Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Matches known Phantom Stealer MaaS infostealer sample hashes
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
000
Matches known VectraRAT sample SHA-256 hashes and the ClickFix distribution domain (verify-cloud.digital) recovered from pivoting across exposed VectraRAT distribution infrastructure
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
000
Matches known SilverFox malware payload samples by SHA256 hash
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
000
Matches known SilverFox malware payload samples by SHA256 hash
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
000
Matches known SilverFox malware payload samples by SHA256 hash
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
000
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
000
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
000
Detects the deletion of the XHOPELESS wiper executable from the filesystem, a technique commonly used by malware to remove its own traces and hinder forensic analysis after execution.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
104
Detects unauthorized remote access sessions within N-able N-central by monitoring the Windows Application log for events indicating usage of the default 'MSP Support' account or source IP addresses associated with active exploitation of CVE-2026-18577.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
104
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
004
This rule monitors for the connection of specific KVM-over-IP hardware devices (e.g., PiKVM, Guermok) which can be used by an adversary to gain remote access to a system's physical keyboard, video, and mouse interface, effectively bypassing software-based security controls.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
604
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
004
Detects pre-encryption activity typical of the CRPx0 ransomware, involving the destruction of Windows Volume Shadow Copies, Windows Backup Catalogs, or macOS Time Machine snapshots using system utilities such as vssadmin, wbadmin, wmic, or tmutil. This behavior is indicative of an imminent encryption phase.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility, a technique often used by the CRPx0 ransomware to establish persistence on a system. The rule specifically monitors for the '/create' command-line argument while excluding common, benign updater processes such as those from Microsoft Edge, Google, and OneDrive.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects the creation of a large file (exceeding 4MB) named 'WindowsUpdate.log' on the system. This behavior is indicative of a masquerading attempt where a malicious PE DLL is disguised with the extension of a known legitimate log file, a technique observed in the CRPx0 ClickFix lure to evade security inspection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects the creation of new executable files (DLL or EXE) that contain a certificate subject string referencing 'Microsoft' but are located outside of the standard 'C:\Windows\' directory. This behavior is indicative of an attacker attempting to bypass trust validation mechanisms by creating binaries with self-signed, fake Microsoft certificates, a technique observed in the CRPx0 builder toolset to evade EDR and AV inspection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects evidence of sandbox or virtualization evasion by identifying discovery commands that query WMI hypervisor classes or common virtual machine hardware strings. This activity is considered a precursor (pre-detonation check) when followed by the execution of encoded PowerShell commands or Python scripts on the same host, which is characteristic of the CRPx0 ClickFix attack chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects evidence of sandbox or virtualization evasion by identifying discovery commands that query WMI hypervisor classes or common virtual machine hardware strings. This activity is considered a precursor (pre-detonation check) when followed by the execution of encoded PowerShell commands or Python scripts on the same host, which is characteristic of the CRPx0 ClickFix attack chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects the execution of PowerShell commands containing indicators of AMSI or ETW unhooking (e.g., references to amsi.dll, AmsiScanBuffer, EtwEventWrite, or VirtualProtect). This activity is commonly associated with attackers attempting to bypass endpoint security telemetry and antimalware scanning mechanisms prior to executing malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects evidence of sandbox or virtualization evasion by identifying discovery commands that query WMI hypervisor classes or common virtual machine hardware strings. This activity is considered a precursor (pre-detonation check) when followed by the execution of encoded PowerShell commands or Python scripts on the same host, which is characteristic of the CRPx0 ClickFix attack chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Detects network communication with a known CRPx0 clearnet relay (207.180.29.236:8080) coupled with evidence of local Tor SOCKS5 proxy activity (ports 9050/9150) on the same host, indicating the bridging of traffic to an onion-hosted C2 server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
000
Page 379 of 1870