Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects Node.js or Electron processes executing from suspicious paths (e.g., Temp, Roaming) while interacting with web browser credential files or executing commands consistent with automated credential dumping tools.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects Node.js or Electron processes executing from suspicious paths (e.g., Temp, Roaming) while interacting with web browser credential files or executing commands consistent with automated credential dumping tools.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects scripts or files referencing the JSCeal loading chain that invokes node.exe with -r preflight.js to decompress and execute a compiled V8 bytecode app.jsc payload
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects the presence of 'winpty-agent.exe' or 'winpty.dll' in proximity to 'node.zip' or 'build.zip' files within common user-writable or temporary directories ('AppData\Local\Temp', 'AppData\Roaming', 'ProgramData', 'Users\Public'). This pattern is often associated with the staging and execution of malicious tools or command-line wrappers in non-standard locations, bypassing legitimate application installation directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
This rule detects the presence of 'winpty-agent.exe' or 'winpty.dll' in proximity to 'node.zip' or 'build.zip' files within common user-writable or temporary directories ('AppData\Local\Temp', 'AppData\Roaming', 'ProgramData', 'Users\Public'). This pattern is often associated with the staging and execution of malicious tools or command-line wrappers in non-standard locations, bypassing legitimate application installation directories.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects the presence of 'winpty-agent.exe' or 'winpty.dll' in proximity to 'node.zip' or 'build.zip' files within common user-writable or temporary directories ('AppData\Local\Temp', 'AppData\Roaming', 'ProgramData', 'Users\Public'). This pattern is often associated with the staging and execution of malicious tools or command-line wrappers in non-standard locations, bypassing legitimate application installation directories.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects a hardcoded PEM RSA public key embedded alongside JSCeal-specific compiled V8 bytecode obfuscation artifacts, used to encrypt exfiltrated data or C2 communications
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the execution of BrowserCore.exe, a native messaging component for web browsers, when combined with command-line redirection (< or >) or specific output file creation (e.g., prt_cookie.txt, formatted_nonce.txt). This behavior is characteristic of an attack designed to extract Primary Refresh Tokens (PRTs) or browser cookies, which can be used to bypass authentication mechanisms.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
1 month ago
106
Detects periodic screen capture activity performed by Node.js or Electron-based processes, correlated with subsequent outbound network connections to public IP addresses within a short timeframe. This behavior is indicative of the JSCeal malware's surveillance and exfiltration module, where local reconnaissance via screenshotting is followed by data transmission.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
Detects when a Node.js process initiates a low-level keyboard hook (WH_KEYBOARD_LL or WH_KEYBOARD) while running from common user-writable directories, which may indicate malicious keylogging activity by a suspicious process.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects when a Node.js process initiates a low-level keyboard hook (WH_KEYBOARD_LL or WH_KEYBOARD) while running from common user-writable directories, which may indicate malicious keylogging activity by a suspicious process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects anomalous child process execution (e.g., cmd.exe, powershell.exe, whoami) by PaperCut application processes (java.exe, pc-app.exe, PCClient.exe), which is indicative of post-exploitation activity following an authentication bypass and remote code execution chain against PaperCut NG/MF.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
000
Detects anomalous child process creation (e.g., cmd.exe, powershell.exe, rundll32.exe) spawned by the VMware host process 'vmware-vmx.exe'. This behavioral pattern is a high-confidence indicator of potential guest-to-host virtual machine escape, specifically monitoring for activity associated with vulnerabilities like CVE-2026-59346.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
This rule detects the execution of processes or network connections that impersonate 'WhatsApp' or 'Instagram' companion applications. It identifies specific file names and process command lines that mimic these applications, often associated with browser-launched or malicious payloads, and monitors for associated network traffic directed toward suspicious endpoints like herokuapp domains.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
101
Detects execution of PowerShell.exe initiated by cplsupport.exe with hidden window styles and non-interactive, no-profile flags, which is often indicative of obfuscated command execution or malicious script activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
101
Detects the modification or creation of the 'SealedConfig' value within the 'Software\synapse\Config' registry key, correlated with the deletion of a 'config.toml' file on the same device. This pattern may indicate an adversary tampering with Synapse software configuration or attempting to remove audit/configuration trails.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
This rule detects attempts to perform process injection techniques (such as creating remote threads or opening processes) targeting the 'ctfmon.exe' process, where the initiating process is not 'ctfmon.exe' itself. This behavior is indicative of potential malicious activity such as reflective code loading or the execution of malware like SparkRAT, which may use this legitimate Windows process to mask its activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
409
Page 435 of 1870