Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
307
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
SlimKQL
17 days ago
6011
This rule detects file and process activity originating from or involving specific directories and filenames associated with 'Agta' software, including temporary files such as PowerShell scripts and XML tasks. This behavior is indicative of potential unauthorized use of backup or testing utilities for malicious purposes, such as script execution or task manipulation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
This rule identifies two distinct security threats on Windows systems: the execution or presence of files matching a known malicious SHA256 hash list, and modifications to the 'PromptOnSecureDesktop' registry key, which could indicate an attempt to weaken User Account Control (UAC) protections.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects modifications to the Windows registry key 'PromptOnSecureDesktop' to set it to '0' (disabled). This configuration change effectively disables the secure desktop for User Account Control (UAC) prompts, which is a technique used by adversaries to facilitate UAC bypasses or simplify credential harvesting by making UAC prompts more easily spoofable or interceptable.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
101
This rule monitors for processes masquerading as Dell-related software (e.g., 'Dell Window Guard.exe', 'Dell.Virus.Guard.exe') or processes containing the command-line argument 'AgtaBackstage'. It flags devices where multiple variations of these suspicious file names appear or where the specific 'AgtaBackstage' string is present, which is indicative of potential malicious activity or persistence mechanisms using software-related naming conventions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects known AgtaBackup RAT staged installers and dropped payload via SHA-256 hash or characteristic filenames
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects the creation of files with specific naming patterns (starting with 'agta_av_' for PowerShell scripts or 'agta_task_' for XML files) within the Windows SystemTemp directory. This behavior is indicative of potential staging of malicious scripts or scheduled task definitions by adversaries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects the AgtaBackup RAT keylogger process, which masks itself as a legitimate Windows service ('Window Security Health Services.exe'), running with SYSTEM privileges and lacking a valid digital signature.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
This rule monitors for suspicious persistence mechanisms associated with 'Agta Backup' software, specifically looking for the creation of new Windows services, the addition of scheduled tasks, and the manipulation of processes related to 'Credential Guard.exe' within Agta Backup directories. It also tracks the presence of specific file artifacts within the application's install directories, which could indicate unauthorized installation or persistence attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects the modification of service permissions for the 'AgtaBackupAgentSvc' service using the 'sdset' command via 'sc.exe', 'cmd.exe', or 'powershell.exe'. Adversaries use this technique to hide services or modify access to them by applying a specific Service Descriptor Definition Language (SDDL) string to bypass security enumeration or maintain persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects the 'Credential Guard.exe' process (associated with AgtaBackup RAT) accessing sensitive browser files (Login Data, Cookies, History, Bookmarks) and subsequently exfiltrating data to a specific C2 endpoint.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects modifications to the Windows registry key 'PromptOnSecureDesktop' to set it to '0' (disabled). This configuration change effectively disables the secure desktop for User Account Control (UAC) prompts, which is a technique used by adversaries to facilitate UAC bypasses or simplify credential harvesting by making UAC prompts more easily spoofable or interceptable.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects the execution of conhost.exe with the --headless flag, which is commonly observed in Kimsuky LNK-based malware campaigns to execute encoded cmd.exe payloads. This pattern involves the use of certutil or echo commands to deobfuscate and execute embedded scripts, often leveraging hidden windows or process hollowing techniques for persistence and evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
009
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
403
Detects attempts to exploit a vulnerability (CVE-2026-68536) in the Apache MyFaces JSF resource handler. The rule monitors for malicious URI parameters ('ln' or 'library') that attempt Server-Side Request Forgery (SSRF) targeting cloud metadata services, path traversal, or URI-based injection attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
002
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
002
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
002
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
002
Page 50 of 1866