Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
000
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
000
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
000
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
000
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
000
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
000
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
000
Detects the execution of control.exe with suspicious command-line arguments involving WebDAV paths (DavWWWRoot) and file extensions like .cpl or .dll, initiated by Windows task-related processes (svchost, taskeng, schtasks). This pattern is indicative of potential malicious payload loading or proxy execution where a scheduled task is used to trigger a secondary malicious component.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
000
Detects the execution of control.exe with suspicious command-line arguments involving WebDAV paths (DavWWWRoot) and file extensions like .cpl or .dll, initiated by Windows task-related processes (svchost, taskeng, schtasks). This pattern is indicative of potential malicious payload loading or proxy execution where a scheduled task is used to trigger a secondary malicious component.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
000
Detects the execution of control.exe with suspicious command-line arguments involving WebDAV paths (DavWWWRoot) and file extensions like .cpl or .dll, initiated by Windows task-related processes (svchost, taskeng, schtasks). This pattern is indicative of potential malicious payload loading or proxy execution where a scheduled task is used to trigger a secondary malicious component.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
Detects the execution of control.exe with suspicious command-line arguments involving WebDAV paths (DavWWWRoot) and file extensions like .cpl or .dll, initiated by Windows task-related processes (svchost, taskeng, schtasks). This pattern is indicative of potential malicious payload loading or proxy execution where a scheduled task is used to trigger a secondary malicious component.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
000
This rule performs a multi-source correlation (network, DNS, file, and process telemetry) to detect artifacts associated with the Coruna campaign. It looks for known malicious file hashes (SHA1), C2 IP addresses, and specific domain/URL patterns in process command lines and network connections.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
000
This rule performs a multi-source correlation (network, DNS, file, and process telemetry) to detect artifacts associated with the Coruna campaign. It looks for known malicious file hashes (SHA1), C2 IP addresses, and specific domain/URL patterns in process command lines and network connections.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
This rule performs a multi-source correlation (network, DNS, file, and process telemetry) to detect artifacts associated with the Coruna campaign. It looks for known malicious file hashes (SHA1), C2 IP addresses, and specific domain/URL patterns in process command lines and network connections.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
000
Detects exploitation attempts against CVE-2026-55040 on Microsoft SharePoint Server. This vulnerability allows an attacker to bypass authentication by sending a malformed JSON Web Token (JWT) with an 'alg: none' header or an empty signature. The SharePoint server incorrectly trusts the provided token, enabling unauthorized access to sensitive API and SOAP endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
002
Detects instances where a legitimate Remote Monitoring and Management (RMM) agent (MSP360 or Faronics) is used to execute PowerShell commands that silently install ScreenConnect (ConnectWise Control) MSI packages within a 10-minute window. This behavior is indicative of an adversary abusing administrative tools for lateral movement or persistence.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
101
Detects potential persistence and network persistence mechanisms associated with the MSP360 RMM agent. The rule correlates the creation of a Windows service for RMM.Agent.exe or RMM.Agent.Launcher.exe with the addition of a firewall rule allowing UDP traffic on port 48678 by netsh or PowerShell, occurring within a one-hour window.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
8 days ago
001
Detects the execution of a Node.js interpreter (node.exe or node) as a child process of a Fortinet management-related process, or where the command line contains references to Fortinet. This behavior is indicative of post-exploitation activity related to CVE-2025-25249, where a heap-based buffer overflow is exploited to deploy the PivotC2 remote access trojan.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
002
Page 45 of 1870