Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects known AgtaBackup RAT staged installers and dropped payload via SHA-256 hash or characteristic filenames
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects the creation of files with specific naming patterns (starting with 'agta_av_' for PowerShell scripts or 'agta_task_' for XML files) within the Windows SystemTemp directory. This behavior is indicative of potential staging of malicious scripts or scheduled task definitions by adversaries.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects the AgtaBackup RAT keylogger process, which masks itself as a legitimate Windows service ('Window Security Health Services.exe'), running with SYSTEM privileges and lacking a valid digital signature.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
This rule monitors for suspicious persistence mechanisms associated with 'Agta Backup' software, specifically looking for the creation of new Windows services, the addition of scheduled tasks, and the manipulation of processes related to 'Credential Guard.exe' within Agta Backup directories. It also tracks the presence of specific file artifacts within the application's install directories, which could indicate unauthorized installation or persistence attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects the modification of service permissions for the 'AgtaBackupAgentSvc' service using the 'sdset' command via 'sc.exe', 'cmd.exe', or 'powershell.exe'. Adversaries use this technique to hide services or modify access to them by applying a specific Service Descriptor Definition Language (SDDL) string to bypass security enumeration or maintain persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects the 'Credential Guard.exe' process (associated with AgtaBackup RAT) accessing sensitive browser files (Login Data, Cookies, History, Bookmarks) and subsequently exfiltrating data to a specific C2 endpoint.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
201
Detects modifications to the Windows registry key 'PromptOnSecureDesktop' to set it to '0' (disabled). This configuration change effectively disables the secure desktop for User Account Control (UAC) prompts, which is a technique used by adversaries to facilitate UAC bypasses or simplify credential harvesting by making UAC prompts more easily spoofable or interceptable.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
Detects the execution of conhost.exe with the --headless flag, which is commonly observed in Kimsuky LNK-based malware campaigns to execute encoded cmd.exe payloads. This pattern involves the use of certutil or echo commands to deobfuscate and execute embedded scripts, often leveraging hidden windows or process hollowing techniques for persistence and evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
009
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
403
Detects attempts to exploit a vulnerability (CVE-2026-68536) in the Apache MyFaces JSF resource handler. The rule monitors for malicious URI parameters ('ln' or 'library') that attempt Server-Side Request Forgery (SSRF) targeting cloud metadata services, path traversal, or URI-based injection attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
002
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
002
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
002
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
002
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
002
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
002
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
002
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
Detects the execution of VBScript files that use a double extension (.pdf.vbs) via Windows Script Host (wscript.exe or cscript.exe). This technique is commonly used to masquerade malicious scripts as benign PDF documents to deceive users into executing them.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
16 days ago
007
Page 56 of 1870