Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
002
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
205
Detects the creation of Object Manager symbolic links that redirect the Windows Defender 'WD_SCAN' object to a loopback UNC share path. This behavior is indicative of a symlink exploitation technique (ShieldCrash/CVE-2026-69414) used to manipulate Windows Defender or associated scan operations by redirecting them to an adversary-controlled or loopback-hosted target.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
205
Detects unexpected crashes or restarts of the Windows Defender service (MsMpEng.exe) occurring in temporal proximity to activities associated with the ShieldCrash PoC or tampering within the Windows Defender object manager namespace. This rule aims to identify potential exploitation attempts targeting Windows Defender, specifically correlating security service instability with known malicious indicators.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
305
Detects rapid deletion and creation cycles of the WD_SCAN object manager link, a behavioral pattern associated with a Time-of-Check-to-Time-of-Use (TOCTOU) exploit chain targeting Windows Defender (referenced as CVE-2026-69414). The rule monitors for at least three cycle events occurring within a 5-second window, specifically involving the 'WD_SCAN' object identifier.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
105
This rule monitors DeviceFileEvents for the presence of specific browser extension files on disk known to be associated with malicious campaigns. It utilizes a predefined mapping of extension IDs to names to identify and flag files matching the known malicious browser extensions.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
21127
Detects rapid, repeated invocation of Microsoft Defender remediation processes (mpcmdrun.exe, MsMpEng.exe) occurring in conjunction with suspicious file write or rename operations in System32. This pattern is characteristic of a Time-of-Check to Time-of-Use (TOCTOU) race condition, where an attacker attempts to exploit the timing gap between Defender's detection and remediation actions to replace a file with a malicious version.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
308
Detects suspicious DLL loads or file drops performed by security product processes (avp.exe, MsMpEng.exe) from directories outside of standard, trusted vendor paths. It specifically flags unsigned or invalidly signed DLLs, which is indicative of DLL sideloading techniques used to abuse security software workflows for potential privilege escalation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
008
Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
008
Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
30 days ago
005
Detects the presence of AsyncRAT's screen-capture functionality, specifically the use of .NET Graphics.CopyFromScreen and MemoryStream routines, identified via Microsoft Antimalware Scan Interface (AMSI) inspection logs within a host process.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
001
Detects the execution of 'charmap.exe' from the Syswow64 directory where the process hierarchy indicates suspicious activity. The detection identifies a chain where PowerShell spawns 'conhost.exe', which in turn spawns a process from a temporary directory (interpreted as a renamed AutoIT executable) that then launches 'charmap.exe'. This pattern is indicative of a multi-stage obfuscated execution flow often used in malware dropper scenarios to bypass standard monitoring.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
001
Detects a suspicious process injection chain (OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread) targeting the Windows Character Map utility (charmap.exe) located within the SysWOW64 directory. This activity is often used by adversaries to execute malicious code within a legitimate, signed process context to evade security monitoring.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
001
This rule detects the execution of a malicious AutoIT loader script (identified by the filename 'kojuyn.ini' and a specific SHA-256 hash). The loader is designed to deobfuscate runtime API names and payload paths from XOR-encoded strings, bypassing static analysis. The detection links the presence of this script with the execution of a corresponding AutoIT interpreter binary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
001
Detects the reflective or in-memory loading of the AsyncRAT DLL (Veukuzmw.dll) into the memory space of the legitimate Windows process charmap.exe, characterized by a lack of corresponding disk activity or suspicious process command-line arguments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
101
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects network connections to known JeetBot infrastructure domains and IP addresses. The rule specifically identifies potential exfiltration of Twitch OAuth tokens via URL parameters or interaction with known token-collection proxy endpoints, which are associated with the JeetBot/Twitch Enhanced Viewer credential harvesting campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
101
Detects network connections to known JeetBot infrastructure domains and IP addresses. The rule specifically identifies potential exfiltration of Twitch OAuth tokens via URL parameters or interaction with known token-collection proxy endpoints, which are associated with the JeetBot/Twitch Enhanced Viewer credential harvesting campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Page 358 of 1870