Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects the termination of specific security-related processes (e.g., antivirus services) shortly after a specific driver, 'ardrv.sys', is loaded on a Windows system. This sequence is characteristic of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where an adversary loads a signed but vulnerable kernel driver to gain elevated privileges, which they then use to disable or terminate security monitoring processes.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
308
Detects instances where a Java process spawns a shell (cmd.exe, powershell.exe, sh, or bash) that executes suspicious commands often associated with remote code execution (RCE) patterns like those seen in Log4j exploitation. The rule excludes common Java-based build tools to reduce noise.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
1 month ago
4010
This rule detects the presence of files known to be part of the SynkLoader malware delivery chain by matching their SHA256 hashes. It specifically identifies a malicious MSI installer, a Python-based loader (ss.py), and a fake msvcp150.dll runtime file used for DLL side-loading.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
007
Detects the execution of the SSH client (ssh.exe) with remote port forwarding arguments (-R). This technique is commonly used by adversaries to establish a reverse SSH tunnel, allowing them to proxy Remote Desktop Protocol (RDP) traffic from an internal victim machine to an external attacker-controlled server, effectively bypassing perimeter firewall restrictions. This behavior has been observed in various ransomware and C2 campaigns, including Bumblebee and Akira.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
407
Detects the execution of psql.exe to query the Veeam Backup & Replication PostgreSQL database for stored credentials. This pattern is associated with credential theft techniques utilized during ransomware operations (e.g., Bumblebee, Akira) where sensitive configuration or credential data is retrieved and potentially later decrypted via DPAPI.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
307
This rule monitors for email events where the email is flagged for suspicious properties (SPF/DKIM/DMARC failure, threat categorization) and includes potentially malicious attachments or URLs. It then correlates these suspicious emails with subsequent process execution events on the recipient's endpoint within a 30-minute window, identifying a potential successful execution of a phishing payload.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
609
Detects the use of reg.exe to modify a Windows Run registry key to execute a destructive 'format C:' command upon system startup, indicative of wiper-style malware activity.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
003
Detects unauthorized access to Chrome and Microsoft Edge login data files. This behavior is indicative of credential theft, frequently observed in info-stealer malware such as Stealer/1.0, which attempts to extract stored browser credentials for exfiltration.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
003
Detects the use of reg.exe to create persistence via Windows Registry Run or RunOnce keys using specific naming conventions commonly associated with Stealer/1.0 malware (e.g., SystemUpdate, SystemCheck) targeting files located in the Downloads directory.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
1 month ago
003
This rule detects when a .zip archive file is created on a host. The creation of archive files can be a precursor to data exfiltration or a method for adversaries to bundle malicious tools for movement.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
4011
This rule detects instances where LockAppHost.exe or a variation of it (likely used as a proxy) initiates processes or command-line arguments that interact with Windows services, scheduled tasks, or Windows Defender configurations. This behavior is indicative of an adversary attempting to disable security features, suppress Windows updates, or manipulate system services to evade detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects anomalous registry enumeration or modification activities targeting software uninstallation registry keys (Run/Uninstall). By monitoring for multiple subkey accesses by processes not associated with standard software management tools (like MsiExec or explorer), this rule identifies potential reconnaissance or software discovery patterns indicative of malicious activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
This rule detects the creation of a scheduled task using 'schtasks.exe' where the task name matches commonly abused names such as 'WinUpdate.exe', 'SoftManager.exe', or 'LockAppHost.exe'. These names are frequently used by adversaries to masquerade as legitimate Windows processes to achieve persistence.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
000
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects bulk file enumeration/access across multiple users' virtual desktop profile shares via a compromised root DFS drive, which CISA's red team used to read local files of all users regardless of active session.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
308
Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects potential cryptocurrency mining activity where known miner executables (specifically XMRig) or malicious scripts/processes are masquerading as or being spawned by 'LockAppHost.exe' or 'LockAppHost14a02b.exe'. It also monitors for subsequent attempts by these processes to terminate security-related tasks or establish persistence via registry run keys.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
This rule detects potential cryptocurrency mining activity where known miner executables (specifically XMRig) or malicious scripts/processes are masquerading as or being spawned by 'LockAppHost.exe' or 'LockAppHost14a02b.exe'. It also monitors for subsequent attempts by these processes to terminate security-related tasks or establish persistence via registry run keys.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects the use of the Windows Service Control Manager (sc.exe) to create or configure a service named 'TaskHandler'. The rule specifically looks for command lines that reference potentially malicious files like 'F7u00ex.exe' or specific driver/restart patterns often associated with the persistence mechanism of the Spark RAT.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
207
Detects the execution of an executable file located within a randomly-generated, hex-like directory structure directly beneath the %AppData%\Roaming folder. This pattern is characteristic of the GoCaracal malware dropper used by the Dark Caracal threat group to evade detection by hiding executables in paths that mimic temporary or system-generated folder structures.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
003
Page 437 of 1870