Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

This rule detects the use of the Windows 'copy /b' command to reconstruct an executable file (named Windowsupdate.exe) by concatenating two separate files ('header.doc' and 'body.doc'). This behavior is consistent with file-based reconstruction techniques used to bypass security controls by splitting payloads into seemingly benign components.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
307
Detects activity (opens, reads, or writes) involving the Windows Registry key associated with Chrome's App Paths. Modifying this key is a common method for achieving persistence or hijacking the execution path of the Chrome browser.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
405
This rule detects browser-based runtime evaluations that utilize WebRTC's RTCPeerConnection and createDataChannel APIs, often indicative of an adversary attempting to establish a covert command-and-control (C2) channel directly from a compromised browser session.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
005
Detects instances of Chrome or Edge browsers initiating a network connection to the localhost (loopback) while executing commands associated with the Chrome DevTools Protocol, specifically targeting Page.setBypassCSP. This behavior is indicative of an adversary attempting to disable Content Security Policy (CSP) protections, often as part of a browser-based attack or malicious extension activity using remote debugging features.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
305
Detects the presence of Afd4Eop12_x64.dll or the execution of command lines referencing specific exploit indicators such as 'initialize_afd_npfs_exploit' or 'enable_god_mode', often associated with local privilege escalation exploits leveraging kernel vulnerabilities.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
10053
The following analytic detects a process enabling the "SeDebugPrivilege" privilege token. It leverages Windows Security Event Logs with EventCode 4703, filtering out common legitimate processes. This activity is significant because SeDebugPrivilege allows a process to inspect and modify the memory of other processes, potentially leading to credential dumping or code injection. If confirmed malicious, an attacker could gain extensive control over system processes, enabling them to escalate privileges, persist in the environment, or access sensitive information.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
206
Detects a victim's WhatsApp Web session being abused to automatically propagate ClickFix lure links to contacts, correlated with recent infection indicators.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
608
Detects AutoIt3.exe launched with a .a3x script argument from a %TEMP%\IXP* self-extraction directory, spawned by WEXTRACT.EXE — the ACRStealer first-stage execution chain (setup_patched.exe IExpress self-extractor deploying an encrypted AutoIt payload).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6010
Detects self-deletion of ACRStealer's first-stage payload artifacts (Proper.a3x / BrowserMetrics) by the same process that recently created a persistence Run key or dropped follow-on files, indicating anti-forensic cleanup after installation.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2010
Detects OptiDrive.exe sweeping multiple browser credential/cookie store files (Local State, Login Data, Cookies, History) across at least 3 distinct files within a 2-minute window, consistent with ACRStealer's browser credential harvesting.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4010
Detects Windows Security events (Event IDs 4728 and 4756) where a member is added to a sensitive or privileged Active Directory domain global or universal security group. The rule compares the target group against a locally maintained inventory of monitored groups to identify potential unauthorized privilege escalation or persistence.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
1010
This rule detects a multi-stage attack pattern associated with Akira ransomware, including AD enumeration using PowerShell, data staging with WinRAR, S3 exfiltration via s5cmd, AnyDesk service installation, registry manipulation for persistence via Safe Mode, and boot configuration changes to facilitate EDR bypass. It also incorporates detection for specific IOCs like attacker jump host RDP connections and malicious file hashes.
avatar
Aamir Muhammad@Aamir
CrowdStrike Logscale
2 months ago
206
Detects modifications to Windows user accounts where the 'Password Never Expires' flag is enabled. This modification, often represented by the DONT_EXPIRE_PASSWORD userAccountControl flag (Event ID 4738), may indicate an attempt to establish persistence or weaken credential lifecycle security by bypassing password rotation requirements.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
4010
This rule detects attempts to manipulate process access tokens using the Windows 'SetTokenInformation' API. Specifically, it monitors for adjustments to token privileges or integrity levels, or the presence of 'Untrusted' markers. These behaviors are often indicative of an adversary attempting to bypass Windows access controls, perform token manipulation, or conduct privilege escalation.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
Detects the loading of known vulnerable drivers (BYOVD - Bring Your Own Vulnerable Driver) by cross-referencing Sysmon Event ID 6 (Driver Loaded) image hashes with the LOLDrivers.io project database. This technique is often used by adversaries to elevate privileges to kernel mode by exploiting vulnerabilities within signed, legitimate drivers.
avatar
0x 1337@0x1337
avatar
Detections.ai Community
2 months ago
1013
Detects the backdoor's put-command file-drop evasion: RtkNGUI64.exe creates tempcache.tmp then renames it to the target path before patching the corrupted MZ header bytes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3010
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
This rule detects attempts to perform process injection techniques (such as creating remote threads or opening processes) targeting the 'ctfmon.exe' process, where the initiating process is not 'ctfmon.exe' itself. This behavior is indicative of potential malicious activity such as reflective code loading or the execution of malware like SparkRAT, which may use this legitimate Windows process to mask its activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
This rule detects attempts to perform process injection techniques (such as creating remote threads or opening processes) targeting the 'ctfmon.exe' process, where the initiating process is not 'ctfmon.exe' itself. This behavior is indicative of potential malicious activity such as reflective code loading or the execution of malware like SparkRAT, which may use this legitimate Windows process to mask its activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
Page 455 of 1866