Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the full process-hollowing sequence (suspended process creation, SetThreadContext, ResumeThread) executed against the same target PID for wab.exe or MSBuild.exe within a short window — the ACRStealer campaign's injection technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
208
Detects a non-browser process reading browser session-cookie databases or 2FA/authenticator extension local storage across 200+ targeted apps, consistent with OnyxC2's MFA-bypass and account-takeover capability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
8019
Detects DNS resolution, network connections, or email-embedded URLs matching known JWR phishing framework hosting domains and IP addresses, including banking/government/logistics brand-impersonation lookalikes and smishing-delivered typosquats.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3010
The following analytic detects the creation of a Python site hook file (`sitecustomize.py` or `usercustomize.py`) within a `site-packages`/`dist-packages` directory in conjunction with a package installation process.
Python's `site` module loads these hooks from directories on `sys.path` before Python is executed.
If an adversary manipulates or plants one of these files, they can hijack the Python environment and execute their payload with every Python invocation, achieving persistence on the victim endpoint.
The VIPERTUNNEL backdoor was reported to abuse site hooks in order to import and trigger DLL execution.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
003
This rule detects the creation or modification of suspicious files (extensions associated with web shells or modules, such as .aspx, .ashx, .asmx, .dll, or .config) within common Microsoft IIS and Exchange web directories. It correlates these file events with process activity initiated by common web server or management processes (e.g., w3wp.exe, powershell.exe) and filters out trusted files (Microsoft-signed), known administrative update activity, and files with a broader footprint in the environment to identify potentially malicious, low-prevalence artifacts.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
007
Detects persistence established via a Run registry key named 'Rapid' or 'TIEmounter' pointing to C:\ProgramData\Rapid\creator-ws.exe, correlated with the corresponding process launch, matching ACRStealer's second-stage payload persistence mechanism.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
308
The following analytic detects the use of net.exe or net1.exe to configure the Windows maximum password age policy as unlimited.
It leverages process creation telemetry from Endpoint Detection and Response (EDR) agents and identifies executions of the `net accounts` command using the `/maxpwage:unlimited` option.
When specified, Windows configures the maximum password age with an unlimited value, effectively preventing passwords governed by the affected password policy from expiring.
This behavior is significant because an adversary may modify password expiration settings to weaken credential security controls and maintain access to compromised accounts for an extended period.
If confirmed malicious, this activity may indicate an attempt to establish or maintain persistence by preventing expected password rotation from invalidating credentials under the affected password policy.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
001
Detects the temporary enablement of the UseLogonCredential registry value by setting it to 1, followed by a subsequent reversion to 0 on the same host. This pattern is indicative of a deliberate 'hit-and-run' attempt to force the WDigest security package to store plaintext credentials in memory for harvesting.
avatar
Renata Cardoso@rcardososec
avatar
Detections.ai Community
2 months ago
101
This rule monitors for suspicious activity involving the OneDrive directory, specifically the file 'wtsapi32.dll'. It triggers when this DLL file is created, modified, or renamed within the OneDrive folder, followed by the termination of the OneDrive process, and subsequent loading of the same DLL file by that process. This pattern is indicative of a DLL side-loading attack where a legitimate application (OneDrive) is used to load a malicious DLL.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
305
Detects the execution of commands 'ls' or 'drives' via command line, which are often used by threat actors for reconnaissance and file/directory enumeration on a compromised host.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
105
Detects the presence of the BRIDGEHEAD malware based on its unique Rust-compiled implementation of ChaCha20, specifically identifying a non-standard initialization string and a known hash associated with a decrypted in-memory payload.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
000
Detects the download or presence of the BRIDGEHEAD malware payload (main.exe), specifically the version hosted on GitHub release infrastructure associated with the BRIDGEHEAD npm typosquatting campaign.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
000
This rule detects the creation or modification of the 'goopdate' registry value under the HKCU\Software\Microsoft\Windows\CurrentVersion\Run path. This technique is used to achieve persistence by executing specified files (e.g., Sang.exe or defender.exe with the 'work' parameter) upon user logon.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
308
Detects the execution of common command-line utilities frequently used by adversaries for system, network, and account discovery after gaining initial access to a host.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
2 months ago
4010
This rule detects malicious activity associated with the RtkNGUI64.exe backdoor, which masquerades as a legitimate Realtek Audio process. It identifies when this process spawns cmd.exe for command execution or interacts with 'tempcache.tmp' files, indicating potential C2 tasking and persistence via WMI event consumers.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
408
Detects the StopAndProtect two-stage PowerShell chain: stage 1 downloads/executes stage 2, which reflectively loads a base64-encoded .NET assembly and invokes an Execute method.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
206
Detects the invocation of the Windows Error Reporting service (WerFault.exe) where the command line arguments reference Zoom-related processes (Zoom.exe, CptHost.exe, or zoom.us). This behavior is often indicative of an abnormal application crash, which may be associated with memory corruption exploitation attempts against the Zoom client.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
4018
Detects instances where a user account requests or enrolls a certificate from Active Directory Certificate Services (AD CS) that is associated with a computer account (SID). This behavior, specifically when the requester is not the computer account itself, is a known indicator of potential AD CS abuse, such as certificate theft or impersonation techniques.
avatar
Subash Ghimire@iamsubashg
avatar
Detections.ai Community
2 months ago
12130
Detects a suspicious pattern associated with the SLEEPWALKER technique, involving multiple memory write operations followed by a memory protection change within an ERAAgent.exe process. This behavior suggests code injection or dynamic code loading within a process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Page 458 of 1866