Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

30 detections

This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
517
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
006
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
105
This rule detects an exploitation attempt targeting a memory overflow vulnerability in Citrix NetScaler Gateway, specifically identifying oversized DTLS handshake length fields in UDP traffic. The rule triggers when a DTLS packet exceeds the specified size threshold, which is indicative of a buffer overflow attack intended to cause a service crash (Denial of Service).
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
003
This rule detects a potential SYN flood denial-of-service attack, characterized by a high volume of TCP SYN packets directed at a target within a short timeframe. Such activity is indicative of attempts to exhaust server resources by leaving TCP handshakes incomplete.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects anomalous, oversized fragmented UDP traffic (exceeding 1400 bytes) targeting or originating from the MikroTik btest service port (2000). This behavior is indicative of attempts to trigger integer underflows, system crashes, or uninitialized memory disclosures within the btest protocol implementation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
003
Detects high-volume POST requests containing HEIF, HEIC, or AVIF image content types, indicative of automated fuzzing or exploitation attempts against an image-processing endpoint targeting CVE-2026-32882.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
003
Detects a specifically malformed IPv6 Routing Header (type 0) with a 'segments_left' value of 255 preceding an Authentication Header (AH). This signature targets an exploit pattern known as 'DirtyAH6', which aims to trigger a remote kernel crash or potential remote code execution on vulnerable systems by manipulating IPv6 header processing.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
003
Detects high-volume POST requests containing HEIF, HEIC, or AVIF image content types, indicative of automated fuzzing or exploitation attempts against an image-processing endpoint targeting CVE-2026-32882.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
Detects high-volume POST requests containing HEIF, HEIC, or AVIF image content types, indicative of automated fuzzing or exploitation attempts against an image-processing endpoint targeting CVE-2026-32882.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
Detects high-volume POST requests containing HEIF, HEIC, or AVIF image content types, indicative of automated fuzzing or exploitation attempts against an image-processing endpoint targeting CVE-2026-32882.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
002
This rule detects malformed SCTP packets that trigger a protocol decoding error ('pkt_too_small'). This behavior is associated with the 'DiagSpill' vulnerability (CVE-2026-74469), where specially crafted chunk sequences in the SCTP stream can cause a remote service crash or potential instability. The rule includes a threshold to mitigate noise from non-malicious malformed packets.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
002
This rule detects malformed SCTP packets that trigger a protocol decoding error ('pkt_too_small'). This behavior is associated with the 'DiagSpill' vulnerability (CVE-2026-74469), where specially crafted chunk sequences in the SCTP stream can cause a remote service crash or potential instability. The rule includes a threshold to mitigate noise from non-malicious malformed packets.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
002
Detects high-frequency SCTP ASCONF/ADD-IP chunk packets originating from external networks. This behavior is indicative of a Denial-of-Service (DoS) exploit attempt targeting a vulnerability (CVE-2026-74469) related to DiagSpill transport_count integer wraparound.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
002
This rule detects malformed SCTP packets that trigger a protocol decoding error ('pkt_too_small'). This behavior is associated with the 'DiagSpill' vulnerability (CVE-2026-74469), where specially crafted chunk sequences in the SCTP stream can cause a remote service crash or potential instability. The rule includes a threshold to mitigate noise from non-malicious malformed packets.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
001
Detects a specifically malformed IPv6 Routing Header (type 0) with a 'segments_left' value of 255 preceding an Authentication Header (AH). This signature targets an exploit pattern known as 'DirtyAH6', which aims to trigger a remote kernel crash or potential remote code execution on vulnerable systems by manipulating IPv6 header processing.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
001
Detects a specifically malformed IPv6 Routing Header (type 0) with a 'segments_left' value of 255 preceding an Authentication Header (AH). This signature targets an exploit pattern known as 'DirtyAH6', which aims to trigger a remote kernel crash or potential remote code execution on vulnerable systems by manipulating IPv6 header processing.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
001
Detects a specifically malformed IPv6 Routing Header (type 0) with a 'segments_left' value of 255 preceding an Authentication Header (AH). This signature targets an exploit pattern known as 'DirtyAH6', which aims to trigger a remote kernel crash or potential remote code execution on vulnerable systems by manipulating IPv6 header processing.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
001
Detects high-frequency SCTP ASCONF/ADD-IP chunk packets originating from external networks. This behavior is indicative of a Denial-of-Service (DoS) exploit attempt targeting a vulnerability (CVE-2026-74469) related to DiagSpill transport_count integer wraparound.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
001
Detects high-frequency SCTP ASCONF/ADD-IP chunk packets originating from external networks. This behavior is indicative of a Denial-of-Service (DoS) exploit attempt targeting a vulnerability (CVE-2026-74469) related to DiagSpill transport_count integer wraparound.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
001
Detects high-frequency SCTP ASCONF/ADD-IP chunk packets originating from external networks. This behavior is indicative of a Denial-of-Service (DoS) exploit attempt targeting a vulnerability (CVE-2026-74469) related to DiagSpill transport_count integer wraparound.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
001