Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a specific evasion behavior associated with the NinjaMare malware, where a process idles for at least 7 minutes before moving its window to off-screen coordinates during automated mouse or keystroke input, followed by restoring the window to its original position.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the creation, modification, or renaming of PHP files within the 'wp-content/uploads' directory of a WordPress installation. This pattern is commonly indicative of an attacker uploading a web shell to maintain persistence or execute arbitrary code on a compromised web server.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects instances where base64-encoded PHP code, obfuscated behind a 'data:image/gif;base64' MIME type prefix, is written to the disk as a .php file or initiated by web server processes. This pattern is commonly used in file upload bypass attacks to execute arbitrary code.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects instances where the process wtass.exe (often associated with specific legacy or third-party enterprise tools) spawns cmd.exe. This pattern is potentially indicative of command-line abuse, where a legitimate application's child process is leveraged to execute shell commands.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden windows) initiated by mshta.exe, excluding instances where a .ps1 script file is involved. This pattern often indicates attempts to bypass execution policy or run obfuscated payloads in memory, which is a common behavior of malicious HTA files.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
101
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
101
Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects potential reflective code injection or in-memory loading (fileless) where a DLL or PE image is loaded by mshta.exe or powershell.exe, but the module load event lacks a valid file path on disk (or indicates a device path). This behavior is often associated with the execution of malicious payloads such as the Amatera loader, where payloads are executed directly in memory to evade file-based security detections.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects network connections or DNS queries to known phishing domains (typosquatted Microsoft login domains), DeadDrop Resolver domains, and suspicious HTML payloads served from common CDN/package hosting sites (e.g., unpkg.com, npmmirror.com, cdn.jsdelivr.net, yarnpkg.com). These patterns are indicative of initial access attempts via phishing or the secondary stage of malware C2 communication.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
101
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
101
Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Page 371 of 1870