Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects a suspicious sequence of command execution patterns characteristic of the Kothamine agent performing post-compromise system discovery. The rule triggers when multiple discovery commands (tasklist, ipconfig, taskkill) are executed by the same process instance within a 5-minute window, consistent with typical C2 behavior for reconnaissance.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Detects the Kothamine post-installation technique where npm/node spawns PowerShell to reflectively load a .NET assembly stager into memory. This behavior is followed by the PowerShell process spawning anomalous instances of RuntimeBroker.exe or svchost.exe. These spawned processes exhibit suspicious characteristics, such as executing from non-standard file paths, having missing command-line arguments (like the required '-k' for svchost), or having an illegitimate parent process (powershell.exe) instead of standard system parents like services.exe or wininit.exe.
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
Matches published SHA-256 hashes for the Kothamine Injector and Agent DLL, which drop MicrosoftEdgeUpdateCore.exe/.dll and inject into explorer.exe. Exact full-file SHA-256 match only, no fuzzy or partial matching, no additional PE structural checks.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
Page 90 of 1870
