Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

This rule detects potentially malicious memory manipulation and thread execution activity originating from the ERAAgent.exe process. It specifically identifies when ERAAgent.exe calls VirtualProtect or VirtualAlloc to set memory as PAGE_EXECUTE_READWRITE, followed shortly by a CreateThread or CreateRemoteThread operation. This behavior is indicative of process injection or reflective code loading, where an executable image is manually mapped into memory and executed, bypassing traditional file-based detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the ESET Remote Administrator (ERAAgent.exe) process loading the 'dpapisvc.dll' module. This behavior is indicative of potential DLL side-loading where an attacker places a malicious DLL with the same name as a legitimate system library in the agent's directory to achieve code execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects the use of raw sockets by 'ERAAgent.exe' by monitoring for socket I/O control (Ioctl) operations involving 'SIO_RCVALL'. This configuration, often associated with promiscuous mode, allows an application to capture all network traffic received by the network interface, a behavior commonly used by network sniffing tools or malicious implants to intercept sensitive data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects periodic execution cycles of ERAAgent.exe that involve memory protection changes, characteristic of the SLEEPWALKER malware's XOR-decrypt-execute-reencrypt loop scheduled by a cron-like mechanism.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects ERAAgent.exe performing suspicious dynamic API resolution for functions commonly used by the SLEEPWALKER malware (VirtualProtect, SetSecurityDescriptorDacl, and CryptGenRandom). By resolving these functions at runtime via GetProcAddress rather than including them in the static import table, the malware attempts to evade detection and analysis.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects potentially malicious memory manipulation and thread execution activity originating from the ERAAgent.exe process. It specifically identifies when ERAAgent.exe calls VirtualProtect or VirtualAlloc to set memory as PAGE_EXECUTE_READWRITE, followed shortly by a CreateThread or CreateRemoteThread operation. This behavior is indicative of process injection or reflective code loading, where an executable image is manually mapped into memory and executed, bypassing traditional file-based detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the ESET Remote Administrator (ERAAgent.exe) process loading the 'dpapisvc.dll' module. This behavior is indicative of potential DLL side-loading where an attacker places a malicious DLL with the same name as a legitimate system library in the agent's directory to achieve code execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
This rule detects the use of raw sockets by 'ERAAgent.exe' by monitoring for socket I/O control (Ioctl) operations involving 'SIO_RCVALL'. This configuration, often associated with promiscuous mode, allows an application to capture all network traffic received by the network interface, a behavior commonly used by network sniffing tools or malicious implants to intercept sensitive data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
000
Detects the malicious 'PDF Viewer' extension (bridged via the com.microsoft.runedge native-messaging helper) requesting both cookie-access and clipboard-access permissions together — the specific combination Jewelbug uses for session-token theft and cryptocurrency address swapping.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5017
Detects the image load of VSS DLL by uncommon executables
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
000
Detects the image load of VSS DLL by uncommon executables
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
000
Detects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
000
Detects a concentrated sweep of multiple browser credential/cookie artifacts (Local State, Login Data, Cookies, History) by a single non-browser process (OptiDrive.exe) within a one-minute window — the ACRStealer credential-theft stage.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
This rule detects the execution of 'vlc.exe' or loading of 'libvlc.dll' from common staging or user-writable directories such as Temp, Downloads, or Desktop. This pattern is commonly associated with adversary efforts to execute masquerading or portable malicious payloads, as legitimate VLC installations are typically located in Program Files.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
001
Detects APC injection into dllhost.exe unbacked/private memory via NtQueueApcThread correlated with a subsequent outbound network connection from the same process — the ACRStealer injection-and-C2 pattern.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects the execution of JavaScript files using WScript or CScript that contain obfuscated 'eval()' calls, such as string concatenation (e.g., (0,this)["ev"+"al"]) or Unicode escaping. Adversaries often use these techniques to bypass signature-based detection for malicious script execution.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
001
Page 459 of 1866