Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects potential DGA fallback beaconing: repeated lookups (~10 per 5 days) of algorithmically-generated .com domains with a failed-resolution cadence, matching the botking implant's C2 fallback behavior.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects a specific Windows PE wrapper associated with the BRIDGEHEAD malware, characterized by a Rust-compiled binary (~22-23MB) with a zeroed-out PE timestamp and a large embedded encrypted payload block.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
001
Detects unauthorized processes accessing browser credential databases (e.g., 'Login Data') used by Google Chrome, Brave, and Microsoft Edge. This activity is a common indicator of credential theft by malicious software.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
606
Detects files with names containing '-EMS' or the specific string 'PO26-EMS134.zip' being created or written to the 'Downloads' directory by common web browsers. This pattern is often associated with phishing campaigns distributing malicious attachments.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
307
Detects installation of unauthorized remote-access/RMM software (AnyDesk, RealVNC, Jump Desktop, Chrome Remote Desktop) outside the normal IT-provisioning window combined with a connection to an unfamiliar external IP, consistent with facilitator-maintained device access in PurpleDelta operations.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2012
This rule detects the creation of a scheduled task where the initiating process is not the standard 'schtasks.exe'. It monitors for activity associated with COM objects (CLSID_TaskScheduler, ITaskService) typically used by applications to interact with the Task Scheduler API programmatically, which is a common technique for persistence or execution in non-standard ways.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
1 month ago
002
Detects the execution of cmd.exe as a child process of the IIS worker process (w3wp.exe) when the worker process is associated with an Exchange application pool. This pattern is indicative of a webshell exploiting an ASPX component to execute arbitrary commands on an Exchange Server.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
8017
Detects a sequence of events where a user interacts with a suspected fraudulent CAPTCHA or slider gate on an non-allowlisted domain, followed by interaction with a spoofed Microsoft 365 login page on the same device within 15 minutes. This behavior is characteristic of the Mirage2FA phishing kit, which intercepts credentials and MFA tokens in real-time.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
7012
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) modifies registry keys related to Windows network security settings, such as LSA policies, NullSession pipes/shares, or server/workstation auto-sharing. These settings can be manipulated to weaken Windows security posture, potentially facilitating lateral movement or credential access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects behavior where the ERAAgent process writes a file to disk and executes that same file shortly after (within 5 minutes). This pattern is consistent with staged payload delivery, decompression, or assembly often observed in malicious activity, specifically referencing SLEEPWALKER malware patterns.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
101
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
101
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
101
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
101
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
101
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
101
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects a suspicious pattern associated with the SLEEPWALKER technique, involving multiple memory write operations followed by a memory protection change within an ERAAgent.exe process. This behavior suggests code injection or dynamic code loading within a process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects behavior where the ERAAgent process writes a file to disk and executes that same file shortly after (within 5 minutes). This pattern is consistent with staged payload delivery, decompression, or assembly often observed in malicious activity, specifically referencing SLEEPWALKER malware patterns.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Page 451 of 1866