Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a specific evasion behavior associated with the NinjaMare malware, where a process idles for at least 7 minutes before moving its window to off-screen coordinates during automated mouse or keystroke input, followed by restoring the window to its original position.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects instances where the Windows Remote Management host process (wsmprovhost.exe) is associated with the execution of specific suspicious files (config.toml, cplsupport.exe, or wtass.exe) within a short time window. This activity often indicates post-exploitation behavior or remote execution of secondary tools using WinRM.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects modifications to the 'metrics_interval' registry value within the 'Software\SynapseAgent' key. This activity suggests configuration changes to the SynapseAgent, which could indicate tampering with agent telemetry or polling frequency.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects Toy Ghouls backdoor binaries (cplsupport.exe and wtass.exe) via known MD5 hashes or the presence of these files alongside a config.toml configuration file.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the presence of Toy Ghouls' mqtt-bird-agent or matrix-bird-agent backdoor binaries. These binaries are identified by specific filenames, the inclusion of ChaCha20-Poly1305 cryptographic indicators, and operations involving the Windows MachineGuid registry key used to seal configuration files.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the modification or creation of the 'SealedConfig' value within the 'Software\synapse\Config' registry key, correlated with the deletion of a 'config.toml' file on the same device. This pattern may indicate an adversary tampering with Synapse software configuration or attempting to remove audit/configuration trails.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the execution of Windowsupdate.exe, a known component of the QUICSILVER campaign. The backdoor is identified by its filename and specific file hash. Once executed, it facilitates system and directory discovery, including hostname enumeration and file system navigation.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
004
Detects network activity initiated by the QUICAgent backdoor (Windowsupdate.exe), which is utilized for file exfiltration and payload delivery. The detection is triggered by identifying the specific file name 'Windowsupdate.exe' in conjunction with the known malicious SHA-256 hash associated with this backdoor.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
004
Detects reconnaissance patterns associated with SynkLoader, specifically focusing on in-memory PowerShell execution used to harvest system information, user privileges, running services, process listings, and Active Directory computer counts.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
004
Detects the presence of small PHP files containing both PHP execution tags and path traversal sequences. This pattern is indicative of a web shell or malicious script placed outside of intended directories via path traversal exploitation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects files that present a valid PNG magic header at the start but contain embedded PostScript instructions. This pattern is commonly used to exploit vulnerabilities in image processing libraries like Ghostscript or ImageMagick, which may attempt to process the file as PostScript despite the misleading header.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects the execution of Windows Explorer (explorer.exe) with specific command-line arguments involving a factory initialization sequence and an embedding flag. This command line pattern is typically associated with shell object manipulation or specific COM object instantiation, which may be leveraged for process injection or hiding malicious activity.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
2 months ago
4011
Detects the use of rundll32.exe to invoke the MiniDump export function of comsvcs.dll to create a memory dump of the LSASS process. This technique is often associated with post-exploitation credential access tools like lsassy or manual execution via remote management tools (e.g., WMI, MMC) by threat actors such as those in the Bumblebee/Akira ransomware intrusion chain.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
104
Detects ClickFix-style social engineering attacks where users are lured into executing obfuscated commands via terminal copy-paste. The detection monitors for the sequential execution of remote file downloads (e.g., curl, PowerShell) followed immediately by shell history-clearing commands designed to obfuscate the malicious activity. This behavior is associated with macOS crypto-drainers and loaders.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
104
Detects the deletion of Volume Shadow Copies using native Windows utilities like WMIC or PowerShell cmdlets (Get-WmiObject, Get-CimInstance) targeting Win32_ShadowCopy. This behavior is a common indicator of ransomware preparation to inhibit system recovery prior to encryption, as observed in attacks involving the Akira ransomware.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
404
Detects the execution of the Windows Installer utility (msiexec.exe) where the command line references an Azure Blob Storage URL. This pattern is commonly used by adversaries to download and install malicious MSI packages directly from a remote storage location, bypassing local file creation.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
1209
Tracks changes and activities affecting a specific user account across both on-premises Active Directory and Microsoft Entra ID. The query combines Windows Security Events and Entra ID Audit Logs into a single timeline, making it easier to investigate account modifications, privilege changes, MFA updates, directory synchronization activity, and administrative actions impacting a user.

This detection is particularly useful during incident response, insider threat investigations, account compromise assessments, and user lifecycle reviews
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
32041
Detects the modification or creation of an NTFS alternate data stream (ADS) on the system file phoneinfo.dll in System32, followed by the execution of a command process within two minutes. This pattern is often associated with file-based living-off-the-land techniques where attackers hide payloads or scripts within existing file metadata to evade detection.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
409
Detects activity related to the registration or attachment of a 'ShieldBreak' cloud provider, identified through specific file paths and event actions. This behavior is indicative of potential unauthorized cloud filtering or provider registration, often used in malicious scenarios to intercept or redirect traffic.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
309
Page 443 of 1870