Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the UAT-11587 TestAssembly.dll downloader by its shared AssemblyAttribute GUID b2b3adb0-1669-4b94-86cb-6dd682ddbea3 embedded in .NET metadata across all campaign builds
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects Antino backdoor binaries (slc.dll and standalone) via embedded AntinoApp application manifest string and Rust PDB path patterns matching GitHub Actions Windows runner structure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects UAT-11587 diplomatic-lure LNK file exploiting ZDI-CAN-25373 whitespace padding to conceal a PowerShell command that extracts CanonStager (cnmpaui.exe/dll) from TAR archives into %TEMP%
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
101
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
101
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects Kothamine Agent via hardcoded base64 AES-GCM key combined with C2 loop markers and plugin command strings, gated on PE structure to reduce false positives
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
101
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
101
Detects the execution of 'tailcat.exe' from non-standard locations such as user directories (AppData, Users), which is indicative of potential unauthorized use of Tailscale portable binaries to establish network proxies or unauthorized tunnels.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
Page 89 of 1870