuration) located in Chrome or Firefox profile directories. The detection excludes known browser-related processes and system processes, focusing on third-party or potentially malicious utilities that could be used to harvest credentials stored in these local files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule detects modifications to the Windows hosts file (C:\Windows\System32\drivers\etc\hosts). Adversaries often modify this file to redirect legitimate traffic to malicious IP addresses, a technique commonly used for command and control or phishing campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects instances where a process masquerading as 'firefox.exe' executes common system reconnaissance commands such as systeminfo, ipconfig, whoami, and tasklist from non-standard file paths. This behavior is indicative of the BabylonRAT malware attempting to gather system and network information after establishing persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects instances where a process named firefox.exe is running from a non-standard location or includes keywords indicative of keylogging activity such as 'SetWindowsHookEx', 'GetAsyncKeyState', 'GetKeyState', or 'keylog'. This is a common behavioral indicator for the BabylonRAT malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects execution of the suspicious installer 'OrionQuests-Setup.exe' or the creation of shortcut (.lnk) files associated with this specific executable name. This activity is indicative of potential malicious installer behavior, likely used to distribute malware or drop persistent components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects execution of the suspicious installer 'OrionQuests-Setup.exe' or the creation of shortcut (.lnk) files associated with this specific executable name. This activity is indicative of potential malicious installer behavior, likely used to distribute malware or drop persistent components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects instances of 'firefox.exe' executing from locations other than the standard Mozilla Firefox program directories, a technique used by BabylonRAT and other malware to masquerade as a legitimate browser application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the creation of a scheduled task named 'Google Chrome Update' using the Windows schtasks.exe utility. The rule flags instances where the task is created from locations other than the legitimate Google Chrome installation directories, identifying potential persistence mechanisms masquerading as a common software update process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the use of PowerShell's System.Reflection.Assembly Load methods to dynamically load .NET assemblies into process memory from a byte array. This technique is often used by adversaries to execute malicious code directly in memory, bypassing disk-based detection mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects the execution or loading of modules, processes, or command lines associated with the Stella_Gary C# backdoor framework. This framework is utilized by the Kimsuky (APT-C-55) threat group as part of a modular, plugin-based capability loading architecture.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects PowerShell command lines that perform environment validation by enumerating running processes for security software (AV/EDR/Analysis tools) and querying WMI for virtualization artifacts. This behavior is consistent with anti-analysis and anti-sandbox evasion techniques used by threat actors, such as Kimsuky, to identify and verify the execution environment before proceeding with malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects files that are masquerading as Rich Text Format (RTF) documents but do not contain valid RTF magic bytes and instead contain embedded Portable Executable (PE) headers or DOS stubs. This behavior is indicative of malware delivery via file-type masquerading, often used in spearphishing campaigns by actors such as Kimsuky.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects unauthorized modifications to the Windows HOSTS file (C:\Windows\System32\drivers\etc\hosts). Adversaries frequently modify this file to perform DNS hijacking or domain redirection, steering users to malicious infrastructure or bypassing security controls. The rule filters out known legitimate system processes that typically interact with this file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Page 349 of 1870