Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects Adblock.dll used by Docro Hijacker to bypass Chrome Secure Preferences HMAC-SHA256 integrity checks and register infected browser UUID via vendralo[.]info
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects an HTTP GET request to 'dl.php' containing an 'f' parameter (target file) and an 'k' parameter (access token), followed by a response body starting with the 'MZ' header, indicating the successful download of a Windows PE executable as part of a potential phishing campaign stage-2 payload delivery.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects PE binaries masquerading as Microsoft's Windows Update Assistant via forged VersionInfo metadata combined with an unsigned or invalid/unverified digital signature, associated with HVNC backdoor delivery
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects PE binaries masquerading as Microsoft's Windows Update Assistant via forged VersionInfo metadata combined with an unsigned or invalid/unverified digital signature, associated with HVNC backdoor delivery
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects the malicious NFe-themed ZIP dropper MOTOROLA_MOB_COM_NFe_2026-07-16_21781624.zip by known hash and archive structure
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects the malicious NFe-themed ZIP dropper MOTOROLA_MOB_COM_NFe_2026-07-16_21781624.zip by known hash and archive structure
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects HVNC final payload masquerading as Windows Update Assistant, combining Firefox credential theft strings, hardcoded AV process names, and XOR-encoded C2 host configuration
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects HVNC final payload masquerading as Windows Update Assistant, combining Firefox credential theft strings, hardcoded AV process names, and XOR-encoded C2 host configuration
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects the execution of known Windows update-related binaries (UpdateAssistant.exe or AppUpdateHelper.exe) from non-standard, suspicious locations within AppData directories. This behavior is indicative of masquerading, where an adversary attempts to blend in by using a legitimate process name from an unexpected path.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
This rule detects suspicious PowerShell execution that attempts to download files from the internet using the Invoke-WebRequest cmdlet. It specifically looks for PowerShell processes launched with hidden and execution policy bypass flags, coupled with specific hardcoded malicious URL patterns associated with a known campaign (NotaFiscal/nfe_valid_access_key_2026_secure).
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
This rule detects suspicious PowerShell execution that attempts to download files from the internet using the Invoke-WebRequest cmdlet. It specifically looks for PowerShell processes launched with hidden and execution policy bypass flags, coupled with specific hardcoded malicious URL patterns associated with a known campaign (NotaFiscal/nfe_valid_access_key_2026_secure).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Page 421 of 1870