Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule detects network connections or DNS queries to known phishing domains (typosquatted Microsoft login domains), DeadDrop Resolver domains, and suspicious HTML payloads served from common CDN/package hosting sites (e.g., unpkg.com, npmmirror.com, cdn.jsdelivr.net, yarnpkg.com). These patterns are indicative of initial access attempts via phishing or the secondary stage of malware C2 communication.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
101
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
101
Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects unauthorized processes (e.g., cmd.exe, powershell.exe, node.exe) accessing sensitive web browser files like 'Login Data' or 'Cookies' in common browser directories. This behavior is indicative of credential theft or data exfiltration attempts.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects a suspicious sequence of activities where PowerShell downloads or extracts specific zip files (node.zip, build.zip) to staging directories, followed by the execution of associated binaries like node.exe, winpty-agent.exe, or winpty.dll from those same locations. This behavior is indicative of an adversary staging and executing tooling within temporary user directories.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects suspicious activity associated with JSCeal proxy handlers. It identifies Node.js or Electron processes running from non-standard, user-writable directories (such as AppData, ProgramData, or Temp folders) that actively delete or modify browser cookie files within standard web browser profile paths, often indicative of session hijacking or data tampering.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects nm_host.exe (PEEP native messaging host binary) spawned by Chrome/Edge, tightened to require either the known PEEP extension ID in the native-messaging invocation command line or the distinctive com.peep.lab host path.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
1001
Detects the creation of a Windows service named 'WpnUserHost' or the modification of its registry configuration where the binary path does not reside within the System32 directory. This behavior is indicative of a potential attempt to masquerade a malicious service or achieve persistence using a legitimate-sounding service name.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects potentially malicious PowerShell execution patterns involving hidden windows, administrative elevation via 'Start-Process -Verb RunAs', and the targeting or execution of rsetup64.exe within specific system paths. It also flags execution chains where 'net session' commands, often used for discovery or local privilege verification, are piped to null and followed by or initiate the same target executables, suggesting lateral movement or persistence attempts.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the use of PowerShell to modify Windows Defender security settings by adding exclusion paths or processes. This behavior is indicative of an adversary attempting to whitelist malicious files or processes to evade detection by the antivirus solution.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Detects the placement of potentially malicious executable or script files onto a network share followed by the execution of that specific file path from a different host within a short timeframe. This behavior is indicative of lateral movement using tainted shared content.
avatar
Arnold Chan@slaz
avatar
Hunters
27 days ago
001
Page 372 of 1870