Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
This rule detects file access, creation, modification, or renaming operations involving sensitive files associated with cryptocurrency wallets (Bitcoin, Electrum, ElectrumSV), game account configurations (Battle.net, Steam, Minecraft), and browser-based cookies (Roblox). The rule filters out legitimate process interactions, identifying suspicious activity from unknown or unauthorized applications potentially attempting to exfiltrate credentials or session tokens.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
This rule detects file access, creation, modification, or renaming operations involving sensitive files associated with cryptocurrency wallets (Bitcoin, Electrum, ElectrumSV), game account configurations (Battle.net, Steam, Minecraft), and browser-based cookies (Roblox). The rule filters out legitimate process interactions, identifying suspicious activity from unknown or unauthorized applications potentially attempting to exfiltrate credentials or session tokens.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects the use of 'schtasks.exe' to disable critical Windows Update or ExploitGuard Malware Removal tasks when initiated by 'LockAppHost.exe'. This behavior is highly irregular, as the LockAppHost process is typically associated with the Windows Lock Screen and should not be modifying security-related scheduled tasks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects the use of 'schtasks.exe' to disable critical Windows Update or ExploitGuard Malware Removal tasks when initiated by 'LockAppHost.exe'. This behavior is highly irregular, as the LockAppHost process is typically associated with the Windows Lock Screen and should not be modifying security-related scheduled tasks.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects malicious network connections, file downloads, or process execution associated with the REVSTEALER malware campaign, which utilizes hijacked YouTube channels to distribute fake game-cheat videos that lure users into downloading 'resightloader.exe' from specific malicious domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects malicious network connections, file downloads, or process execution associated with the REVSTEALER malware campaign, which utilizes hijacked YouTube channels to distribute fake game-cheat videos that lure users into downloading 'resightloader.exe' from specific malicious domains.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects anomalous registry enumeration or modification activities targeting software uninstallation registry keys (Run/Uninstall). By monitoring for multiple subkey accesses by processes not associated with standard software management tools (like MsiExec or explorer), this rule identifies potential reconnaissance or software discovery patterns indicative of malicious activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects execution patterns associated with 'NinjaMare' style malware, where a process masquerading as a browser (e.g., tenbrowser.exe, fireflybrowser.exe) performs an external IP geolocation lookup followed by suspicious registry or file modifications indicative of browser hijacking or extension installation within a five-minute window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
204
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects unauthorized remote write operations (via SMB, Named Pipes, or TCP) to the Windows Certificate Services CertLog directory (C:\Windows\System32\CertLog\). This directory contains sensitive CA database, transaction logs, and checkpoint files. Any modification by a process other than the legitimate certsvc.exe is indicative of potential CA database tampering, malicious log manipulation, or anti-forensics activity.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
106
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
101
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Page 409 of 1870