Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the execution of suspicious commands via the Windows Explorer RunMRU registry key. RunMRU records commands previously entered in the 'Run' dialog box. Adversaries may use this mechanism to launch malicious scripts or tools (e.g., rundll32, powershell, pcalua) with potential arguments that include suspicious markers like '@ssl'.

RunMRU registry values containing rundll32, pcalua, powershell, or @SSL, indicating a user-pasted Run command
avatar
H Fang@Fangtastic
avatar
Detections.ai Community
1 month ago
10143
Matches known VectraRAT sample SHA-256 hashes and the ClickFix distribution domain (verify-cloud.digital) recovered from pivoting across exposed VectraRAT distribution infrastructure
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
001
Matches known VectraRAT sample SHA-256 hashes and the ClickFix distribution domain (verify-cloud.digital) recovered from pivoting across exposed VectraRAT distribution infrastructure
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
101
Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
001
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
001
Detects Node.js or Electron processes executing from suspicious paths (e.g., Temp, Roaming) while interacting with web browser credential files or executing commands consistent with automated credential dumping tools.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
409
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
005
Detects network connections initiated by common web browsers to a specific LinodeObjects domain or any subdomains within the linodeobjects.com infrastructure, which may indicate command and control communication or data exfiltration via legitimate cloud storage providers.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
804
This rule detects the creation of a scheduled task intended to run an executable named 'wsc_updata.exe' from a temporary directory, or identifies svchost.exe initiating a process from that location. Such behavior is indicative of potential persistence mechanisms where malicious actors attempt to run code from unauthorized or writable directories under the context of system processes or scheduled tasks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
104
This rule detects instances where a process named 'wsc_updata.exe' executing from a Temp directory loads a library named 'wsc.dll'. This behavior is characteristic of DLL side-loading or DLL hijacking, where a malicious or potentially unwanted executable attempts to load a library from a user-writable directory to execute arbitrary code.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
104
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
006
Detects the installation or presence of the GemStone browser extension backdoor. The detection logic identifies the malicious extension by flagging specific service worker file names ('background.js') located in browser extension directories, or by detecting browser extension events associated with unique indicators found in the 'AdditionalFields' metadata, specifically looking for keys such as 'kc_state', 'portal_sync_config', or a 'background.js' file reference.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
604
Detects unauthorized processes accessing sensitive web browser files (login data, cookies, local state) from suspicious or non-standard paths. This is a common behavioral pattern for infostealers attempting to exfiltrate user credentials and browser session tokens.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
105
This rule detects potential ransomware activity by correlating three distinct indicators: deletion of Volume Shadow Copies (using native Windows utilities), mass file modifications (>100 files in 15 minutes), and the creation or modification of files typically associated with ransom notes. The rule uses an inner join to ensure these events happen within a 30-minute window of each other on the same device.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
002
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
102
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
002
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
104
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
004
Page 354 of 1870