Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

KQL Query from file: JivaChat Installer - Full Chain
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
002
KQL Query from file: JivaChat Installer - Full Chain
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
002
KQL Query from file: JivaChat Installer - Full Chain
avatar
Ankit Mehta@Secvyn
Defender - KQL
15 days ago
002
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
101
This rule detects potential MFA phishing attempts by identifying access to known malicious domains used for MFA credential harvesting within email communications and network traffic. It flags instances where users interact with domains masquerading as legitimate multi-factor authentication setup or registration services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
105
Detects the use of the Windows certutil utility to decode Base64-encoded files into executable, library, or script formats. This technique is commonly used by adversaries to decode malicious payloads that were dropped on a system in an encoded form to bypass signature-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
002
Detects the use of bitsadmin.exe to create or modify Background Intelligent Transfer Service (BITS) jobs, specifically when combined with the /setnotifycmdline flag. This technique is used by adversaries to download malicious payloads and trigger their execution upon job completion, often bypassing network security controls that might otherwise flag traditional download-and-execute activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
002
Detects suspicious execution patterns of rundll32.exe, including usage for JavaScript execution, control panel file abuse, potential credential dumping using comsvcs.dll, and execution from common user-writable temporary directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
202
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
002
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
202
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
002
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
402
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
102
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
202
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
102
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
002
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
002
Detects a suspicious sequence of network events consistent with a credential-harvesting campaign abusing the FedCM (Federated Credential Management) API. The rule identifies the initial fetch of a malicious loader script from a lookalike domain (pdf.gusercontent.com), followed closely (within 5 minutes) by a redirect to Google's legitimate 'EmbeddedSetup' sign-in flow containing an email parameter.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
202
Detects an account takeover chain where a device loads a malicious JavaScript component ('load-addon.js') in a browser session, followed by repeated attempts to bypass bot detection mechanisms (targeting Google's 'errors/robot.png') as the payload attempts to force authentication challenges or password resets.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
102
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
102
This rule detects the presence of the malicious 'pdf-para-texto@extensao.local' Firefox extension on disk. This extension is known to perform browser-based credential interception by patching the WebAuthn PublicKeyCredential interface at document_start on Google-related domains to facilitate account takeover.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
102
Page 129 of 1870