Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,242 detections

Detects potential exfiltration staging by copying files from Windows mounts (/mnt/) into the WSL Linux filesystem using wsl.exe -e cp/mv
avatar
Trevor Moore@gr4dyb4by
avatar
Detections.ai Community
16 days ago
4014
Detects Microsoft Installer (MSI) files associated with the psychedelic stealer malware family. The rule identifies MSI components that contain embedded paths to the psychedeliclove.exe payload, specific command and control IP/port combinations, and decoy file names (e.g., MsMpEng.exe or explorer.exe) used to disguise the malware installation or execution process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the creation of a Windows service that impersonates the legitimate Windows Time (w32time) service name or display name but utilizes a binary located outside of the standard system32 directory. This behavior is indicative of a persistence mechanism, often used by backdoors like RemotePanel to evade detection after initial compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
This rule detects persistence mechanisms involving the creation or modification of Windows Registry Run keys, the creation of scheduled tasks, or the execution of specific binaries (COTFileReadApp.exe, DeElevate64.exe) associated with potentially unauthorized activity, specifically tracking strings related to 'Canon Configuration Reader' or 'Stardock DeElevation Tool'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
202
Detects a credential-theft pattern associated with Psychedelic Stealer where a process accesses the 'Login Data' file of common Chromium-based browsers, followed shortly by a network connection to a known stealer exfiltration API endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
This rule detects the creation of a new Windows service using common administrative tools like sc.exe or PowerShell's New-Service cmdlet that masquerades as the legitimate Windows Time service (w32time). The rule specifically flags service creation commands that use relevant service names but point to non-standard, suspicious executable paths or configurations, potentially indicating persistence or malicious activity by RemotePanel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
202
Detects the loading of spoofed system DLLs (dnsapi.dll or ws2_32.dll) from non-system directories, followed by network beaconing to suspicious domains associated with the NeedyMantis malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the execution of taskkill.exe to terminate known security software processes, when the command is initiated from sqlservr.exe or via a command shell child process of sqlservr.exe. This activity is a common post-exploitation step after abusing xp_cmdshell to neutralize defenses before deploying further payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the use of certutil.exe to decode files located within directories associated with the MSSQL service account (e.g., AppData, ServiceProfiles). This behavior is characteristic of an attack chain where an adversary uses SQL Server's xp_cmdshell to stage and decode a malicious payload from a base64-encoded file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the creation of Windows services that reference file paths often associated with NeedyMantis malware sideloading activities. These paths typically involve directories inside ProgramData or ProgramFiles where benign executables are used to sideload malicious DLLs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the first-stage loader DLL associated with the NeedyMantis actor, which masquerades as the WinSparkle.dll component used in Poedit software. This rule uses a specific SHA256 file hash to identify this malicious component.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
Detects the execution of a specific, tampered version (12.5.1) of the DAEMON Tools Lite installer, which has been identified as a distribution vector for malicious activity linked to Storm-3069.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
This rule detects potential DLL sideloading by monitoring known legitimate Windows binaries that are commonly abused to load malicious DLLs from non-standard directories (i.e., not System32, SysWOW64, or WinSxS). This activity is often associated with the TerminalFix / Lorem Ipsum Loader campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
001
Detects execution of various reconnaissance commands commonly used by Remote Access Trojans (RATs) to profile a target host. This includes querying security product status (AV/Defender), enumerating domain controllers, network adapters, port scanning, and gathering system hardware and software inventory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
002
This rule detects instances where Python package management processes (pip or python) perform build or installation tasks, immediately followed by an outbound network connection initiated by the same process tree to a non-PyPI domain. This behavior is indicative of a supply chain attack where a malicious package contains code (e.g., in setup.py) that beacons to an attacker-controlled server upon installation.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
9 days ago
002
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
001
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
101
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
101
Detects PowerShell commands that load images (JPG/PNG) and parse their pixel data for encoded payloads. This technique, often associated with Invoke-PSImage, uses steganography to hide malicious scripts within image files, which are then extracted using GDI+ methods (GetPixel) or byte manipulation and executed in-memory via IEX or assembly reflection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
Detects suspicious command execution patterns (such as PowerShell encoded commands, IEX, or cmd.exe) being stored or accessed within the Windows Registry 'TypedPaths' key, which is used by Windows Explorer to track recently accessed paths. Adversaries may attempt to use this location to execute payloads via user-triggered interactions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
Detects the execution of the Windows finger.exe utility with a command-line argument containing an '@' symbol, which indicates a request to a remote host. This technique is often abused by adversaries for reconnaissance or to retrieve remote stagers or other payloads, as the finger protocol is rarely used in modern enterprise environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
102
Page 35 of 1869