Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the use of PowerShell to download string content from the internet and execute it immediately using Invoke-Expression (IEX). This is a common pattern for fileless malware delivery and secondary stage payload execution.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
30 days ago
203
Detects the creation of a scheduled task using schtasks.exe or reg.exe that is configured to run at system logon (/sc onlogon) using potentially malicious or persistence-related filenames such as client32.exe or NSM789508.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
30 days ago
103
Detects the creation of a scheduled task using schtasks.exe or reg.exe that is configured to run at system logon (/sc onlogon) using potentially malicious or persistence-related filenames such as client32.exe or NSM789508.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
103
Detects the use of PowerShell to download string content from the internet and execute it immediately using Invoke-Expression (IEX). This is a common pattern for fileless malware delivery and secondary stage payload execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
103
Detects the execution of rundll32.exe with a command line pointing to a WebDAV share path (DavWWWRoot). This technique is commonly used to execute remote payloads by forcing the system to access a remote resource, often as part of a malicious DLL loading chain.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
103
This rule detects the creation of a scheduled task named 'GlobalProtectVPNUpdate' using schtasks.exe, which has been identified as a technique used to facilitate the execution of malicious payloads masquerading as legitimate GlobalProtect VPN components. It also monitors for the subsequent execution of 'GlobalProtect.exe' when initiated by Windows background services like taskeng.exe or svchost.exe, which is indicative of persistence and unauthorized code execution.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detection & Hunting Community
1 month ago
204
Detects the execution of the Windows shutdown utility (shutdown.exe) with parameters configured to force an immediate reboot (/r /t 0 /f). This behavior is often associated with disruptive activities or attempts to clear system state by unauthorized actors.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
205
Detects the XHOPELESS wiper routine 'KillNetworkPermanent' which severs network connectivity by resetting the TCP/IP stack using netsh, blocking all traffic via Windows Advanced Firewall commands, and disabling network adapters via devcon.exe as a final destructive action.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
105
Detects malicious command-line activity associated with the XHOPELESS v1.0 wiper, specifically targeting firmware/BIOS/UEFI integrity. The detection covers WMI-based corruption of BIOS attributes, abuse of OEM-specific BIOS management namespaces, execution of legitimate firmware update tools with suspicious flags, modification of registry keys intended to disable firmware updates, and interaction with specific UEFI NVRAM GUIDs.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
405
Detects potential web reconnaissance or scanning activity against Microsoft IIS servers. The rule identifies suspicious behavior by monitoring for high frequencies of distinct URI requests, excessive 404 Not Found status codes indicative of path brute-forcing, and the presence of known security scanning user-agents.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
005
This rule detects suspicious command executions (e.g., whoami, downloadstring, iex, registry modifications) initiated by processes associated with the CrowdStrike Falcon agent. It also correlates these executions with the loading of unsigned or unverifiable DLLs by the same Falcon processes within a 5-minute window, which may indicate attempts to tamper with or masquerade as the security agent.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
205
Detects suspicious activities originating from CrowdStrike Falcon remediation processes (e.g., CSFalconService.exe, CSFalconContainer.exe). The rule identifies two distinct patterns: either a file operation (delete, modify, rename, quarantine, or restore) followed within 2 minutes by the loading of an unsigned or non-standard DLL, or the spawning of an elevated SYSTEM process from a non-SYSTEM parent process. This behavior is indicative of potential LPE (Local Privilege Escalation) abuse via the Falcon remediation engine, often referred to as FalconFlank-style exploitation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
005
This rule detects unauthorized attempts to modify CrowdStrike Falcon sensor exclusion registry keys or commands involving DLL loading techniques that may indicate evasion preparation, specifically referencing potential FalconFlank-related activities. It filters out legitimate management activity from known service accounts, SCCM, and the CrowdStrike Falcon agent itself.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
005
This rule detects potential ransomware activity by correlating three distinct indicators: deletion of Volume Shadow Copies (using native Windows utilities), mass file modifications (>100 files in 15 minutes), and the creation or modification of files typically associated with ransom notes. The rule uses an inner join to ensure these events happen within a 30-minute window of each other on the same device.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Detects unauthorized remote access sessions within N-able N-central by monitoring the Windows Application log for events indicating usage of the default 'MSP Support' account or source IP addresses associated with active exploitation of CVE-2026-18577.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects the use of raw sockets by 'ERAAgent.exe' by monitoring for socket I/O control (Ioctl) operations involving 'SIO_RCVALL'. This configuration, often associated with promiscuous mode, allows an application to capture all network traffic received by the network interface, a behavior commonly used by network sniffing tools or malicious implants to intercept sensitive data.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the ESET Remote Administrator (ERAAgent.exe) process loading the 'dpapisvc.dll' module. This behavior is indicative of potential DLL side-loading where an attacker places a malicious DLL with the same name as a legitimate system library in the agent's directory to achieve code execution.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Page 370 of 1870