Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
101
This rule monitors network connections initiated by common web browsers (chrome.exe, msedge.exe, brave.exe) to known domains associated with a specific VPN proxy service or subscription-based proxy farm infrastructure. The rule flags endpoints communicating with URLs involved in proxy beaconing, fallback hosting, and subscription API calls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Matches archived SHA-256 hashes of known malicious CRX builds from the 'VPN for X' proxy farm extension family
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects browser-side network activity involving known command-and-control or subscription API domains associated with a malicious VPN browser extension proxy campaign. The rule monitors for beaconing behavior from popular web browsers (Chrome, Edge, Brave) to specific domains utilized by the campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
004
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
004
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
004
Detects evidence of a SharePoint pre-authentication RCE exploit chain where an adversary injects a malicious Namespace containing an ExpandedWrapper-wrapped XamlServices payload (e.g., ObjectDataProvider or LosFormatter gadget) into the w3wp.exe worker process. This specifically looks for command-line arguments indicative of deserialization-based exploit attempts targeting SharePoint web server components.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
16 days ago
405
This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
9 days ago
000
Page 91 of 1870