Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
9 days ago
000
This rule monitors for the installation of specific known-malicious or suspicious NPM packages that are commonly used in supply chain attacks. It identifies the execution of npm (or node) commands to install or add packages explicitly listed as malicious by security research, which may indicate a supply chain compromise or an attempt to introduce unauthorized code into the development environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
106
Detects two suspicious Kerberos activity patterns indicative of potential credential theft or reconnaissance: 1) A single account requesting tickets for multiple services or across multiple hosts in a short duration, which may indicate automated credential harvesting such as Kerberoasting; 2) The use of RC4 encryption (0x17) for Kerberos tickets, which is an older, weaker protocol and may indicate a forced downgrade attack to facilitate offline password cracking.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
24 days ago
2034
Detects the SCKit Go-based credential-stealing implant found in compromised npm and PyPI packages. The detection logic focuses on unique build-info module paths, specific C2 encryption protocol headers, and embedded campaign identifiers related to 'memos-cloud-openclaw-plugin' and 'MemoryOS' supply chain compromises.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule monitors application, build system, and dependency scanning logs for references to known-malicious versions of the @memtensor/memos-cloud-openclaw-plugin (npm) and MemoryOS (PyPI) packages. These versions contain the sckit Go worm and are associated with automated supply chain attacks involving the reuse of stolen credentials, indicated by the 'exact-ref-one-use-NPM_TOKEN' marker.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects npm package publish events that lack 'gitHead' provenance metadata. The absence of this field indicates that the package was likely published from a developer's local machine rather than through an authorized CI/CD pipeline, a technique used in supply chain attacks to bypass CI-gated controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of the sckit Go implant, linked to the MemTensor supply chain compromise, during its host-profiling stage. The rule monitors for the 'sckit' binary being executed with 'stage0' and '--config64' command-line arguments, or being spawned by legitimate runtime interpreters like Node.js or Python, indicating an attempt to profile host information (timezone, language, privileges) and subsequent self-deletion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects execution of 'clspack.exe' from within the user's AppData directory. This location is frequently used by adversaries to stage and execute malicious binaries to evade detection, as it is outside of typical system directories like System32 or SysWOW64 where trusted system binaries are expected.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
Detects the execution of rundll32.exe with the '/sta' command line argument followed by a CLSID. This behavior leverages the IShellRunDll COM interface to execute registered objects, bypassing the standard requirement of providing a DLL path and exported function name. This method is often used by adversaries to execute malicious code while blending in with legitimate system processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
103
This rule detects potentially malicious file execution by monitoring for the usage of .pif files, often disguised as image files or documents, which subsequently launch suspicious child processes such as msiexec, wscript, cscript, or rundll32. The detection logic matches on specific parent processes (e.g., browsers, email clients, file explorers) triggering the file, followed by suspicious command line arguments within a 10-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
This rule detects potentially malicious activity involving the execution of WSF scripts from the AppData directory, followed by registry modifications using reg.exe or rundll32.exe. Additionally, it monitors for the creation or presence of specific suspicious files (clspack.exe, filetext.txt, prnfig.wsf) in user profile directories, often indicative of staging or persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects instances where a Terraform process or its associated provider plugins spawn a Go toolchain process (go.exe) to execute a local package. This pattern is associated with malicious Terraform providers that use this technique to bootstrap second-stage payloads such as the Graphalgo RAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of rundll32.exe with the '/sta' command-line flag and a GUID-formatted CLSID. This technique is often used by malware (e.g., DarkME RAT) to proxy execution through COM components, which hides the actual path of the loaded DLL or payload, aiding in evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
This rule detects the execution of 'clspack.exe' from within the AppData\Microsoft directory. 'clspack.exe' is a legitimate Windows utility normally residing in System32 or SysWOW64. Execution from user-writable directories like AppData is a common indicator of masquerading or binary hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects potential staging and execution chains involving remote MSI file fetching via msiexec.exe, or the execution of .wsf scripts or registry imports originating from or residing in AppData directories. This behavior is indicative of multistage malware delivery or persistence mechanisms where components are downloaded and executed using LOLBins.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of a file named 'setup.exe' from suspicious user-writable directories (Temp, Downloads, AppData) when the command line arguments contain keywords associated with archive utilities like 7-Zip or Foobar2000. This pattern is indicative of a 'nested installer' technique where legitimate software utilities are leveraged to extract or execute malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule detects DLL files being loaded by common archive extraction and setup utilities (7-zip, setup.exe). Adversaries often use self-extracting (SFX) archives or installer wrappers to execute malicious code by placing a malicious DLL in the same directory as the executable to facilitate DLL side-loading or masquerading.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule detects network connections on standard web ports (80, 443) initiated by Windows executable files (.exe) to specific, known malicious or suspicious domains (codeonicinc.com, setupsoftwarecenter.com). This pattern is consistent with malware installers attempting to download secondary payloads or communicate with C2 infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule detects the execution of processes associated with known malicious SHA256 file hashes linked to OpenSUpdater. It monitors DeviceProcessEvents from the past 30 days to identify instances where these specific file hashes are executed on endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule detects network connections originating from hosts to specific remote domains ('codeonicinc.com', 'setupsoftwarecenter.com') which are associated with OpenSUpdater command and control (C2) activity. It leverages Microsoft Defender DeviceNetworkEvents to identify endpoints communicating with these known malicious infrastructure components.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule detects the execution of a file named 'setup.exe' that is spawned by common interpreters (explorer.exe, msiexec.exe, powershell.exe, cmd.exe) where the command line arguments reference archiving or compression utilities like 'foobar2000', '7z', or '7zip'. This is a common pattern for self-extracting (SFX) installers or malicious droppers attempting to execute payload components.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Page 109 of 1870