Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

This rule detects attempts to perform process injection techniques (such as creating remote threads or opening processes) targeting the 'ctfmon.exe' process, where the initiating process is not 'ctfmon.exe' itself. This behavior is indicative of potential malicious activity such as reflective code loading or the execution of malware like SparkRAT, which may use this legitimate Windows process to mask its activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
This rule detects the creation of a Windows scheduled task named 'TaskHandler' using the schtasks.exe utility. The task is configured to execute a specific file, 'F7u00ex.exe', on system startup under the 'NT AUTHORITY\SYSTEM' account. This behavior is indicative of a persistence mechanism, often associated with the Spark RAT malware, which attempts to maintain a foothold on the system with high-level privileges.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
This rule detects the use of the Windows Service Control Manager (sc.exe) to create or configure a service named 'TaskHandler'. The rule specifically looks for command lines that reference potentially malicious files like 'F7u00ex.exe' or specific driver/restart patterns often associated with the persistence mechanism of the Spark RAT.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
Detects the process 'Acrobatlog.exe' loading the library 'scansts.dll'. This behavior is potentially indicative of DLL injection or side-loading techniques aimed at executing malicious code within the context of a legitimate or masquerading process.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
001
This rule detects the use of the Windows Service Control Manager (sc.exe) to create or configure a service named 'TaskHandler'. The rule specifically looks for command lines that reference potentially malicious files like 'F7u00ex.exe' or specific driver/restart patterns often associated with the persistence mechanism of the Spark RAT.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
1 month ago
000
Detects the execution of the Cortex XDR agent administration tool (Cytool) with the 'protect disable' command line argument. This indicates an attempt to manually disable the security agent's protective features on an endpoint, which is a common technique used by adversaries to impair security controls.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
3010
This rule detects multiple occurrences of suspicious Common Log File System (CLFS) error strings within command-line arguments of processes executed on the same device within a 5-minute window. These specific error messages are often indicative of attempts to interact with or exploit vulnerabilities within the Windows CLFS driver.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
001
This rule detects the presence of the file 'eicar_com.zip', which is used in ShieldBreak Proof-of-Concept repositories to validate the bypass or evasion of Windows Defender.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
001
Detects the execution of a process named 'Windowsupdate.exe' from within the user's Local AppData directory. This pattern is indicative of masquerading, where malware attempts to evade detection by mimicking the legitimate Windows Update executable, a technique observed in the Operation QUICSILVER campaign.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
6010
Detects repeated network requests to specific JSON files hosted on GitHub (e.g., beacon.json) initiated by processes other than standard web browsers or git. This behavior is indicative of a C2 heartbeat mechanism where an agent periodically retrieves configuration or tasking files from a public repository.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
006
Detects the C2Looper secondary payload dropped as pld.exe under %LocalAppData%, typically staged as a ransomware precursor after backdoor check-in.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
1007
Detects C2Looper's remote interactive shell and ShellExecuteW run-and-self-delete command execution, correlated with the c2_out.txt output-capture artifact.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
This rule detects the installation of malicious VS Code extensions by monitoring file system writes within common VS Code and VS Code Server extension directories. It specifically alerts on a predefined list of extension namespaces associated with a known malicious coordinated campaign that impersonated legitimate publishers.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
4010
Detects the spawning of cmd.exe by processes associated with Microsoft Exchange Server, specifically MSExchangeMailboxReplication.exe or w3wp.exe. This activity is indicative of post-exploitation command execution following an exploit of an Exchange web service or MRSProxy endpoint.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
5010
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces)
using either the WinNT or LDAP provider. This is an uncommon method to create user accounts
and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
2 months ago
007
Aggregates identity, endpoint, cloud application, and messaging telemetry to build a consolidated profile of the devices, clients, applications, and user agents associated with a specific user account.

The query combines Microsoft Entra sign-in data, endpoint logon activity, cloud application events, and email telemetry to provide a high-level overview of a user's activity footprint across the environment.

This query is useful for incident response, account compromise investigations, insider threat investigations, and validating whether a user is accessing services from expected devices and client applications.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
105
Detects BeaverTail malware deployed via PurpleDelta/PurpleBravo coordination; requires multiple occurrences of the distinctive BeaverTail string to reduce false positives
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
007
Detects the execution of various command-line tools (sc, net, powershell, wmic, taskkill, systemctl, launchctl) used to stop or disable system services. This behavior is often associated with adversaries attempting to stop security services, backup agents, or other critical infrastructure for impact, defense evasion, or prior to data destruction.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
2 months ago
104
Detects network activity (DNS queries and TLS connections) to the known command-and-control (C2) domain 'vm180012.hosted-by.qwins.co' associated with the PureLogs Stealer malware.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects the BYOVD kill chain for the DCRCVDrv.sys driver: drop to C:\Windows\Temp\, DCRCVDRV_U/LEGACY_DCRCVDRV_U service installation, device open, and IOCTL 0x2205c0 invocation used to terminate security/EDR processes from kernel context.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
909
Detects Amatera Stealer shellcode anti-emulation patching stub using cff_state control-flow flattening and inplace_xor_decrypt reflective loader routine
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
104
Page 456 of 1866