Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
101
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
101
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Page 90 of 1870