Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects malicious JavaScript injection attempts by msaRAT that leverage the Chrome DevTools Protocol (CDP) Runtime.evaluate method. The malware attempts to execute specific code snippets to facilitate flow-controlled data transfers over WebRTC DataChannels using Base64ToArrayBuffer conversions and a 24KB buffer threshold.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
103
Detects the NetworkShareScanner SMB/USB worm by known hash or by unsigned-executable propagation to remote shares/removable drives.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects wscript.exe executing OptiDrive.vbs from the %LOCALAPPDATA%\DriveOptimize Technologies\ masquerade directory to invoke the renamed AutoIt interpreter OptiDrive.exe — the ACRStealer staging/masquerade technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
206
Detects the creation of a scheduled task using the schtasks.exe utility designed to run with SYSTEM privileges upon system startup. This behavior is often associated with persistence mechanisms where an adversary attempts to maintain long-term access by ensuring malicious code executes automatically with high privileges whenever the system boots.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
2 months ago
5011
KQL Query
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
205
Detects non-interactive PowerShell invoked via the Sysnative path with -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -, reading attacker commands from standard input, spawned by a process that is not a known RMM/patch-management agent and is unsigned, low-integrity, or itself suspicious — matching ACRStealer's follow-on command execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects the unsigned/untrusted DLL tbbmalloc.dll being side-loaded by pgocvt.exe from C:\ProgramData\TIEmounter\, matching ACRStealer's second payload-set DLL side-loading technique.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
306
Detects installation/loading of the DCRCVDrv.sys BYOVD driver at the atypical staging path C:\Windows\Temp\DCRCVDrv.sys — including SCM service registration, \Device\DCRCVDRV_U device/symlink creation, and named kernel share-event objects — distinguishing attacker deployment from a legitimate DLP install.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects a user-session window titled 'Password Input' associated with PowerShell, PowerShell Core, or PowerShell ISE processes. This technique may be used for GUI-based credential capture or social engineering.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
206
Detects the creation of a new Group Policy Object (GPO) in Active Directory by monitoring Windows Security Event ID 5137 where the object class is 'groupPolicyContainer'. While typically an administrative task, the creation of new GPOs can be a precursor to malicious configuration changes or domain persistence via Group Policy modification.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
006
Detects five or more distinct Windows user-account deletion events (Event ID 4726) performed by the same actor on the same host within a one-hour time window, which may indicate unauthorized account access removal or malicious impact activity.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
406
Detects five or more distinct Windows user-account creation events (Event ID 4720) associated with the same actor and host within a one-hour time bucket, which may indicate unauthorized account creation for persistence or mass provisioning.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
806
Detects the use of net.exe or net1.exe to interact with administrator accounts, specifically looking for attempts to hardcode passwords in the command line or enabling/modifying domain accounts. This is a common pattern for local account persistence, privilege escalation, or lateral movement.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
105
Detects the execution or installation of the cloudflared utility via PowerShell, which is often used by adversaries to establish persistence or remote access tunnels (Cloudflare Tunnel). The rule triggers on process command lines involving 'cloudflared' and '1.ps1' keywords commonly associated with scripted deployment.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
205
Detects the creation of a local user account followed by the modification of the Winlogon SpecialAccounts\UserList registry key to hide the account from the Windows logon UI. This behavior is indicative of persistent access maintenance by adversaries, such as the Andariel threat group.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
5014
Detects anomalous child process creation by Zoom client executables (Zoom.exe, CptHost.exe, ZoomOpener.exe, zoom.us), specifically monitoring for command interpreters, script hosts, and browser processes, which may indicate exploitation of the Zoom client for code execution.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
10014
Detects creation of a zero-byte C:\ProgramData\desktop.ini by RtkNGUI64.exe, the crash artifact left behind when the implant's config has not been staged on a host.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects RtkNGUI64.exe creating or writing to tempcache.tmp during command-output staging, scoped to direct process attribution. The rename-away leg of this file's lifecycle is covered by the separate put-command drop-and-rename detection.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects command-history clearing and log-deletion events (history -c, PowerShell history wipe, Clear-EventLog, wevtutil cl) co-occurring with another suspicious indicator (credential access or lateral movement) on the same host within a 1-hour window, excluding scheduled group-policy retention jobs.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
13035
Detects RtkNGUI64.exe being launched via a WMI consumer using the 8.3 short-path form (Progra~1\Realtek\Audio), the same masquerading binary used for backdoor persistence.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects execution of command shell interpreters (cmd.exe, powershell.exe) associated with specific command-and-control opcodes indicative of the LxBaseRAT remote interactive shell subsystem.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
2 months ago
107
Page 461 of 1866