Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the fake, undersized RtkNGUI64.exe exiting without reading C:\ProgramData\desktop.ini. Scoped by file size to the known 12,288-byte backdoor binary -- the legitimate, much larger signed Realtek Audio Console also never reads that file, so without this filter every normal launch of the real app would match.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
305
Detects RtkNGUI64.exe creating a mutex named as an 8-character hex string, consistent with the backdoor's CRC-32(USERNAME+USERDOMAIN+COMPUTERNAME) per-victim beacon ID used for single-instance checking.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Requires the 'Realtek'-named WMI object AND (the 19:50 time-trigger query pattern OR the RtkNGUI64.exe destination) together, rather than matching on the name alone -- avoids flagging unrelated benign WMI objects that happen to share the name.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects HTTP POST tasking check-ins to /version/check.php using the backdoor's hardcoded, obsolete Chrome 78.0.3904.108 user-agent string.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Consolidated detection for RtkNGUI64.exe spawning cmd.exe to execute CMD= tasking (SYSTEM/PUT/TIME verbs). Merges two previously separate rules that detected the same underlying signal via different tasking-mechanism angles.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
This rule detects instances where the Windows Defender Antivirus service (MsMpEng.exe) spawns common command-line shells (cmd.exe, powershell.exe, conhost.exe) while running under the SYSTEM context. This behavior is highly irregular for a security product and is indicative of process injection, exploit payload execution, or anti-tampering bypass attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
13021
Detects instances where the Windows spooler driver (winspool.drv) is loaded by a process that subsequently performs suspicious memory operations typical of process injection (e.g., CreateRemoteThreadApiCall, WriteToProcessMemory, ProcessInjection) within a 5-minute window.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
103
Detects anomalous, frequent, or repetitive device crash events (including BSODs) on a single device, which may indicate system instability, hardware failure, or an attempt to induce a Denial of Service (DoS) condition on the endpoint.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
004
Detects devices exhibiting sustained high CPU or memory utilization (>= 90%) for a duration of at least 30 minutes, which may indicate resource exhaustion, performance degradation, or potentially malicious activity such as cryptocurrency mining, denial-of-service, or other unauthorized resource-intensive processes.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
004
Detects high-frequency state changes in authentication events for a single account within a short time window. This type of 'flapping' behavior, where an account repeatedly toggles between different authentication statuses (e.g., success and failure) on one or more hosts, can be an indicator of brute force attempts, credential stuffing, or misconfigured automated authentication services.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
004
This rule detects potential Bumblebee loader activity by identifying files named 'msimg32.dll' that possess specific known builder file versions and exhibit anomalous, dictionary-derived 'gibberish' entries within their PE version information metadata fields (Comments, CompanyName, or FileDescription).
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
004
Detects modifications to the 'userPrincipalName' attribute in Active Directory via Security Event ID 5136 where the assigned value lacks an '@' character. This behavior is indicative of the ResetNightmare exploitation technique (CVE-2026-27912), which involves setting the UPN to a bare sAMAccountName to facilitate unauthorized password resets or account takeover.
avatar
Georgios Maragos@Gmarak
avatar
Detections.ai Community
2 months ago
4011
Detects instances where the legitimate Windows consent.exe process loads the library 'msimg32.dll' from a non-standard system directory, specifically targeting suspicious paths such as user-writable AppData or application installation folders. This behavior is indicative of DLL side-loading, where an attacker places a malicious DLL with the same name as a legitimate library to achieve arbitrary code execution under the context of the trusted consent.exe process.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
104
Detects the use of the built-in Windows tool 'wbadmin.exe' to perform a system backup that specifically includes the Active Directory database (ntds.dit) along with SYSTEM and SECURITY registry hives. This technique is often used by adversaries to perform offline credential theft by creating an accessible copy of sensitive domain files.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
104
Detects the TWINLOOT Python implant's arbitrary shell command handler, in which pythonw.exe running from a non-standard directory (ProgramData, AppData, or Temp) spawns cmd.exe with a /c argument and CREATE_NO_WINDOW creation flags, consistent with the implant's default command handler executing operator-tasked commands with a hidden console window.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
102
Detects the loading of the 'calibre-launcher.dll' library by the 'ebook-edit.exe' process when accompanied by the creation of an 'edit2.hlp' file within a 10-minute window. This behavior pattern is indicative of potential side-loading or exploitation attempts where a legitimate process is coerced into interacting with a malicious or specifically placed helper file.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
000
This rule detects unauthorized or suspicious registration of native Internet Information Services (IIS) modules. It monitors command-line activity involving common administrative tools used to modify IIS configurations (appcmd.exe) and manage .NET assemblies (gacutil.exe), as well as the execution of specific PowerShell cmdlets like New-WebGlobalModule. Such activities are often indicative of an attacker attempting to establish persistence on a web server by loading malicious modules.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
104
Detects the creation of symbolic links involving the Common Log File System (CLFS) path or paths containing 'ShieldBreak', often associated with local privilege escalation exploits that leverage race conditions or symbolic link attacks to interact with kernel-mode components.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
000
Detects static file artifacts bundled with the publicly released ShieldBreak Microsoft Defender exploit kit
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5019
Detects the creation of new domain user accounts using the 'net user /add /domain' command. This activity can be indicative of an adversary establishing persistence or escalating privileges within a Windows domain environment.
avatar
Barsha Sketh@Barshasketh
avatar
Detections.ai Community
2 months ago
5014
This rule detects potentially malicious behavior where a process accesses environment variables containing 'TOKIO_WORKER_THREADS' (often associated with Rust applications or specific runtime environments) and simultaneously performs sensitive process operations like 'GetSystemInfo' or 'CreateThread'. This pattern may indicate an attempt by an adversary to perform discovery or process injection within a target application environment.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
002
Page 464 of 1866