Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
This rule detects behavior associated with Hidden Virtual Network Computing (HVNC) implants, which allow remote attackers to interact with a hidden desktop session on a compromised host. The rule specifically looks for processes that perform a sequence of sensitive Windows API calls—CreateDesktopA, SetThreadDesktop, BitBlt/GetDIBits (for screen capture), and SendInput (for input simulation)—when originating from suspicious, unsigned, or non-standard file paths, indicating potential malicious use rather than legitimate software.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
This rule detects behavior associated with Hidden Virtual Network Computing (HVNC) implants, which allow remote attackers to interact with a hidden desktop session on a compromised host. The rule specifically looks for processes that perform a sequence of sensitive Windows API calls—CreateDesktopA, SetThreadDesktop, BitBlt/GetDIBits (for screen capture), and SendInput (for input simulation)—when originating from suspicious, unsigned, or non-standard file paths, indicating potential malicious use rather than legitimate software.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects the creation of a shortcut file (.lnk) in the Windows Startup directory by the 'UpdateAssistant.exe' process. The rule specifically looks for evidence of a masquerading attempt where the shortcut appears to be an application update helper but potentially references or exhibits characteristics of being linked to a notepad execution, suggesting persistence via shortcut file manipulation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects the creation of a shortcut file (.lnk) in the Windows Startup directory by the 'UpdateAssistant.exe' process. The rule specifically looks for evidence of a masquerading attempt where the shortcut appears to be an application update helper but potentially references or exhibits characteristics of being linked to a notepad execution, suggesting persistence via shortcut file manipulation.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Detects the creation of a shortcut file (.lnk) in the Windows Startup directory by the 'UpdateAssistant.exe' process. The rule specifically looks for evidence of a masquerading attempt where the shortcut appears to be an application update helper but potentially references or exhibits characteristics of being linked to a notepad execution, suggesting persistence via shortcut file manipulation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects attempts to crash or terminate the Kaspersky Antivirus process (avp.exe), as well as associated events indicating the service has been stopped or is encountering abnormal fault conditions. This behavior is indicative of an adversary attempting to disable security software.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
204
Detects anomalous access to specific registry keys under SYSTEM\CurrentControlSet\Control\Lsa that are associated with LSA secrets. The rule monitors for multiple registry operations (set, create, delete) performed by processes other than standard Windows system processes (lsass.exe, svchost.exe, winlogon.exe, services.exe), which is often indicative of credential dumping attempts.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
204
Detects the issuance of certificates using templates associated with the Certificate Request Agent. This is a critical component of the ESC3 attack vector, where an adversary first acquires an Enrollment Agent certificate and subsequently uses it to enroll for certificates on behalf of other privileged users or principals.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
705
Detects Invoke-Mimikatz PowerShell script and alike. Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
003
Detects suspicious PowerShell execution spawned by common development tools or shell environments like node, npm, or WSL. The rule evaluates the process lineage and scores the command line arguments for characteristics commonly used by malicious payloads, such as hidden execution, bypass flags, network download activity, or temporary file access, which are indicative of software supply chain attacks or automated malicious script execution.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
2 months ago
23051
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
This rule detects the use of raw sockets by 'ERAAgent.exe' by monitoring for socket I/O control (Ioctl) operations involving 'SIO_RCVALL'. This configuration, often associated with promiscuous mode, allows an application to capture all network traffic received by the network interface, a behavior commonly used by network sniffing tools or malicious implants to intercept sensitive data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule detects potentially malicious memory manipulation and thread execution activity originating from the ERAAgent.exe process. It specifically identifies when ERAAgent.exe calls VirtualProtect or VirtualAlloc to set memory as PAGE_EXECUTE_READWRITE, followed shortly by a CreateThread or CreateRemoteThread operation. This behavior is indicative of process injection or reflective code loading, where an executable image is manually mapped into memory and executed, bypassing traditional file-based detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Page 422 of 1870