Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects execution of mshta.exe when initiated by common office or web browser applications, or when command arguments include external network references (URLs/UNC paths) or script protocols (vbscript/javascript), which are common patterns for LOLBAS-based initial access or exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
215
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
302
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects the 'ClickFix' social engineering pattern where a user is instructed to copy and paste a malicious command into the Windows Run dialog. The rule triggers on PowerShell being launched from explorer.exe with 'ExecutionPolicy Bypass', utilizing 'irm' (Invoke-RestMethod) to download content, and saving it to the user's TEMP directory via 'Out-File' for subsequent execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects the execution of known, signed legitimate binaries (COTFileReadApp.exe or DeElevate64.exe) from user-writable directories, such as %LOCALAPPDATA%\Programs\. This behavior is a common indicator of DLL sideloading, where adversaries utilize a trusted, signed application to execute malicious code by placing a malicious DLL in the same directory as the executable.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects unauthorized data staging activities using archival utilities followed by data exfiltration to known public cloud storage providers. The rule specifically excludes hosts experiencing mass file renaming activity, focusing on extortion-only scenarios where data is stolen without encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects the execution of rundll32.exe or regsvr32.exe where the command line arguments reference a DLL that was recently written to the disk on the same host. This behavior is indicative of a RAT or malware dropping a secondary payload (DLL) and immediately executing it using built-in Windows binary proxies to bypass security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects potential post-exploitation activity where a web server process spawns a command shell, executes system discovery commands, and immediately initiates an outbound network connection. This behavior is indicative of a web-based exploit leading to interactive command execution and subsequent C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
502
Detects potential browser-based infostealer activity where a non-standard process, launched from temporary or user-download directories, accesses sensitive browser data files (cookies, login data) followed by a suspicious outbound network connection to a previously unseen domain, matching common patterns for LummaStealer or Vidar malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects sophisticated in-memory loader activity characterized by a sequence of events: process module loads involving AMSI patching (amsi.dll), fresh ntdll.dll remapping to bypass EDR hooks, and the enumeration of hypervisor-related drivers or services, often associated with advanced payload execution chains like ClickFix.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects potential process injection or process hollowing attempts by correlating Sysmon Event ID 10 (ProcessAccess) events indicating process memory modification permissions (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) with subsequent Sysmon Event ID 8 (CreateRemoteThread) events targeting the same process. This behavior is indicative of an adversary injecting malicious code into a legitimate host process (e.g., svchost.exe, explorer.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects modifications to Windows Registry auto-start keys (Run, RunOnce, Winlogon, or Services) by suspicious processes (e.g., script interpreters, shell, or office applications) or processes running from temporary directories, where the registry value points to paths commonly used by adversaries (AppData, Temp, or ProgramData).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
102
Detects the execution of PowerShell commands that reflectively load .NET assemblies into memory, followed immediately by a process injection event targeting Chromium-based browsers (e.g., chrome.exe) or Firefox. This behavior is highly characteristic of credential harvesting tools like BoundSiphon, which injects code into browser processes to decrypt and extract App-Bound encryption keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
001
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects potential 'ClickFix' activity where a browser or file explorer process initiates a shell (e.g., cmd, powershell, osascript) with command arguments indicative of remote script execution, obfuscated commands, or web-based payload downloading. This pattern matches known social engineering tactics that entice users to copy-paste malicious code into a system shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
1102
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects the execution of 'tscon.exe', a Windows utility used to control Remote Desktop sessions. The rule specifically alerts when 'tscon.exe' is executed with parameters indicative of session hijacking (such as '/dest:') or when it is invoked by suspicious processes or under SYSTEM privileges, which are characteristic of RDP session hijacking techniques used for privilege escalation and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects obfuscated PowerShell command lines indicative of malicious file downloading and execution. The detection logic searches for specific indicators such as 'scriptblock', '::create', and numeric obfuscation patterns paired with common .NET web client methods ('net.webclient', 'downloadfile', 'downloadstring') used for staged payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
101
Page 52 of 1866