Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution of PowerShell or PowerShell Core (pwsh) triggered by common Windows shell applications (explorer, mshta, wscript, cscript) where the command line contains indicators associated with the downloading of VelvetCake stager files, including specific GitHub raw content URLs or AppData paths referencing known stager filenames.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
006
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
002
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
002
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
002
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
002
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
002
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
002
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
002
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
002
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
002
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
002
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
002
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
002
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
002
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
002
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
002
This rule monitors for network communication with known malicious infrastructure (IPs/domains) and the execution of specific suspicious file names. It correlates device network events, file system activity, and process execution, specifically flagging attempts to execute MSI installers or other binaries associated with the identified threat indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
Page 62 of 1870