Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the creation of files within a directory structure matching 'ShieldBreak_' that involve 'BERLIN:' in the file path, specifically when 'ntdll.dll' is present in either the previous filename or the initiating process command line. This pattern is indicative of specific malware behavior involving file manipulation and potential DLL sideloading or obfuscation attempts.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
309
This rule detects file creation and modification events within a specific 'ShieldBreak' directory structure, as well as process execution events where the command line references this directory or contains a specific 'Placeholder created.' string. This pattern is indicative of potential data staging or file-based operations by malicious activity using this naming convention.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
309
Detects instances where processes other than the primary web browsers (Chrome, Brave, Firefox) create, rename, or modify sensitive browser data files like 'Cookies' or 'Login Data'. This behavior is indicative of credential theft or data exfiltration attempts where an adversary is accessing browser-stored information.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
205
Detects the creation of an NTUSER.MAN file followed by an update or creation of a registry run key (Run or RunOnce) on the same device within a 60-minute window. NTUSER.MAN is a mandatory user profile file that, when present, can be used to override user settings and persist malicious configurations or startup entries.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
105
Detects the GoCaracal lightweight implant performing process injection by identifying combinations of remote process memory allocation (VirtualAllocRemoteApiCall), memory writing (WriteProcessMemoryRemoteApiCall), and remote thread creation (CreateRemoteThreadApiCall) associated with specific suspicious filenames. It also monitors command-line activity for injection-related flags.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
005
Detects file creation, modification, or rename activity involving filenames that contain credential related indicators. The detection focuses on common document, spreadsheet, text, PDF, and archive formats that are frequently used to store sensitive authentication material. Such files may represent exposed credentials that could be leveraged by adversaries for credential access, privilege escalation, or lateral movement following endpoint compromise.
Anas Sohail@Anas44
avatar
Detections.ai Community
2 months ago
27251
Detects the execution of Node.js processes where the command line contains the argument 'parser.js'. This is often used by adversaries to execute JavaScript-based payloads or custom scripts for malicious purposes.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
This rule monitors for the execution of Node.js processes involving a file named 'parser.js' and a component or argument referred to as 'ldata'. This behavior is characteristic of specific application workflows, but when observed as a standalone or unusual process, it may indicate unauthorized script execution or the activity of a malicious node-based tool.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
000
Detects the execution of Node.js processes where the command line contains the argument 'parser.js'. This is often used by adversaries to execute JavaScript-based payloads or custom scripts for malicious purposes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
000
This rule detects the execution of a file named 'report.bin' and correlates it with subsequent network connections originating from the same process. This behavior is indicative of a potential C2 heartbeat or exfiltration activity involving a non-standard or obfuscated executable.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the execution of 'driverquery.exe' to enumerate information about the 'npf.sys' driver (Network Packet Filter), which is associated with Npcap/WinPcap used for packet capture. The rule specifically monitors when this command is launched by non-standard parent processes like 'report.bin' or 'nw.exe', which may indicate malicious reconnaissance or network monitoring tools.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the addition of suspicious file names or known potentially unwanted program artifacts to Windows Run registry keys, often used for persistence. The rule correlates registry modifications with potential installer process activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects instances where the Mp3tag executable (Mp3tag.exe) loads the DLL 'tak_deco_lib.dll'. This behavior is indicative of potential DLL sideloading or search order hijacking, where a malicious DLL is placed in the application's directory to be loaded by the legitimate process.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
105
Detects behavior observed during BTR Reforged execution by correlating a .sys file staged from a user-writable location with subsequent driver service configuration and kernel driver loading within a short time window. The detection focuses on the behavior rather than specific BTR filenames, hashes, or process names.
avatar
Yazan Sh@ysh
avatar
Detections.ai Community
2 months ago
3125
Detects installation of a Windows service (System EventID 7045)
named after known VirtualBox Guest Additions components (VBoxGuest, VBoxMouse, VBoxSF,
VBoxService, VBoxVideo, VBoxWDDM). Fires when either:
(a) the service binary is registered outside the legitimate VirtualBox install/driver
paths, or
(b) a driver-class component name (VBoxGuest/VBoxMouse/VBoxSF/VBoxVideo/VBoxWDDM) is
registered as a user-mode/own-process service instead of a kernel or file-system
driver — a structural mismatch that cannot occur with the genuine component and is
a strong indicator of name-based masquerading (T1036.005).
Adversaries reuse trusted VirtualBox names to blend malicious persistence into expected
guest-VM/EDR-noise telemetry.
avatar
Pavan Pothamsetti@pepete
avatar
Detections.ai Community
2 months ago
4111
Detects interactive sign-in by an Entra Connect/AAD Connect sync service account (Sync_ prefix), which should only authenticate non-interactively. CISA's red team compromised a hybrid sync account to pivot from on-prem AD into cloud resources.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
605
The following analytic identifies the use of ping commands as a delay or sleep mechanism within batch-style command execution.
It leverages process creation telemetry from Endpoint Detection and Response (EDR) agents and examines process and parent process command-line fields for ping commands that specify a count and are chained with additional commands using command separators or redirection operators.
While execution of the command may generate individual process creation events, such as a separate ping.exe process, this analytic specifically focuses on the original command string passed to a command interpreter, such as cmd.exe /c, that combines the ping-based delay with subsequent command execution.
Adversaries may use ping as an alternative to explicit sleep or timeout commands to introduce execution delays, potentially evading automated analysis, sandboxing, or behavior-based detection.
Because ping is commonly used for legitimate network troubleshooting, findings should be reviewed in the context of the complete command line, parent process, user, and commands executed before or after the delay.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
5010
Detects the execution of JavaScript files using Windows Script Host (wscript.exe or cscript.exe) containing specific obfuscated patterns or indicators typically associated with malicious multi-stage dropper payloads. These patterns are indicative of obfuscated code attempting to evade static analysis and security controls during the initial execution phase.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
3011
Detects periodic execution cycles of ERAAgent.exe that involve memory protection changes, characteristic of the SLEEPWALKER malware's XOR-decrypt-execute-reencrypt loop scheduled by a cron-like mechanism.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
305
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
605
Detects upload requests targeting executable or server-side script file extensions.
avatar
Anmol Vats@jerry
avatar
Detection Engineers
1 month ago
002
Page 444 of 1870