Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects registry value modifications to the Windows Explorer RunMRU key where the data contains indicators of obfuscated PowerShell commands. This pattern is commonly associated with the 'ClickFix' social-engineering campaign, where users are prompted to copy and paste a malicious PowerShell command into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects the abuse of Windows protocol handlers ('search-ms:') and WebDAV UNC paths ('@SSL\DavWWWRoot') launched from common web browsers or Windows shell processes. This technique, frequently observed in 'ClickFix' phishing campaigns, enables attackers to stage remote payloads like LNK, HTA, or scripts by leveraging native Windows functionality to resolve remote content as if it were a local resource, bypassing typical file download security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects instances where a suspected malicious loader initiates process hollowing or APC injection by launching trusted Windows binaries (e.g., LockAppHost.exe, makecab.exe, Magnify.exe) in a suspended state. The rule identifies suspicious post-injection behavior such as unexpected network connections or child process creation originating from these typically benign binaries, which is characteristic of the DeepLoad/ClickFix attack chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects a suspected ClickFix-style delivery mechanism where a user visits suspicious domains mimicking legitimate CLI tools (e.g., Gemini, Claude) via web browsers. The detection correlates this initial network access with subsequent suspicious Windows RunMRU activity and the spawning of shell processes (powershell.exe, cmd.exe) from explorer.exe using encoded or download-oriented command line arguments within a 5-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects multiple reconnaissance commands executed by PowerShell processes running as the SYSTEM account. This behavior is indicative of an attacker attempting to enumerate domain trusts, group memberships, or user sessions on a host to facilitate lateral movement or privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
304
Detects the execution of 'sqlcmd.exe' when spawned by web application pools (w3wp.exe) or general command shell (cmd.exe) processes that do not appear to be related to authorized database administration or IIS appcmd activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the use of 'findstr' or PowerShell to query sensitive configuration files (such as web.config or applicationHost.config) for credential-related keywords like 'connectionString', 'AccountKey', or 'machineKey'. This behavior is indicative of an adversary attempting to harvest credentials or sensitive configuration data stored in cleartext on the filesystem.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the Microsoft IIS worker process (w3wp.exe) spawning common command-line shells (cmd.exe or powershell.exe) and executing discovery-related commands. This is highly indicative of potential web shell activity where an adversary uses an existing web application vulnerability to gain remote code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the presence of known SHA256 hashes associated with the 'ccrtc' planter PowerShell scripts and C2 SDK JavaScript components. These files were identified as being dropped into 'C:\Windows\Temp' during the STAC4924 webshell intrusion campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the creation of an ASPX file within a member file upload directory, followed immediately by the execution of 'cmd.exe' by the 'w3wp.exe' web server process. This behavior is indicative of a web shell being uploaded and used to execute arbitrary commands on the server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects reconnaissance activity on IIS servers where the worker process (w3wp.exe) spawns appcmd.exe or PowerShell to list websites, virtual directories, or application pools. This pattern is indicative of an attacker performing post-exploitation discovery after establishing a web shell.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where a Microsoft IIS worker process (w3wp.exe) executes commands such as 'findstr', 'Get-Content', or 'Select-Xml' to scan configuration files (e.g., applicationHost.config, web.config) or source code files (e.g., App_Code/*.cs) for sensitive information like passwords, connection strings, or API keys. This behavior is indicative of credential harvesting by an attacker using a webshell or compromised IIS process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates a child process of sqlcmd.exe. This behavior is highly suspicious and often indicates a post-exploitation activity where an attacker, having established a webshell or similar foothold on a web server, is using harvested credentials to query backend SQL databases directly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where the Internet Information Services (IIS) worker process (w3wp.exe) initiates a child process of sqlcmd.exe. This behavior is highly suspicious and often indicates a post-exploitation activity where an attacker, having established a webshell or similar foothold on a web server, is using harvested credentials to query backend SQL databases directly.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where an IIS worker process (w3wp.exe) spawns a command shell (cmd.exe) that executes a conditional file copy operation. This pattern is characteristic of an adversary creating a webshell by copying a payload to a filename that masquerades as a legitimate web application asset, such as a CSS bundle or validation script.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule monitors for suspicious command-line activity involving the Fortis payment processor's webhook log files. It detects when attackers use tools like 'findstr', 'cmd', or 'dir' to navigate directories containing webhook data and specifically searches for payment card fields such as CVV, primary account numbers, and expiration dates, which is a common indicator of post-compromise data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects DLL sideloading activity associated with the 'Lorem Ipsum Loader' malware. The rule monitors for specific combinations of legitimate Windows binaries loading specific DLLs from non-system directories, a common technique to execute malicious code via trusted processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule detects HTTP requests where the User-Agent header indicates a PowerShell execution occurring from a system configured with the zh-CN locale. This pattern is often associated with automated scripts or potential malicious activity masquerading as legitimate PowerShell traffic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detection of common web server reconnaissance, enumeration, and brute-force patterns targeting IIS environments. This includes detection of short-name (~1) probes, WebDAV method usage, NTFS alternate data stream requests, and brute-force attempts on login endpoints originating from PowerShell user agents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the presence of an embedded word-to-hex lookup table within a PE file. This technique is used by the Lorem Ipsum Loader to store shellcode as plaintext English words to evade entropy-based detection and static analysis tools. The rule matches a dense sequence of lowercase words frequently found in these malicious loaders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
The following analytic detects creation and removal of intermediary remediation artifacts of Windows Defender, during exploitation of ShieldCrash attacks.
Exploit abuses the race condition between file validation and its remediation performed by Windows Defender. In between these steps, ShieldCrash changes the
symbolic link to redirect the remediation process to a staging directory controlled by the attacker. This detection aims to detect creation of defender artifact,
its alternate data stream, and their subsequent removal.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
7 days ago
000
Page 64 of 1870