Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the DOUBLECUP/ClickFix loader activity which involves a sequence of suspicious command-line execution patterns. The rule correlates three specific behaviors occurring within a 5-minute window: finding PowerShell paths using 'where', searching for the 'ZZ1984' marker using 'findstr', and executing a minimized background command process. This combination is highly indicative of the ClickFix delivery chain used to trick users into running malicious commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
8019
Detects the Abyssos UAC_BYPASS_FODHELPER technique: a ms-settings\Shell\Open\command registry value set immediately before fodhelper.exe launches an unsigned child payload, silently elevating to a high-integrity process without a UAC prompt.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a WinRAR-extracted OnyxC2 loader spawning an identical self-copy child process from a temp/download path, marking the transition from loader stage to active stealer logic.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
302
Detects creation of the ONYXC2 mutex used by the malware to enforce single-instance execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects extraction and execution of OnyxC2 lure archives (Setup_File*.zip, Fling-Standalone*.zip) via WinRAR/7-Zip from a Downloads/Temp directory, correlating the archive-open with the lure-named installer executing shortly after.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Matches endpoint file/process hashes and network IPs against a curated, freshness-checked OnyxC2 indicator feed.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
302
Detects creation of a non-default hidden desktop by a browser process, correlated with either an inherited long-lived authenticated browser network session or a non-standard parent process, consistent with OnyxC2's HVNC capability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects a multi-hop HTTP redirect chain traversing two or more known OnyxC2 phishing lure domains from the same host within a two-minute window, consistent with the redirect obfuscation used before final payload delivery.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
This rule detects DNS configuration changes (via 'netsh' commands or registry modifications to the 'NameServer' value) initiated by specific system processes ('SwiService.exe' or 'svchost.exe') shortly after a Plug-and-Play (PnP) event, such as a USB drive connection. This pattern is indicative of potential malicious activity attempting to redirect DNS queries upon the insertion of unauthorized hardware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
208
This rule detects potential privilege escalation through the abuse of a debug backdoor in the Wacom WTabletServiceISD service. It identifies when the 'PowerT' registry value is set for the service, followed shortly by the service spawning a command shell (cmd.exe or powershell.exe) under SYSTEM privileges. It specifically excludes scenarios where AutoAdminLogon is enabled, which might otherwise trigger false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
008
This one's the interesting bit they're using Ethereum RPC calls as a C2channel and dumping stolen secrets to attacker-owned public repos tagged "Shai-Hulud: Here We Go Again". Also flags Claude/VS Code config file writes dropped by the worm for lateral persistence across dev machines.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
7018
Detects the use of native Windows utilities such as vssadmin, wbadmin, wmic, diskshadow, and bcdedit to delete volume shadow copies, backup catalogs, or modify boot configuration to prevent system recovery. The rule explicitly excludes designated backup servers to reduce noise from legitimate management activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
206
This rule detects the creation or modification of files within the Google Chrome browser extensions directory by processes other than legitimate Chrome-related binaries (chrome.exe, GoogleUpdate.exe). This activity is highly indicative of malicious browser extension sideloading or persistence, where an adversary attempts to install a rogue extension to achieve goals such as credential theft, session hijacking, or command-and-control communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
606
This rule detects potentially unauthorized access or memory dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. It monitors for events where processes interact with LSASS or execute commands containing 'lsass.exe', 'MiniDump', or 'comsvcs.dll', while excluding known administrative and benign processes like Task Manager, Procdump, and Windows Error Reporting.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
906
Detects python.exe executing from unusual locations (AppData, Temp, or ProgramData directories) that subsequently establish outbound network connections, consistent with DeviceManager RAT behavior delivered via the DOUBLECUP loader.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3017
Detect DNS tunnelling via long subdomain labels. The query is useful for identifying DNS queries with unusually long request strings (typically 40+ characters per label) and high volumes of repetitive requests used by attackers to exfiltrate data or run command-and-control (C2) channels.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
15035
This rule detects instances where a process that is not a recognized web browser attempts to access sensitive files associated with browser credential stores, such as Login Data, Cookies, and web browser state files. Such activity is commonly associated with infostealer malware, which attempts to exfiltrate saved passwords, session cookies, and autofill information.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
2 months ago
16032
Detects execution of a 'setup.mjs' preinstall lifecycle hook, the stage-1 loader used in the
4 August 2026 compromise of the keyv and cacheable npm namespaces. The trojanised package.json
adds "preinstall": "node setup.mjs" while leaving dist/ byte-identical to the last clean
release, so the only execution-time signal is the hook itself. The loader downloads a
standalone Bun runtime and executes an obfuscated second stage (Math_Symbol.js).
avatar
Lourenço Santos@lourenco
avatar
Detections.ai Community
2 months ago
9032
Detects unusually high-volume recursive file/directory enumeration (dir /s, tree, Get-ChildItem -Recurse) spanning multiple distinct user-profile directories or department shares in a short window, excluding known AV/EDR scanning engines and backup-agent processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects C2Looper v2 retrieving GitHub-hosted C2 tasking files (cmd.json, result.json, beacon.json) via raw.githubusercontent.com or api.github.com, requiring repeated requests to reduce false positives from incidental single fetches.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000
This detection identifies instances where a Microsoft Office application (Word, Excel, PowerPoint, or Outlook) spawns a child process commonly associated with script execution or living-off-the-land binary (LOLBin) abuse — including wscript.exe, cscript.exe, mshta.exe, powershell.exe, cmd.exe, regsvr32.exe, rundll32.exe, certutil.exe, and bitsadmin.exe.

This behavior is a well-known indicator of malicious macro or embedded-object execution following a phishing lure: a victim opens a weaponized document, and a macro (or OLE/DDE object) launches a script interpreter or LOLBin to download, decode, or execute a second-stage payload. Office applications rarely need to spawn these processes during legitimate use, making this a high-fidelity pivot point for detecting initial access and user-execution activity.

Rationale
Office applications spawning script hosts or command interpreters is atypical for normal document/spreadsheet/presentation workflows.
Threat actors frequently abuse Office macros (VBA), DDE, or OLE objects as an initial access vector, then use LOLBins to evade detection and blend in with legitimate system activity.
Tools like mshta.exe, certutil.exe, and bitsadmin.exe are commonly abused for downloading and executing remote payloads while evading traditional AV/EDR signatures.

MITRE ATT&CK Mapping
Technique Tactic
T1566 (Phishing) Initial Access
T1204 (User Execution) / T1204.002 (Malicious File) Execution
T1059 (Command and Scripting Interpreter) Execution
T1218 (System Binary Proxy Execution) — e.g. T1218.005 Mshta, T1218.010 Regsvr32, T1218.011 Rundll32 Defense Evasion
T1197 (BITS Jobs) Defense Evasion, Persistence
T1140 (Deobfuscate/Decode Files or Information) — via certutil Defense Evasion
Data Source
Microsoft Defender for Endpoint — DeviceProcessEvents

Logic Summary
Flags process creation events over the last 30 days where:

The initiating (parent) process is winword.exe, excel.exe, powerpnt.exe, or outlook.exe, and
The spawned (child) process i
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
11033
Page 476 of 1866