Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

4 detections

Potential exploitation of JetBrains TeamCity (Unauthenticated RCE, CVE-2026-63077) looking for suspicious child processes spawned by TeamCity services.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
6020
Potential exploitation of JetBrains TeamCity (Unauthenticated RCE, CVE-2026-63077) looking for suspicious child processes spawned by TeamCity services.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
409
Detects file creation, write, or rename operations to specific paths known to be used in exploitation of CVE-2026-63077.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
408
Detects suspicious command-line activity originating from TeamCity service processes on Windows. The rule looks for unexpected child processes (e.g., cmd.exe, powershell.exe, curl.exe) initiated by the TeamCity server or associated Java processes, which may indicate exploitation of an unauthenticated remote code execution vulnerability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006