Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects the suspicious retrieval and immediate execution of Agentic AI configuration files (e.g., AGENTS.md, KNOWLEDGE.md) from remote sources using common command-line utilities. This pattern is indicative of an adversary injecting malicious agent instructions or unauthorized configurations into an AI environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
604
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
001
This rule detects potential phishing or HTML smuggling attempts by identifying a burst of anomalously large SVG file attachments delivered via email to multiple recipients, followed by a correlation with web browser process network activity from the same recipients shortly after the email delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the use of PowerShell or Windows Script Host to access files within common web browser cache directories combined with indicators of Base64 decoding and pixel data manipulation. This behavior is indicative of extracting malicious payloads hidden via steganography within browser-cached image files, a technique often used in phishing campaigns to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the presence of package.json or node_modules artifacts associated with a known typosquatting campaign targeting the 'sorted-btree' npm package. The rule identifies suspicious package names or dependencies by matching against a list of known malicious packages used in the campaign, or by detecting the co-occurrence of the malicious 'indexed-btree' package alongside the legitimate 'sorted-btree' package.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
1010
Detects the execution of command-line interpreters (cmd, powershell, mshta, etc.) directly spawned by explorer.exe. This activity is indicative of the 'ClickFix' or 'ConsentFix' attack chain, where a victim is coerced into pasting malicious commands into the Windows Run dialog (Win+R) after interacting with a fraudulent CAPTCHA or verification page in their browser. The rule filters out standard installer-related activity to reduce false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects instances where PowerShell or pwsh processes are initiated directly by explorer.exe containing command-line arguments indicative of obfuscated or hidden execution, often used in ClickFix-style social engineering attacks where victims are coerced into pasting malicious commands into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects registry value modifications to the Windows Explorer RunMRU key where the data contains indicators of obfuscated PowerShell commands. This pattern is commonly associated with the 'ClickFix' social-engineering campaign, where users are prompted to copy and paste a malicious PowerShell command into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects the abuse of Windows protocol handlers ('search-ms:') and WebDAV UNC paths ('@SSL\DavWWWRoot') launched from common web browsers or Windows shell processes. This technique, frequently observed in 'ClickFix' phishing campaigns, enables attackers to stage remote payloads like LNK, HTA, or scripts by leveraging native Windows functionality to resolve remote content as if it were a local resource, bypassing typical file download security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects instances where a suspected malicious loader initiates process hollowing or APC injection by launching trusted Windows binaries (e.g., LockAppHost.exe, makecab.exe, Magnify.exe) in a suspended state. The rule identifies suspicious post-injection behavior such as unexpected network connections or child process creation originating from these typically benign binaries, which is characteristic of the DeepLoad/ClickFix attack chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects the execution of 'sqlcmd.exe' when spawned by web application pools (w3wp.exe) or general command shell (cmd.exe) processes that do not appear to be related to authorized database administration or IIS appcmd activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the use of 'findstr' or PowerShell to query sensitive configuration files (such as web.config or applicationHost.config) for credential-related keywords like 'connectionString', 'AccountKey', or 'machineKey'. This behavior is indicative of an adversary attempting to harvest credentials or sensitive configuration data stored in cleartext on the filesystem.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the Microsoft IIS worker process (w3wp.exe) spawning common command-line shells (cmd.exe or powershell.exe) and executing discovery-related commands. This is highly indicative of potential web shell activity where an adversary uses an existing web application vulnerability to gain remote code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the presence of known SHA256 hashes associated with the 'ccrtc' planter PowerShell scripts and C2 SDK JavaScript components. These files were identified as being dropped into 'C:\Windows\Temp' during the STAC4924 webshell intrusion campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the creation of an ASPX file within a member file upload directory, followed immediately by the execution of 'cmd.exe' by the 'w3wp.exe' web server process. This behavior is indicative of a web shell being uploaded and used to execute arbitrary commands on the server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects reconnaissance activity on IIS servers where the worker process (w3wp.exe) spawns appcmd.exe or PowerShell to list websites, virtual directories, or application pools. This pattern is indicative of an attacker performing post-exploitation discovery after establishing a web shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where a Microsoft IIS worker process (w3wp.exe) executes commands such as 'findstr', 'Get-Content', or 'Select-Xml' to scan configuration files (e.g., applicationHost.config, web.config) or source code files (e.g., App_Code/*.cs) for sensitive information like passwords, connection strings, or API keys. This behavior is indicative of credential harvesting by an attacker using a webshell or compromised IIS process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates a child process of sqlcmd.exe. This behavior is highly suspicious and often indicates a post-exploitation activity where an attacker, having established a webshell or similar foothold on a web server, is using harvested credentials to query backend SQL databases directly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates a child process of sqlcmd.exe. This behavior is highly suspicious and often indicates a post-exploitation activity where an attacker, having established a webshell or similar foothold on a web server, is using harvested credentials to query backend SQL databases directly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where an IIS worker process (w3wp.exe) spawns a command shell (cmd.exe) that executes a conditional file copy operation. This pattern is characteristic of an adversary creating a webshell by copying a payload to a filename that masquerades as a legitimate web application asset, such as a CSS bundle or validation script.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Page 58 of 1866