Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects execution and file activity associated with the XRed backdoor, which masquerades as 'Synaptics.exe' by running from the non-standard 'C:\ProgramData\Synaptics\' directory instead of authorized system paths.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
27 days ago
000
This rule detects potentially malicious activity involving the modification of Excel macro security settings (specifically VBAWarnings or AccessVBOM) or the creation of autorun.inf files on removable drives. It identifies these behaviors when they coincide with the execution of Synaptics.exe within a 30-minute window, suggesting a potential correlation between local administrative tasks and malicious document-based payloads or portable drive staging.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
27 days ago
000
This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
001
This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
001
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
001
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
001
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
001
Detects an HTTP GET request to 'dl.php' containing an 'f' parameter (target file) and an 'k' parameter (access token), followed by a response body starting with the 'MZ' header, indicating the successful download of a Windows PE executable as part of a potential phishing campaign stage-2 payload delivery.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
401
Detects the malicious NFe-themed ZIP dropper MOTOROLA_MOB_COM_NFe_2026-07-16_21781624.zip by known hash and archive structure
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
001
Detects HVNC final payload masquerading as Windows Update Assistant, combining Firefox credential theft strings, hardcoded AV process names, and XOR-encoded C2 host configuration
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
001
Detects the download of ZIP files with filenames matching known phishing patterns associated with NFe (Nota Fiscal Eletrônica) campaigns, correlated with access to specific malicious or suspicious download URLs within a 15-minute window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
001
Detects the execution of known Windows update-related binaries (UpdateAssistant.exe or AppUpdateHelper.exe) from non-standard, suspicious locations within AppData directories. This behavior is indicative of masquerading, where an adversary attempts to blend in by using a legitimate process name from an unexpected path.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
101
Detects the execution of known Windows update-related binaries (UpdateAssistant.exe or AppUpdateHelper.exe) from non-standard, suspicious locations within AppData directories. This behavior is indicative of masquerading, where an adversary attempts to blend in by using a legitimate process name from an unexpected path.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
001
Detects Evil-WinRM / WinRM-fs usage or wsmprovhost.exe-spawned PowerShell tied specifically to bird-agent backdoor artifacts (cplsupport, wtass, config.toml) or encoded/download-cradle command patterns, rather than any WinRM session, reducing noise from routine remote administration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
105
This rule detects suspicious PowerShell execution that attempts to download files from the internet using the Invoke-WebRequest cmdlet. It specifically looks for PowerShell processes launched with hidden and execution policy bypass flags, coupled with specific hardcoded malicious URL patterns associated with a known campaign (NotaFiscal/nfe_valid_access_key_2026_secure).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
001
This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.
avatar
Arnold Chan@slaz
Defender - KQL
30 days ago
001
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
This rule detects two suspicious patterns: 1) DLL sideloading of 'libcef.dll' by processes like 'ClaudeDesktop.exe' or JetBrains-related tools when executed from non-standard directories like 'Downloads', 'Temp', or 'AppData'. 2) Unauthorized access to common browser credential storage files (e.g., 'Login Data', 'Cookies') by processes other than standard browsers.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
11015
Detects the execution of rundll32.exe with a command line pointing to a WebDAV share path (DavWWWRoot). This technique is commonly used to execute remote payloads by forcing the system to access a remote resource, often as part of a malicious DLL loading chain.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
30 days ago
001
Detects the creation of a scheduled task using schtasks.exe or reg.exe that is configured to run at system logon (/sc onlogon) using potentially malicious or persistence-related filenames such as client32.exe or NSM789508.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
30 days ago
001
Detects attempts by processes to query Windows Registry keys that store configuration data for virtualization software like VMware and Oracle VirtualBox. This behavior is commonly used by malware to detect if it is running within an analysis environment to evade detection.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
102
Page 399 of 1870