Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects potential cryptocurrency mining activity where known miner executables (specifically XMRig) or malicious scripts/processes are masquerading as or being spawned by 'LockAppHost.exe' or 'LockAppHost14a02b.exe'. It also monitors for subsequent attempts by these processes to terminate security-related tasks or establish persistence via registry run keys.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects when a Node.js process initiates a low-level keyboard hook (WH_KEYBOARD_LL or WH_KEYBOARD) while running from common user-writable directories, which may indicate malicious keylogging activity by a suspicious process.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
302
This rule detects the presence of 'winpty-agent.exe' or 'winpty.dll' in proximity to 'node.zip' or 'build.zip' files within common user-writable or temporary directories ('AppData\Local\Temp', 'AppData\Roaming', 'ProgramData', 'Users\Public'). This pattern is often associated with the staging and execution of malicious tools or command-line wrappers in non-standard locations, bypassing legitimate application installation directories.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects Node.js or related helper processes executing shell commands (cmd.exe, powershell.exe) or other processes where the execution involves the 'withCreateProcessUser' argument. This often indicates attempts to bypass execution restrictions or run malicious payloads by utilizing Node.js as an execution proxy within unconventional or temporary directories.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects network activity from infrastructure provisioner tools (Terraform, Coder) or shell processes attempting to connect to suspicious domains (e.g., coder-infra.com) that resemble legitimate infrastructure domains. This activity is indicative of credential theft, specifically targeting OIDC tokens, SSH keys, or authentication tokens during automated provisioning processes.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects PEEP Secure Preferences integrity-hash forgery (protection.macs/super_mac) and known PEEP persistence scripts (patch_secure_prefs.ps1, install_silent.ps1, force_enable.ps1), anchored to actual Chrome/Edge profile paths rather than generic terms like 'protection' or 'developer_mode' that appear in unrelated admin tooling.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects the use of the native Windows registry utility 'reg.exe' to import configuration files (install.reg) related to the Radmin remote access software, specifically targeting the security settings registry path.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
102
Detects the execution of 'famitrf2.exe' when it is launched as a child process of 'rserver3.exe' from the specific path 'C:\intel\rserver\rserver3.exe'. This pattern is highly indicative of Remote Administrator (RAdmin) software activity, which can be leveraged for legitimate remote management or malicious remote access.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects instances where PowerShell is used to download an executable named 'svchost.exe' from an external IP address (103.86.86.244). The rule monitors for network connections to this IP, file creation events matching specific download patterns in fonts directories, and direct command-line arguments involving the suspicious IP and file path, indicating potential malware dropper activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
Page 357 of 1870