Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the two-stage execution chain associated with Raspberry Robin (Gamarue) propagation via removable media. The rule correlates the initiation of suspicious processes (msiexec.exe, rundll32.exe, or explorer.exe) from removable drive paths containing disguised DLLs or LNK files with subsequent obfuscated rundll32.exe execution command lines within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects ClickFix-style activity where a user is tricked into entering or pasting malicious command strings into the Windows File Explorer address bar. This activity results in the spawning of common utilities like cmd.exe, powershell.exe, or certutil.exe with arguments associated with UNC paths, Base64 encoding, or download cradles (e.g., IEX, bitsadmin, or URLCache operations).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects suspicious processes such as PowerShell, Python, or scripting hosts performing network communication with major AI/LLM provider APIs, followed immediately by child process execution or related activity. This pattern is indicative of LLM-assisted automation for malicious activities, potentially using AI to generate code, scripts, or orchestrate command and control actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects potential execution of malicious commands following a fake browser crash dialog, often used in social engineering attacks (CrashFix). The rule identifies PowerShell or Windows Script Host processes spawned by common web browsers shortly after a browser session start, specifically looking for common command-line indicators used to copy-paste or execute malicious snippets, while filtering out legitimate WerFault.exe crash reporting activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the installation of browser extensions that utilize sensitive permissions (e.g., full URL access, cookie access) followed shortly by network connections to potentially non-reputable domains within one hour of the installation. This pattern is indicative of malicious browser extensions established for data exfiltration or credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects high-risk domain account activity, specifically identifying either impossible-travel authentication patterns in cloud logs or rapid, multi-host interactive authentication fan-out within one hour. These detections are further correlated with subsequent RDP or WinRM session establishment, indicating potential lateral movement or compromise of legitimate accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
201
Detects processes querying registry keys or accessing file paths associated with common virtualization and sandbox environments (e.g., VMware, VirtualBox, Hyper-V, Sandboxie). This behavior is often indicative of malware attempting to identify if it is running in an analysis or sandbox environment to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects attempts to disable, stop, or reconfigure security software (Antivirus, EDR, Endpoint Protection) on Windows endpoints by abusing legitimate administrative utilities such as sc.exe, net.exe, taskkill.exe, wmic.exe, and PowerShell to tamper with service configurations or kill security-related processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects potential exploitation of Active Directory Certificate Services (AD CS) misconfigurations (specifically ESC1, involving client-auth EKU and enrollee-supplies-subject). The rule correlates certificate issuance events (4886, 4887, 4888) involving sensitive templates or suspicious subject alternative name (SAN) mismatches with subsequent Kerberos PKINIT authentication (4768) events using the issued certificate.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects a potential mass-encryption event by identifying a single host rapidly renaming or rewriting a large volume of files across multiple SMB network shares within a short timeframe, where the renamed files consistently adopt a single file extension.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects lateral movement via SMB by identifying multiple connections to Windows admin shares (ADMIN$ or C$) followed within a 10-minute window by the creation of a remote service, often indicative of techniques like PsExec. This pattern detects suspicious fan-out behavior where a single source host interacts with multiple targets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the creation of scheduled tasks via schtasks.exe or native Windows event logs that exhibit suspicious characteristics commonly associated with persistence mechanisms. These characteristics include tasks triggered at logon or system startup, tasks running with elevated SYSTEM privileges, tasks configured to be hidden, or tasks executing binaries from temporary, user-writable directories (Temp, AppData, Public). This pattern is often observed in attack chains leveraging RMM tools or delivery mechanisms like ClickFix.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects common Windows system binaries (svchost.exe, csrss.exe, lsass.exe, explorer.exe) executing from non-standard directories, which is a common indicator of process masquerading to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
This rule detects unauthorized or unauthenticated attempts to call the NetrServerPasswordSet2 method on a Domain Controller via the MS-NRPC (Netlogon) interface, which is indicative of an exploitation attempt related to CVE-2020-1472 (Zerologon). This vulnerability allows an attacker to bypass authentication and reset a Domain Controller's computer account password, leading to full domain compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects the execution of LNK files masquerading as PDF files through the use of double extensions (e.g., .pdf.lnk). The rule monitors for processes spawned by explorer.exe that contain '.pdf.lnk' in the command line and trigger child processes like PowerShell, CMD, WScript, or MSHTA, which are common indicators of malicious intent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects a coordinated attack sequence where a browser process is terminated, followed immediately by the execution of an unsigned Python interpreter from a suspicious location (temp/downloads folder), which is then followed by the installation of an unsigned browser extension. This pattern mimics ClickFix and browser-based RAT lure campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects network traffic indicative of VelvetCake malware exfiltrating data. The rule specifically monitors for HTTP POST requests to 'logout.php' containing 'OKey' and 'Who' parameters, using a user agent string that includes 'WebClient', which is often associated with PowerShell-based network requests.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Page 95 of 1870