Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the creation of a scheduled task using 'schtasks.exe' where the initiating process is a script interpreter such as 'mshta.exe' or 'powershell.exe'. This behavior is often associated with the execution of malicious payloads or the establishment of persistence.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
101
Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects potential reflective code injection or in-memory loading (fileless) where a DLL or PE image is loaded by mshta.exe or powershell.exe, but the module load event lacks a valid file path on disk (or indicates a device path). This behavior is often associated with the execution of malicious payloads such as the Amatera loader, where payloads are executed directly in memory to evade file-based security detections.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects network connections or DNS queries to known phishing domains (typosquatted Microsoft login domains), DeadDrop Resolver domains, and suspicious HTML payloads served from common CDN/package hosting sites (e.g., unpkg.com, npmmirror.com, cdn.jsdelivr.net, yarnpkg.com). These patterns are indicative of initial access attempts via phishing or the secondary stage of malware C2 communication.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
101
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
101
Detects the use of PowerShell commands to add directory exclusions to Windows Defender settings. Adversaries often use this technique to exclude directories in 'AppData' from being scanned by antivirus solutions to hide malicious activity, tools, or persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects unauthorized processes (e.g., cmd.exe, powershell.exe, node.exe) accessing sensitive web browser files like 'Login Data' or 'Cookies' in common browser directories. This behavior is indicative of credential theft or data exfiltration attempts.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects a suspicious sequence of activities where PowerShell downloads or extracts specific zip files (node.zip, build.zip) to staging directories, followed by the execution of associated binaries like node.exe, winpty-agent.exe, or winpty.dll from those same locations. This behavior is indicative of an adversary staging and executing tooling within temporary user directories.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects Node.js or related helper processes executing shell commands (cmd.exe, powershell.exe) or other processes where the execution involves the 'withCreateProcessUser' argument. This often indicates attempts to bypass execution restrictions or run malicious payloads by utilizing Node.js as an execution proxy within unconventional or temporary directories.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects suspicious activity associated with JSCeal proxy handlers. It identifies Node.js or Electron processes running from non-standard, user-writable directories (such as AppData, ProgramData, or Temp folders) that actively delete or modify browser cookie files within standard web browser profile paths, often indicative of session hijacking or data tampering.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects nm_host.exe (PEEP native messaging host binary) spawned by Chrome/Edge, tightened to require either the known PEEP extension ID in the native-messaging invocation command line or the distinctive com.peep.lab host path.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
1001