Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the use of 'bootsect.exe' with parameters specifically designed to overwrite the Master Boot Record (MBR) and the targeting or modification of 'winload.efi', which is indicative of destructive boot-level attacks or bootkit deployment attempts.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
001
Detects persistence attempts via the 'BootExecute' registry value hijack and identifies specific file system paths associated with XHOPELESS malware infection markers. This rule alerts on unauthorized modifications to the session manager startup configuration or the presence of known infection indicators.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
101
Detects a process enabling multiple sensitive Windows privileges simultaneously via a single AdjustTokenPrivileges event (Event ID 4703). This behavior is characteristic of malicious tools, such as the XHOPELESS wiper, attempting to gain broad system control for activities like tampering with firmware, killing protected processes, loading malicious drivers, or modifying boot configurations.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
101
Detects suspicious activity related to the Windows Subsystem for Linux (WSL), such as installing new distributions (especially penetration testing ones like Kali), importing custom images, or executing commands non-interactively. Attackers may use WSL to run malicious Linux binaries, hide artifacts, and evade defenses.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
201
This rule detects the execution of arbitrary commands via the Windows Subsystem for Linux (WSL) by monitoring process creation events where 'wsl.exe' is the executable. It specifically looks for command lines that include flags like '--exec' or '-e', or common shell commands and downloaders such as 'curl', 'wget', 'bash -c', 'sh -c', 'nc ', or 'ncat '. This activity can indicate an adversary leveraging WSL to execute malicious code or bypass security controls.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects the ESET Remote Administrator (ERAAgent.exe) process loading the 'dpapisvc.dll' module. This behavior is indicative of potential DLL side-loading where an attacker places a malicious DLL with the same name as a legitimate system library in the agent's directory to achieve code execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) modifies registry keys related to Windows network security settings, such as LSA policies, NullSession pipes/shares, or server/workstation auto-sharing. These settings can be manipulated to weaken Windows security posture, potentially facilitating lateral movement or credential access.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects ERAAgent.exe performing suspicious dynamic API resolution for functions commonly used by the SLEEPWALKER malware (VirtualProtect, SetSecurityDescriptorDacl, and CryptGenRandom). By resolving these functions at runtime via GetProcAddress rather than including them in the static import table, the malware attempts to evade detection and analysis.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects a suspicious pattern associated with the SLEEPWALKER technique, involving multiple memory write operations followed by a memory protection change within an ERAAgent.exe process. This behavior suggests code injection or dynamic code loading within a process.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects the execution of 'driverquery.exe' to enumerate information about the 'npf.sys' driver (Network Packet Filter), which is associated with Npcap/WinPcap used for packet capture. The rule specifically monitors when this command is launched by non-standard parent processes like 'report.bin' or 'nw.exe', which may indicate malicious reconnaissance or network monitoring tools.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
101
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
001
Detects modifications to the Windows Registry that disable Microsoft Defender Tamper Protection. Tamper Protection is a security feature that prevents malicious changes to security settings, including the disabling of antivirus and real-time monitoring.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
101
Page 414 of 1870