Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the installation or execution of known remote access tools (RMM) from suspicious parent processes (browsers, archives) or from user-writable directories (Temp, Downloads). This behavior is characteristic of initial access and staging activities performed by ransomware operators or Initial Access Brokers (IABs). The rule excludes known IT-managed deployment paths and signed binaries used by the organization.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
101
Detects the installation or execution of known remote access tools (RMM) from suspicious parent processes (browsers, archives) or from user-writable directories (Temp, Downloads). This behavior is characteristic of initial access and staging activities performed by ransomware operators or Initial Access Brokers (IABs). The rule excludes known IT-managed deployment paths and signed binaries used by the organization.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
101
Detects the creation or modification of Windows Registry RunOnce keys using the value name 'GlobalProtectVPN', intended to execute 'GlobalProtect.exe'. This pattern is associated with malware masquerading as legitimate GlobalProtect VPN software to achieve persistence upon user logon.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detection & Hunting Community
1 month ago
101
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
101
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
001
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
001
Detects the creation of a Windows Scheduled Task configured with the 'InteractiveToken' LogonType. This configuration is often associated with adversary techniques designed to execute tasks in an interactive user context, potentially to bypass certain security controls or to facilitate the extraction of sensitive tokens or credentials (e.g., PRT cookies).
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
1 month ago
8017
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects the ESET Remote Administrator (ERAAgent.exe) process loading the 'dpapisvc.dll' module. This behavior is indicative of potential DLL side-loading where an attacker places a malicious DLL with the same name as a legitimate system library in the agent's directory to achieve code execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
101
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects instances where WerFault.exe or WerMgr.exe, running with SYSTEM privileges, loads a DLL file from the Windows\System32 directory that was created within 10 minutes of the image load event. This behavior is indicative of potential DLL side-loading or hijack techniques used to achieve privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
205
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects the execution of processes named 'ProManager.exe' or 'ProManagerServicedc894.exe', which may be indicative of unauthorized software or potentially malicious activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
202
Detects the execution of processes named 'ProManager.exe' or 'ProManagerServicedc894.exe', which may be indicative of unauthorized software or potentially malicious activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects the execution of an executable file located within the Windows Temp directory structure via the command prompt (cmd.exe). This pattern is commonly associated with the execution of downloaded payloads, droppers, or staged malware that are moved to temporary directories to evade initial detection.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
102
Detects the execution of an executable file located within the Windows Temp directory structure via the command prompt (cmd.exe). This pattern is commonly associated with the execution of downloaded payloads, droppers, or staged malware that are moved to temporary directories to evade initial detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
202
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
202
Page 408 of 1870