Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects artifacts of the winAgent v2.0 Windows implant line, including mod_* modules, WUEngine persistence binaries, and COM/CLSID hijack strings used by AI-assisted implant development
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
Detects artifacts of the winAgent v2.0 Windows implant line, including mod_* modules, WUEngine persistence binaries, and COM/CLSID hijack strings used by AI-assisted implant development
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects artifacts of the winAgent v2.0 Windows implant line, including mod_* modules, WUEngine persistence binaries, and COM/CLSID hijack strings used by AI-assisted implant development
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
104
Detects unauthorized modifications to Active Directory Certificate Services (AD CS) template objects (pKICertificateTemplate) using Windows Event ID 5136. This behavior is indicative of ESC4-style attacks, where an adversary with write access to a certificate template modifies security descriptors, enrollment rights, or sensitive configuration flags (like enabling enrollee-supplied SANs or adding a Client Authentication EKU) to facilitate privilege escalation or persistence.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
7010
This rule monitors for specific PowerShell command-line patterns often associated with malicious activity, including 'ClickFix' clipboard-paste lures (using iex/irm with sleep timers), evasion techniques involving pscustomobject/ScriptBlock, and WinHttp COM object usage for stage-2 payload fetching. These patterns are characteristic of adversary attempts to bypass security controls and download secondary implants.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
205
Triggers on any Sysmon "FileExecutableDetected" event, which triggers every time a PE that is monitored by the config is created.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
106
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
106
Detects a suspicious sequence of activities where PowerShell downloads or extracts specific zip files (node.zip, build.zip) to staging directories, followed by the execution of associated binaries like node.exe, winpty-agent.exe, or winpty.dll from those same locations. This behavior is indicative of an adversary staging and executing tooling within temporary user directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects a suspicious sequence of activities where PowerShell downloads or extracts specific zip files (node.zip, build.zip) to staging directories, followed by the execution of associated binaries like node.exe, winpty-agent.exe, or winpty.dll from those same locations. This behavior is indicative of an adversary staging and executing tooling within temporary user directories.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects periodic screen capture activity performed by Node.js or Electron-based processes, correlated with subsequent outbound network connections to public IP addresses within a short timeframe. This behavior is indicative of the JSCeal malware's surveillance and exfiltration module, where local reconnaissance via screenshotting is followed by data transmission.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
This rule detects network connections or DNS queries to known phishing domains (typosquatted Microsoft login domains), DeadDrop Resolver domains, and suspicious HTML payloads served from common CDN/package hosting sites (e.g., unpkg.com, npmmirror.com, cdn.jsdelivr.net, yarnpkg.com). These patterns are indicative of initial access attempts via phishing or the secondary stage of malware C2 communication.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
203
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects modifications to the Windows Registry that disable Microsoft Defender Tamper Protection. Tamper Protection is a security feature that prevents malicious changes to security settings, including the disabling of antivirus and real-time monitoring.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
103
Detects attempts to tamper with Microsoft Windows Defender configuration, specifically by modifying exclusion paths via PowerShell cmdlets (Add-MpPreference, Set-MpPreference), direct registry modifications, or forced Group Policy updates. It also monitors for the disabling of Tamper Protection via registry and the creation of scheduled tasks designed to apply Defender exclusions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
103
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Page 403 of 1870