Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects instances where the GlobalProtect VPN client executable spawns a Windows command shell (cmd.exe). This behavior is highly suspicious as a legitimate VPN client typically does not launch interactive shells, and this pattern has been associated with the execution of malicious payloads such as fake MSI installers.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
102
Detects OAuth2 JWT bearer-grant token requests to Google's OAuth endpoint using the attacker-controlled service-account identity and Sheets API scope observed in the fake GlobalProtect campaign
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
102
Detects potential DLL side-loading attempts involving GlobalProtect VPN components. The rule identifies the execution of GlobalProtect.exe with specific command-line arguments combined with the presence of suspicious versions of bcrypt.dll or WININET.dll within the same directory, which are characteristic of recent malicious activity involving modified DLL files targeting GlobalProtect environments.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
002
Detects the creation or modification of Windows Registry RunOnce keys using the value name 'GlobalProtectVPN', intended to execute 'GlobalProtect.exe'. This pattern is associated with malware masquerading as legitimate GlobalProtect VPN software to achieve persistence upon user logon.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
002
This rule detects the creation of a scheduled task named 'GlobalProtectVPNUpdate' using schtasks.exe, which has been identified as a technique used to facilitate the execution of malicious payloads masquerading as legitimate GlobalProtect VPN components. It also monitors for the subsequent execution of 'GlobalProtect.exe' when initiated by Windows background services like taskeng.exe or svchost.exe, which is indicative of persistence and unauthorized code execution.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
002
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
002
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
102
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
102
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
102
Detects the invocation of the AppInstaller executable to install .msix packages, often used in software installation or malicious delivery scenarios involving application deployment.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
406
Detects the execution or presence of files, processes, or paths associated with the 'SnowKiller' malware or tool, as identified by keyword matching in process event logs.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
206
This rule detects the installation of browser extensions that occur during an idle user session (greater than 7 minutes). This behavior is consistent with automated, remote-driven synthetic input injection, often utilized by malware (e.g., NinjaMare) to install malicious extensions without user consent while the system is unattended.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
306
Detects the execution of 'driverquery.exe' to enumerate information about the 'npf.sys' driver (Network Packet Filter), which is associated with Npcap/WinPcap used for packet capture. The rule specifically monitors when this command is launched by non-standard parent processes like 'report.bin' or 'nw.exe', which may indicate malicious reconnaissance or network monitoring tools.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
106
This rule detects a suspicious sequence of events where a process with a name resembling an updater (AutoUpdate.exe or au.exe) accesses a specific remote configuration file from a herokuapp.com URL, followed by the creation or modification of specific application binaries (e.g., InstaTime.exe, ffmpegsumo.dll). This pattern is indicative of a supply chain compromise or an automated software update hijacking where malicious binaries are staged to replace legitimate application components.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
206
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
205
Detects access to the SAM registry hive or SAM-related LSA control keys initiated by a process associated with the Avast Sandbox component rather than LSASS or an administrative security tool. The PrettyPrague PoC abuses a vulnerability in Avast Sandbox to dump the SAM database and spawn a SYSTEM shell, so SAM hive reads originating from the sandbox component itself are anomalous.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
1 month ago
3016
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
102
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
102
Detects the use of PowerShell to modify Windows Defender security settings by adding exclusion paths or processes. This behavior is indicative of an adversary attempting to whitelist malicious files or processes to evade detection by the antivirus solution.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
102
Detects the use of PowerShell to modify Windows Defender security settings by adding exclusion paths or processes. This behavior is indicative of an adversary attempting to whitelist malicious files or processes to evade detection by the antivirus solution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
202
Detects instances where PowerShell is used to download an executable named 'svchost.exe' from an external IP address (103.86.86.244). The rule monitors for network connections to this IP, file creation events matching specific download patterns in fonts directories, and direct command-line arguments involving the suspicious IP and file path, indicating potential malware dropper activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
102
Page 394 of 1870