Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects UNC3569/GRAYRABBIT shellcode combining call/pop self-location, PEB InLoadOrderModuleList walk, and the specific XOR-then-ROR8 export-name hashing loop observed in the GRAYRABBIT loader chain, requiring multiple distinctive elements together to reduce false positives on generic shellcode idioms
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects UNC3569/GRAYRABBIT shellcode combining call/pop self-location, PEB InLoadOrderModuleList walk, and the specific XOR-then-ROR8 export-name hashing loop observed in the GRAYRABBIT loader chain, requiring multiple distinctive elements together to reduce false positives on generic shellcode idioms
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
000
Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Detects Rust-compiled executables exhibiting C2-capable characteristics consistent with backdoors dropped on compromised JFrog Artifactory servers
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects Rust-compiled executables exhibiting C2-capable characteristics consistent with backdoors dropped on compromised JFrog Artifactory servers
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
000
Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
000
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
000
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
This rule detects the use of PowerShell or common command-line network tools (curl, wget) to download or interact with files containing references to WPPConnect or WhatsApp automation JavaScript libraries. It flags activity where the parent process is a common LOLBIN (Living Off the Land Binary) or originates from suspicious locations such as user temporary directories, which is indicative of malicious automated tooling or script execution.
avatar
F S@Fsdr
avatar
Detections.ai Community
27 days ago
000
Detects when an attacker tries to disable User Account Control (UAC) notification by tampering with the "UACDisableNotify" value.
UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users.
When "UACDisableNotify" is set to 1, UAC prompts are suppressed.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
909
Detects the installation of common remote access tools (such as TeamViewer, AnyDesk, or ScreenConnect) followed by an external network connection within a 10-minute window, which may indicate unauthorized remote access setup.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
3010
This rule detects the execution of a file named 'report.bin' and correlates it with subsequent network connections originating from the same process. This behavior is indicative of a potential C2 heartbeat or exfiltration activity involving a non-standard or obfuscated executable.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
304
Page 405 of 1870