Search and filter across all detection sources
343 rules
Replace Malicious code: Malicious code in the connection was replaced.
[FORTINET] Malicious Code Detected
[CHECKPOINT] Action Replace Malicious Code
[FORTINET] Malicious Code Detected - Direction Outgoing
Potential Persistence Via Outlook Form
Detects the creation of a new Outlook form which can contain malicious code
Suspicious PowerShell Keywords
Detects keywords that could indicate the use of some PowerShell exploitation framework.
Systemd Service Creation
Detects a creation of systemd services which could be used by adversaries to execute malicious code.
Powershell Create Scheduled Task
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code
Microsoft Defender Antivirus Threat Detected
Detection of a Microsoft Defender Antivirus (MDAV) alert indicating the presence of potential malware
Wordpress_Config_Webshell_Preprend [yara]
Webshell that uses standard Wordpress wp-config.php file and appends the malicious code in front of it
Potential DLL Hollowing from a Writable Image
Identifies attempts to stealthily execute malicious code using DLL hollowing technique from a writable image.
Unsigned DLL Loaded by Windows Utility
Detects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.
Command Shell Activity Started via RunDLL32
Identifies command shell activity started via RunDLL32, which is commonly abused by attackers to host malicious code.
Windows LOLBAS Executed Outside Expected Path
The following analytic identifies a LOLBAS process being executed outside of it's expected location. Processes being executed outside of expected locations may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Scriptlet Execution via Rundll32
Identifies when scrobj.dll is loaded into rundll32.exe. An adversary may abuse rundll32.exe to proxy execution of malicious code.
Attachment: Embedded VBScript in MHT file
MHT files can be used to run VBScript, which can run malicious code.
Raw Paste Service Access
Detects direct access to raw pastes in different paste services often used by malware in their second stages to download malicious code in encrypted or encoded form
Windows LOLBAS Executed As Renamed File
The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Suspicious Windows Script Interpreter Child Process
Identifies unusual windows script interpreter child process which could indicate code injection or other form of malicious code execution via Windows scripts.
ISO LNK Infection Chain
Detection of an ISO download followed by a child-process of explorer, which is characteristic of an infection using an ISO containing an LNK file.
Registry Edit from Screensaver
Adversaries may use screensaver files to run malicious code. This analytic triggers on suspicious edits to the screensaver registry keys, which dictate which .scr file the screensaver runs.
Java Drop followed by network activity
Identifies attempts to execute a JAVA application that was recently dropped followed by network connection. Adversaries may abuse this utility to execute malicious code.