Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

4 detections

This rule detects network connections and user sign-ins originating from IP addresses identified as belonging to Iran. It also identifies sign-ins where the reported country is Iran, but the IP address is not found within the provided Iranian IP list, which could indicate IP geolocation discrepancies or obfuscation attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
This rule detects network connections and user sign-ins originating from IP addresses identified as belonging to Iran. It also identifies sign-ins where the reported country is Iran, but the IP address is not found within the provided Iranian IP list, which could indicate IP geolocation discrepancies or obfuscation attempts.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
101
Detects network requests to known malicious domains associated with the fake RedAlert Android malware campaign used by pro-Iranian actors, acting as a payload host or C2 endpoint.
avatar
Elgonad .@elgonad
avatar
Detections.ai Community
6 months ago
20212
This rule detects network connections and user sign-ins originating from IP addresses identified as belonging to Iran. It also identifies sign-ins where the reported country is Iran, but the IP address is not found within the provided Iranian IP list, which could indicate IP geolocation discrepancies or obfuscation attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 months ago
170191