Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
This rule detects behavior associated with Hidden Virtual Network Computing (HVNC) implants, which allow remote attackers to interact with a hidden desktop session on a compromised host. The rule specifically looks for processes that perform a sequence of sensitive Windows API calls—CreateDesktopA, SetThreadDesktop, BitBlt/GetDIBits (for screen capture), and SendInput (for input simulation)—when originating from suspicious, unsigned, or non-standard file paths, indicating potential malicious use rather than legitimate software.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
002
This rule detects behavior associated with Hidden Virtual Network Computing (HVNC) implants, which allow remote attackers to interact with a hidden desktop session on a compromised host. The rule specifically looks for processes that perform a sequence of sensitive Windows API calls—CreateDesktopA, SetThreadDesktop, BitBlt/GetDIBits (for screen capture), and SendInput (for input simulation)—when originating from suspicious, unsigned, or non-standard file paths, indicating potential malicious use rather than legitimate software.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
002
Detects the creation of a shortcut file (.lnk) in the Windows Startup directory by the 'UpdateAssistant.exe' process. The rule specifically looks for evidence of a masquerading attempt where the shortcut appears to be an application update helper but potentially references or exhibits characteristics of being linked to a notepad execution, suggesting persistence via shortcut file manipulation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
102
Detects a specific pattern of PowerShell execution involving the download of files from a remote endpoint using parameters associated with Brazilian tax documents (NotaFiscal) to the Desktop directory, followed by immediate execution. The rule looks for a combination of hidden window style, Invoke-WebRequest, specific URL parameters (dl.php, NFe identifiers), and subsequent Start-Process calls, which is indicative of malware dropper activity.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
102
Detects a specific pattern of PowerShell execution involving the download of files from a remote endpoint using parameters associated with Brazilian tax documents (NotaFiscal) to the Desktop directory, followed by immediate execution. The rule looks for a combination of hidden window style, Invoke-WebRequest, specific URL parameters (dl.php, NFe identifiers), and subsequent Start-Process calls, which is indicative of malware dropper activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects suspicious PowerShell execution initiated by explorer.exe containing encoded commands, correlated with concurrent activity in the Windows RunMRU registry key or execution of rundll32.exe referencing 'WindowsUpdate.log'. This pattern is frequently used to mask malicious activity and maintain stealth during fileless execution or persistence operations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
102
Detects suspicious PowerShell execution initiated by explorer.exe containing encoded commands, correlated with concurrent activity in the Windows RunMRU registry key or execution of rundll32.exe referencing 'WindowsUpdate.log'. This pattern is frequently used to mask malicious activity and maintain stealth during fileless execution or persistence operations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
002
Detects suspicious PowerShell execution initiated by explorer.exe containing encoded commands, correlated with concurrent activity in the Windows RunMRU registry key or execution of rundll32.exe referencing 'WindowsUpdate.log'. This pattern is frequently used to mask malicious activity and maintain stealth during fileless execution or persistence operations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects the use of PowerShell to download string content from the internet and execute it immediately using Invoke-Expression (IEX). This is a common pattern for fileless malware delivery and secondary stage payload execution.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
30 days ago
002
Detects the use of PowerShell to download string content from the internet and execute it immediately using Invoke-Expression (IEX). This is a common pattern for fileless malware delivery and secondary stage payload execution.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
30 days ago
002
Detects the creation of a scheduled task using schtasks.exe or reg.exe that is configured to run at system logon (/sc onlogon) using potentially malicious or persistence-related filenames such as client32.exe or NSM789508.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
30 days ago
102
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
202
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
002
The following analytic detects the execution of `arp.exe` with the `-a` flag, which is used to list network connections on a compromised system. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, command-line executions, and related telemetry. Monitoring this activity is significant because both Red Teams and adversaries use `arp.exe` for situational awareness and Active Directory discovery. If confirmed malicious, this activity could allow attackers to map the network, identify active devices, and plan further lateral movement or attacks.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
7025
Detects the creation of Object Manager symbolic links that redirect the Windows Defender 'WD_SCAN' object to a loopback UNC share path. This behavior is indicative of a symlink exploitation technique (ShieldCrash/CVE-2026-69414) used to manipulate Windows Defender or associated scan operations by redirecting them to an adversary-controlled or loopback-hosted target.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
102
Detects suspicious file activity within directories named 'ShieldCrash' followed by a cloud provider registration or placeholder creation event within a 5-minute window. This behavior is indicative of unauthorized software or an adversary attempting to stage data for exfiltration or create persistent storage aliases outside of legitimate cloud client applications.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
002
This rule detects suspicious file operations (creation, modification, or renaming) initiated by MsMpEng.exe (Microsoft Defender Antivirus) involving specific indicators related to ELAM (Early Launch Anti-Malware) or 'ShieldCrash' components. These indicators often suggest tampering attempts or the presence of tools designed to interfere with Defender's security operations by targeting its configuration, staging, or protected storage locations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
002
Detects the Warden.dll companion DLL shipped as part of the ShieldCrash (CVE-2026-69414) exploit chain, tightened to require an unsigned/unknown publisher or a suspicious install path alongside the generic filename
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
002
Detects presence of multiple ShieldCrash CVE-2026-69414 PoC Visual Studio project/solution build artifacts indicating exploit tooling staging
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
002
Page 386 of 1870