Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects potential exploitation of a CrowdStrike Falcon remediation process vulnerability ('FalconFlank'). The rule identifies either direct execution of the PoC binary or the suspicious combination of a CrowdStrike remediation process loading an unsigned or untrusted DLL from a user-writable path followed by the same process spawning a command shell in the SYSTEM context within 15 minutes.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
102
This rule detects suspicious command executions (e.g., whoami, downloadstring, iex, registry modifications) initiated by processes associated with the CrowdStrike Falcon agent. It also correlates these executions with the loading of unsigned or unverifiable DLLs by the same Falcon processes within a 5-minute window, which may indicate attempts to tamper with or masquerade as the security agent.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects the loading of registry hives using the 'reg load' command. This technique is often associated with adversary attempts to manipulate the Windows registry, access sensitive data, or establish persistence, particularly when followed by actions executed in the SYSTEM context from the same process lineage.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
102
Detects rapid, repeated invocation of Microsoft Defender remediation processes (mpcmdrun.exe, MsMpEng.exe) occurring in conjunction with suspicious file write or rename operations in System32. This pattern is characteristic of a Time-of-Check to Time-of-Use (TOCTOU) race condition, where an attacker attempts to exploit the timing gap between Defender's detection and remediation actions to replace a file with a malicious version.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
102
This rule detects unauthorized attempts to modify CrowdStrike Falcon sensor exclusion registry keys or commands involving DLL loading techniques that may indicate evasion preparation, specifically referencing potential FalconFlank-related activities. It filters out legitimate management activity from known service accounts, SCCM, and the CrowdStrike Falcon agent itself.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
402
Detects the execution of 'driverquery.exe' to enumerate information about the 'npf.sys' driver (Network Packet Filter), which is associated with Npcap/WinPcap used for packet capture. The rule specifically monitors when this command is launched by non-standard parent processes like 'report.bin' or 'nw.exe', which may indicate malicious reconnaissance or network monitoring tools.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
102
Detects execution patterns associated with 'NinjaMare' style malware, where a process masquerading as a browser (e.g., tenbrowser.exe, fireflybrowser.exe) performs an external IP geolocation lookup followed by suspicious registry or file modifications indicative of browser hijacking or extension installation within a five-minute window.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects the addition of suspicious file names or known potentially unwanted program artifacts to Windows Run registry keys, often used for persistence. The rule correlates registry modifications with potential installer process activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects the execution of processes or network connections that impersonate 'WhatsApp' or 'Instagram' companion applications. It identifies specific file names and process command lines that mimic these applications, often associated with browser-launched or malicious payloads, and monitors for associated network traffic directed toward suspicious endpoints like herokuapp domains.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule monitors the software inventory for outdated versions of the PostgreSQL database server. It identifies installations where the major and minor versions are below the threshold for current security releases (e.g., v18 < 6, v17 < 11, v16 < 15, v15 < 19, v14 < 24). Running outdated software increases the risk of exploitation of known vulnerabilities.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
KQL Query from file: clickfix-mshtapowershell-run-dialog-exec-with-download-cradle-after-captcha-lu.kql
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
312
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects instances where LockAppHost.exe or a variation of it (likely used as a proxy) initiates processes or command-line arguments that interact with Windows services, scheduled tasks, or Windows Defender configurations. This behavior is indicative of an adversary attempting to disable security features, suppress Windows updates, or manipulate system services to evade detection.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects the creation of a scheduled task using 'schtasks.exe' where the task name matches commonly abused names such as 'WinUpdate.exe', 'SoftManager.exe', or 'LockAppHost.exe'. These names are frequently used by adversaries to masquerade as legitimate Windows processes to achieve persistence.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Page 356 of 1870