Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects rapid deletion and creation cycles of the WD_SCAN object manager link, a behavioral pattern associated with a Time-of-Check-to-Time-of-Use (TOCTOU) exploit chain targeting Windows Defender (referenced as CVE-2026-69414). The rule monitors for at least three cycle events occurring within a 5-second window, specifically involving the 'WD_SCAN' object identifier.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects rapid deletion and creation cycles of the WD_SCAN object manager link, a behavioral pattern associated with a Time-of-Check-to-Time-of-Use (TOCTOU) exploit chain targeting Windows Defender (referenced as CVE-2026-69414). The rule monitors for at least three cycle events occurring within a 5-second window, specifically involving the 'WD_SCAN' object identifier.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) modifies registry keys related to Windows network security settings, such as LSA policies, NullSession pipes/shares, or server/workstation auto-sharing. These settings can be manipulated to weaken Windows security posture, potentially facilitating lateral movement or credential access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects ERAAgent.exe performing suspicious dynamic API resolution for functions commonly used by the SLEEPWALKER malware (VirtualProtect, SetSecurityDescriptorDacl, and CryptGenRandom). By resolving these functions at runtime via GetProcAddress rather than including them in the static import table, the malware attempts to evade detection and analysis.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects high-frequency file creation, modification, or renaming activity involving files with the specific '.df_win' extension, likely indicative of mass encryption activity or automated ransomware behavior. The rule excludes known backup and security software processes to reduce noise.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Detects DragonForce ransomware note (readme.txt) referencing known DragonForce Tor negotiation/blog onion addresses
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects DragonForce ransomware note (readme.txt) referencing known DragonForce Tor negotiation/blog onion addresses
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects repeated attempts to delete Volume Shadow Copies using WMIC. This is a common technique used by ransomware and other malware to prevent system recovery and inhibit forensic investigations. The rule filters out known backup agents and service accounts and identifies patterns where multiple distinct deletions occur within a 5-minute window.
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Detects high volumes of file renaming activities involving files with the .df_win extension. This pattern is often indicative of ransomware-like behavior where mass renaming occurs as part of an encryption process, impacting multiple directories.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects Run key persistence pointing to the known VBScript staging directory (C:\Users\Public\Libraries\Default\Lib\Lib1) used by the worm-like ScreenConnect campaign (Aug 2026), matching known script filenames (WindowsServiceHost.vbs, 1.vbs-4.vbs) invoked via wscript.exe/cscript.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
000
Detects Run key persistence pointing to the known VBScript staging directory (C:\Users\Public\Libraries\Default\Lib\Lib1) used by the worm-like ScreenConnect campaign (Aug 2026), matching known script filenames (WindowsServiceHost.vbs, 1.vbs-4.vbs) invoked via wscript.exe/cscript.exe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
000
Detects instances where Faronics Core related processes (FaronicsCore.exe, NCService.exe, ScriptRunner.exe) spawn common system utilities (curl.exe, mshta.exe, msiexec.exe) often used for downloading or executing payloads. This pattern may indicate the abuse of legitimate management software to facilitate unauthorized activity or second-stage payload delivery.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
103
Detects several potentially malicious activities related to Active Directory Certificate Services (AD CS). This includes high volumes of failed requests (potential enumeration), requests for sensitive templates (privilege escalation), and potential impersonation attempts using Subject Alternative Names (SANs). These activities are associated with AD CS abuse techniques.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects the execution of an executable file located within the Windows Temp directory structure via the command prompt (cmd.exe). This pattern is commonly associated with the execution of downloaded payloads, droppers, or staged malware that are moved to temporary directories to evade initial detection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule detects file access, creation, modification, or renaming operations involving sensitive files associated with cryptocurrency wallets (Bitcoin, Electrum, ElectrumSV), game account configurations (Battle.net, Steam, Minecraft), and browser-based cookies (Roblox). The rule filters out legitimate process interactions, identifying suspicious activity from unknown or unauthorized applications potentially attempting to exfiltrate credentials or session tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
201
This rule detects instances where LockAppHost.exe or a variation of it (likely used as a proxy) initiates processes or command-line arguments that interact with Windows services, scheduled tasks, or Windows Defender configurations. This behavior is indicative of an adversary attempting to disable security features, suppress Windows updates, or manipulate system services to evade detection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
201
This rule detects the creation of a scheduled task using 'schtasks.exe' where the task name matches commonly abused names such as 'WinUpdate.exe', 'SoftManager.exe', or 'LockAppHost.exe'. These names are frequently used by adversaries to masquerade as legitimate Windows processes to achieve persistence.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Page 423 of 1870