Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects usage of the 'finger' utility via command line within scripts or batch files, or network connections originating from the 'finger' process on port 79 to non-internal destinations. This activity is commonly associated with internal network reconnaissance to gather user information or system details.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
28 days ago
001
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
002
Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
102
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
103
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
103
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
103
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
Detects the use of PowerShell to modify Windows Defender security settings by adding exclusion paths or processes. This behavior is indicative of an adversary attempting to whitelist malicious files or processes to evade detection by the antivirus solution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
103
Detects instances where PowerShell is used to download an executable named 'svchost.exe' from an external IP address (103.86.86.244). The rule monitors for network connections to this IP, file creation events matching specific download patterns in fonts directories, and direct command-line arguments involving the suspicious IP and file path, indicating potential malware dropper activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
003
Detects the execution of 'famitrf2.exe' when it is launched as a child process of 'rserver3.exe' from the specific path 'C:\intel\rserver\rserver3.exe'. This pattern is highly indicative of Remote Administrator (RAdmin) software activity, which can be leveraged for legitimate remote management or malicious remote access.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
003
This rule detects potentially malicious PowerShell execution patterns involving hidden windows, administrative elevation via 'Start-Process -Verb RunAs', and the targeting or execution of rsetup64.exe within specific system paths. It also flags execution chains where 'net session' commands, often used for discovery or local privilege verification, are piped to null and followed by or initiate the same target executables, suggesting lateral movement or persistence attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
003
This rule detects potentially malicious PowerShell execution patterns involving hidden windows, administrative elevation via 'Start-Process -Verb RunAs', and the targeting or execution of rsetup64.exe within specific system paths. It also flags execution chains where 'net session' commands, often used for discovery or local privilege verification, are piped to null and followed by or initiate the same target executables, suggesting lateral movement or persistence attempts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Detects files referencing malicious implant install paths under C:\Windows\Fonts\web used to blend with legitimate system files
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
003
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
106
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden windows) initiated by mshta.exe, excluding instances where a .ps1 script file is involved. This pattern often indicates attempts to bypass execution policy or run obfuscated payloads in memory, which is a common behavior of malicious HTA files.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
406
Detects the loading of 'Adblock.dll' by the executable 'eld2.exe', specifically when 'eld2.exe' is executed as a child process of 'windirstat.exe'. This behavior is indicative of DLL side-loading where a legitimate or potentially malicious application is used to load a secondary library.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
30 days ago
102
Detects instances where multiple executables named 'eld0.exe', 'eld1.exe', or 'eld2.exe' are executed on the same device within a short time window, all containing a 'CID=' argument in the command line. This behavior is often indicative of automated deployment, staging, or modular malware execution patterns.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
30 days ago
002
Detects Adblock.dll used by Docro Hijacker to bypass Chrome Secure Preferences HMAC-SHA256 integrity checks and register infected browser UUID via vendralo[.]info
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
002
Detects Adblock.dll used by Docro Hijacker to bypass Chrome Secure Preferences HMAC-SHA256 integrity checks and register infected browser UUID via vendralo[.]info
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
002
Page 384 of 1870