Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects periodic execution cycles of ERAAgent.exe that involve memory protection changes, characteristic of the SLEEPWALKER malware's XOR-decrypt-execute-reencrypt loop scheduled by a cron-like mechanism.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects instances where processes other than the primary web browsers (Chrome, Brave, Firefox) create, rename, or modify sensitive browser data files like 'Cookies' or 'Login Data'. This behavior is indicative of credential theft or data exfiltration attempts where an adversary is accessing browser-stored information.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the creation of an NTUSER.MAN file followed by an update or creation of a registry run key (Run or RunOnce) on the same device within a 60-minute window. NTUSER.MAN is a mandatory user profile file that, when present, can be used to override user settings and persist malicious configurations or startup entries.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects instances where WerFault.exe or WerMgr.exe, running with SYSTEM privileges, loads a DLL file from the Windows\System32 directory that was created within 10 minutes of the image load event. This behavior is indicative of potential DLL side-loading or hijack techniques used to achieve privilege escalation.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
101
Detects instances where the NW.js (Node-Webkit) framework binaries (nw.exe, node.exe) spawn common command-line interpreters or script-hosting utilities (e.g., cmd.exe, powershell.exe, wscript.exe) while executing associated application files like main.js or nw.pak. This behavior is indicative of potential exploitation of a browser-based application to gain shell access or execute arbitrary code on the host system.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the invocation of the AppInstaller executable to install .msix packages, often used in software installation or malicious delivery scenarios involving application deployment.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
101
This rule detects unauthorized modifications to browser search provider settings in the Windows Registry, targeting keys associated with Chrome and Microsoft Edge search configuration. This activity is often indicative of browser hijacking or search engine redirection campaigns, such as the NinjaMare malware.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
101
This rule detects a suspicious sequence of events where a process with a name resembling an updater (AutoUpdate.exe or au.exe) accesses a specific remote configuration file from a herokuapp.com URL, followed by the creation or modification of specific application binaries (e.g., InstaTime.exe, ffmpegsumo.dll). This pattern is indicative of a supply chain compromise or an automated software update hijacking where malicious binaries are staged to replace legitimate application components.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects a specific evasion behavior associated with the NinjaMare malware, where a process idles for at least 7 minutes before moving its window to off-screen coordinates during automated mouse or keystroke input, followed by restoring the window to its original position.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the creation, modification, or renaming of PHP files within the 'wp-content/uploads' directory of a WordPress installation. This pattern is commonly indicative of an attacker uploading a web shell to maintain persistence or execute arbitrary code on a compromised web server.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects instances where base64-encoded PHP code, obfuscated behind a 'data:image/gif;base64' MIME type prefix, is written to the disk as a .php file or initiated by web server processes. This pattern is commonly used in file upload bypass attacks to execute arbitrary code.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects instances where the process wtass.exe (often associated with specific legacy or third-party enterprise tools) spawns cmd.exe. This pattern is potentially indicative of command-line abuse, where a legitimate application's child process is leveraged to execute shell commands.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden windows) initiated by mshta.exe, excluding instances where a .ps1 script file is involved. This pattern often indicates attempts to bypass execution policy or run obfuscated payloads in memory, which is a common behavior of malicious HTA files.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
101
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001