Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
002
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
30 days ago
102
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
102
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
102
Detects rapid, repeated invocation of Microsoft Defender remediation processes (mpcmdrun.exe, MsMpEng.exe) occurring in conjunction with suspicious file write or rename operations in System32. This pattern is characteristic of a Time-of-Check to Time-of-Use (TOCTOU) race condition, where an attacker attempts to exploit the timing gap between Defender's detection and remediation actions to replace a file with a malicious version.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
8011
Detects the use of bcdedit.exe to disable automatic system recovery features, a common technique used by ransomware and other malware to prevent automated restoration of the operating system after compromise.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
000
Detects the creation of a scheduled task named 'Windows Update ALPHV' using the schtasks.exe utility. This task is associated with the OpnKey ransomware, which uses this name to masquerade as a legitimate Windows Update task while running with SYSTEM privileges to maintain persistence.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
000
Detects the execution of vssadmin.exe or WMIC.exe with commands intended to delete Volume Shadow Copies. This behavior is commonly associated with ransomware attempting to prevent system restoration by deleting local backups.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
000
Detects command-line execution containing 'Processes.KillRunningProcesses', a string characteristic of the OpnKey ransomware builder configuration, suggesting an intent to terminate critical processes to facilitate encryption.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
000
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects command-line execution patterns indicative of OpnKey ransomware host fingerprinting. The ransomware gathers system metadata, including system IDs, PC hostnames, domain information, Windows versions, and processor names, likely to profile the environment prior to encryption or exfiltration.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
000
Detects usage of the Windows API function GetUserObjectInformationW to inspect the current window station for specific strings, such as 'Service-0x'. This technique is often used by malware for environmental awareness, specifically to detect if it is running within a virtual machine or analysis sandbox by checking window station object attributes.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
000
Detects the presence of OpnKey ransomware-specific configuration strings related to size-tiered file encryption settings in process command lines. These indicators suggest the execution of a binary with hardcoded logic to categorize files for encryption based on their size.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
25 days ago
000
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
102
Detects an HTTP GET request to 'dl.php' containing an 'f' parameter (target file) and an 'k' parameter (access token), followed by a response body starting with the 'MZ' header, indicating the successful download of a Windows PE executable as part of a potential phishing campaign stage-2 payload delivery.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
002
Detects PE binaries masquerading as Microsoft's Windows Update Assistant via forged VersionInfo metadata combined with an unsigned or invalid/unverified digital signature, associated with HVNC backdoor delivery
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects instances where a shell process (powershell, cmd, mshta, or wscript) is spawned by a browser-related process (explorer, wt, or SearchHost) shortly after a user focuses on a web browser, followed by a network connection from that shell within a short time window. This pattern is indicative of potential web-based exploitation or file download and execution chains.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
13021
Detects the download of ZIP files with filenames matching known phishing patterns associated with NFe (Nota Fiscal Eletrônica) campaigns, correlated with access to specific malicious or suspicious download URLs within a 15-minute window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
202
Detects the download of ZIP files with filenames matching known phishing patterns associated with NFe (Nota Fiscal Eletrônica) campaigns, correlated with access to specific malicious or suspicious download URLs within a 15-minute window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
002
Page 385 of 1870