Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects potentially malicious activity associated with removable media (USB drives) by identifying two distinct patterns: first, the creation of an 'autorun.inf' file on a removable drive followed by the execution of a script or executable from that same drive shortly after. Second, it identifies executables appearing on removable media that are launched across multiple distinct hosts within a one-hour window, which may indicate worm-like spreading or mass-malware distribution via portable storage.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
This rule detects potential lateral movement activity by identifying executable or script files being written to administrative shares (C$ or ADMIN$) followed by the execution of a file with the same name on the destination device within 15 minutes. It includes logic to filter out known deployment/patch management service accounts and file names to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects unauthorized modifications to critical authentication-related configuration files and registry keys. Specifically monitors changes to LSA security packages and notification packages on Windows systems, as well as PAM configuration file modifications on Linux systems, when performed by unsigned or untrusted processes outside of known installer activity.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects high volumes of file renaming activities involving files with the .df_win extension. This pattern is often indicative of ransomware-like behavior where mass renaming occurs as part of an encryption process, impacting multiple directories.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects repeated attempts to delete Volume Shadow Copies using WMIC. This is a common technique used by ransomware and other malware to prevent system recovery and inhibit forensic investigations. The rule filters out known backup agents and service accounts and identifies patterns where multiple distinct deletions occur within a 5-minute window.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
This rule detects potentially malicious activity where multiple critical processes (such as database engines or email clients) are terminated in a short time frame, correlated with a high volume of file creation or modification events on the same device. This behavior is indicative of destructive activity, such as ransomware encrypting data stores or disabling defensive software.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects high-frequency file creation, modification, or renaming activity involving files with the specific '.df_win' extension, likely indicative of mass encryption activity or automated ransomware behavior. The rule excludes known backup and security software processes to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects unauthorized processes accessing sensitive web browser files (login data, cookies, local state) from suspicious or non-standard paths. This is a common behavioral pattern for infostealers attempting to exfiltrate user credentials and browser session tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects the download of ZIP files with filenames matching known phishing patterns associated with NFe (Nota Fiscal Eletrônica) campaigns, correlated with access to specific malicious or suspicious download URLs within a 15-minute window.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects the execution of known Windows update-related binaries (UpdateAssistant.exe or AppUpdateHelper.exe) from non-standard, suspicious locations within AppData directories. This behavior is indicative of masquerading, where an adversary attempts to blend in by using a legitimate process name from an unexpected path.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
This rule detects behavior associated with Hidden Virtual Network Computing (HVNC) implants, which allow remote attackers to interact with a hidden desktop session on a compromised host. The rule specifically looks for processes that perform a sequence of sensitive Windows API calls—CreateDesktopA, SetThreadDesktop, BitBlt/GetDIBits (for screen capture), and SendInput (for input simulation)—when originating from suspicious, unsigned, or non-standard file paths, indicating potential malicious use rather than legitimate software.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects the creation of a shortcut file (.lnk) in the Windows Startup directory by the 'UpdateAssistant.exe' process. The rule specifically looks for evidence of a masquerading attempt where the shortcut appears to be an application update helper but potentially references or exhibits characteristics of being linked to a notepad execution, suggesting persistence via shortcut file manipulation.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects a specific pattern of PowerShell execution involving the download of files from a remote endpoint using parameters associated with Brazilian tax documents (NotaFiscal) to the Desktop directory, followed by immediate execution. The rule looks for a combination of hidden window style, Invoke-WebRequest, specific URL parameters (dl.php, NFe identifiers), and subsequent Start-Process calls, which is indicative of malware dropper activity.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
This rule detects the creation of a scheduled task intended to run an executable named 'wsc_updata.exe' from a temporary directory, or identifies svchost.exe initiating a process from that location. Such behavior is indicative of potential persistence mechanisms where malicious actors attempt to run code from unauthorized or writable directories under the context of system processes or scheduled tasks.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
100
Detects remote administration activity via Windows Management Instrumentation (WMI) originating from a host that has no recorded history of performing such actions within the previous 30 days. This includes the use of wmic.exe for remote nodes, Invoke-WmiMethod, or WmiPrvSe.exe spawning common command-line interpreters or utilities.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
100
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Page 396 of 1870