Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule detects the presence of command line artifacts, filenames, and strings associated with the SilverFox malware. These strings indicate the execution of a malicious desktop monitoring component ('active_desktop_launcher.exe') or the use of specific IPC/configuration markers ('@@RAPID_CFG_START@@') characteristic of this threat's tradecraft.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
001
This rule detects executable files (ending in .exe) executing from a specific subdirectory within the user's AppData path (\AppData\Microsoft\Update\). This path is often used by adversaries to masquerade malicious activity or persistence mechanisms as legitimate update processes. The rule excludes common system service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise, focusing on processes initiated by user-level accounts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
101
Detects the specific pattern associated with Storm-2570 for enabling Remote Desktop Protocol (RDP) on a target host to facilitate lateral movement. The detection looks for registry modifications to disable RDP denial (fDenyTSConnections=0), firewall rules allowing TCP port 3389 via netsh or PowerShell, and the deployment of these configurations using PsExec against a target host list file.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
304
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
101
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
809
Detects the VelvetCake malware installation and operational pattern, which utilizes a scheduled task named 'OneDriveUpdateScheduler' to execute PowerShell scripts ('update1.ps1' or 'update2.ps1'). These scripts periodically retrieve modules or payloads from external infrastructure, specifically hardcoded C2 IPs or a dedicated GitHub repository.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
007
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
401
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
4012
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
101
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
101
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
101
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
201
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
101
Detects C:\Windows\System32\wsl.exe spawning a child wsl.exe process from outside the legitimate WSL install locations.
When WSL or bash is invoked, the System32 stub (wsl.exe) looks up the InstallLocation registry key and executes the wsl.exe found there.
An attacker who modifies InstallLocation to a controlled path causes the stub to transparently proxy execution to a malicious payload,
which then appears as a wsl.exe child of the legitimate System32 stub.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
6 days ago
000
Detects the use of reg.exe or PowerShell to modify the WSL InstallLocation registry key via command-line arguments.
Legitimate modifications to this key are performed exclusively by the Windows Installer (msiexec.exe) during WSL package installation or update.
Manual use of reg.exe or PowerShell to set this value strongly indicates an attempt to redirect WSL execution to a malicious binary.
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
6 days ago
000
Detects anomalous behavior where a node.exe process establishes an outbound network connection, characteristic of a C2 registration or ping loop, followed shortly by the spawning of an interactive command shell (cmd.exe or powershell.exe) by the same node.exe process. This pattern is indicative of a RAT (Remote Access Trojan) shell handler execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
209
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
14 days ago
505
Detects a sequence of activity indicative of destructive ransomware or wiper behavior on a Windows device. The rule correlates a high volume of file modification, creation, or rename events within a short timeframe with concurrent attempts to delete or modify Windows backup and recovery mechanisms (such as Volume Shadow Copies or Boot Configuration Data) using native administrative utilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
202
Detects suspicious post-compromise activity associated with ALPHV/BlackCat affiliates. This rule monitors for anomalous Kerberos ticket requests (e.g., weak encryption types or TGS requests) closely followed by access to sensitive credential stores or tools on the same host, which is indicative of credential harvesting after a session hijacking or initial access event.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
202
Detects coordinated activity characteristic of NotPetya-like lateral movement. It identifies a local account authenticating across multiple hosts (credential reuse), followed by the creation of a transient Windows service (typically for remote command execution) and the invocation of rundll32.exe to execute a DLL export by ordinal on the same device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
002
Page 49 of 1866