Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution or presence of AnyDesk.exe within directories containing 'UBP-Asset' that are outside of known, legitimate installation paths. This behavior often indicates an adversary attempting to use remote access software for persistent access or command and control, commonly disguised within unconventional directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
0013
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
001
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
001
Detects the execution of PowerShell with a bypass execution policy that performs a download or web request to save content to a file in the user's temp directory, followed by the immediate execution of that file. This pattern is characteristic of multi-stage malware droppers or fileless attack techniques attempting to stage and execute malicious scripts from temporary locations.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
101
Detects the WAV-based loader staging technique: a RIFF/WAVE file carrying a high-entropy appended blob, or a companion DLL chain (rdCore.dll/WMPCL.dll/WPFLocalizeExtension.dll) referencing the hidden audio payload and the encrypted monitor.raw container used to unpack the final RAT
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
001
Detects instances where rundll32.exe is used to invoke shell32.dll with the SHCreateLocal function, or where a web browser process (msedge.exe, chrome.exe, or firefox.exe) is spawned by rundll32.exe to open an HTML file. This pattern is often indicative of malicious activity such as HTML smuggling or local file execution attacks where rundll32 is used as a proxy to open files via the browser.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
006
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
001
Detects service-creation commands (sc create / New-Service / reg add under a Services key) whose COMMAND LINE itself references a known NeedyMantis binary name or sideload staging folder. Requiring the malicious reference to appear in the command being executed -- rather than merely in the calling process's own folder location -- removes false matches from unrelated legitimate software that happens to be installed under a similarly-named folder.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
001
Detects >=2 of the four NeedyMantis archive-extraction artifacts (encryptbase64.ps1, dnsapi.dll, ws2_32.dll, msvcrt140.dll) written by the same process within 60 seconds. Anchored to the known sideload staging directories (ProgramData/ProgramFiles subfolders used by the Poedit/curl/Vim/TightVNC/Office/Broadcom/Intel/NVIDIA-masquerading bundles) and excludes System32/SysWOW64, since ws2_32.dll and dnsapi.dll are legitimate system DLL names that would otherwise cause noise if matched by name alone anywhere on disk.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
001
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
101
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
406
Detects instances where a browser or agentic-browser process initiates a file download and subsequently executes that same file within a five-minute window, without the intervention of a user-driven process like explorer.exe. This pattern is indicative of automated 'agentic' browser activity, potentially signifying hijacked web instructions or malicious automated tool execution flows.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
204
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
101
Detects the suspicious retrieval and immediate execution of Agentic AI configuration files (e.g., AGENTS.md, KNOWLEDGE.md) from remote sources using common command-line utilities. This pattern is indicative of an adversary injecting malicious agent instructions or unauthorized configurations into an AI environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
604
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
001
This rule detects potential phishing or HTML smuggling attempts by identifying a burst of anomalously large SVG file attachments delivered via email to multiple recipients, followed by a correlation with web browser process network activity from the same recipients shortly after the email delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the use of PowerShell or Windows Script Host to access files within common web browser cache directories combined with indicators of Base64 decoding and pixel data manipulation. This behavior is indicative of extracting malicious payloads hidden via steganography within browser-cached image files, a technique often used in phishing campaigns to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the presence of package.json or node_modules artifacts associated with a known typosquatting campaign targeting the 'sorted-btree' npm package. The rule identifies suspicious package names or dependencies by matching against a list of known malicious packages used in the campaign, or by detecting the co-occurrence of the malicious 'indexed-btree' package alongside the legitimate 'sorted-btree' package.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
1010
Detects the execution of command-line interpreters (cmd, powershell, mshta, etc.) directly spawned by explorer.exe. This activity is indicative of the 'ClickFix' or 'ConsentFix' attack chain, where a victim is coerced into pasting malicious commands into the Windows Run dialog (Win+R) after interacting with a fraudulent CAPTCHA or verification page in their browser. The rule filters out standard installer-related activity to reduce false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects instances where PowerShell or pwsh processes are initiated directly by explorer.exe containing command-line arguments indicative of obfuscated or hidden execution, often used in ClickFix-style social engineering attacks where victims are coerced into pasting malicious commands into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Page 63 of 1870