Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
102
Detects a behavioral fingerprint associated with the NeedyMantis group, characterized by the creation of a DLL and a identically-named, extensionless, encrypted archive file in the same directory within a short time window. This approach identifies the underlying packaging strategy rather than relying on static file names or known paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Detects .ps1-named files dropped to disk that are never actually executed by a PowerShell interpreter (powershell.exe / pwsh.exe) within a short window afterward. NeedyMantis's second-stage loader (e.g. encryptbase64.ps1) is raw x64 shellcode, not a real script -- it's read and executed directly by the dropping process, so no genuine PowerShell host process ever references the file by name. Replaces an earlier version of this rule that watched DeviceImageLoadEvents for a .ps1 extension: Windows can only emit an image-load event for a file with a valid PE header loaded via the OS loader, and raw shellcode has no PE header and is never mapped that way, so that approach would not have fired on this malware. Caveat: legitimate deployment tooling that stages a script for delayed or remote execution can also produce this create/execute mismatch; tune the window and add known-good deployment-tool exclusions for your environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
002
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
001
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
001
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
001
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
001
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
001
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
101
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
001
Detects SectopRAT (Arechclient2) .NET RAT binaries deployed via tampered libcef.dll / JetBrains helper DLL sideloading that harvest browser credentials, cookies, credit card data, and files. Tightened to require combined sideload+family+target indicators plus .NET CLR import evidence, avoiding standalone generic strings.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
001
Detects SectopRAT (Arechclient2) .NET RAT binaries deployed via tampered libcef.dll / JetBrains helper DLL sideloading that harvest browser credentials, cookies, credit card data, and files. Tightened to require combined sideload+family+target indicators plus .NET CLR import evidence, avoiding standalone generic strings.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
001
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
002
Detects the GitHub Actions runner executing the Bun runtime to run a hidden index.js payload, specifically associated with the compromised 'actions-cool/issues-helper' or 'actions-cool/maintain-one-comment' actions. The rule filters for process execution context tied to GitHub runner internals and validates that the Bun execution follows the pattern observed in these supply chain attacks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
001
Detects the GitHub Actions runner executing the Bun runtime to run a hidden index.js payload, specifically associated with the compromised 'actions-cool/issues-helper' or 'actions-cool/maintain-one-comment' actions. The rule filters for process execution context tied to GitHub runner internals and validates that the Bun execution follows the pattern observed in these supply chain attacks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
001
Detects the GitHub Actions runner executing the Bun runtime to run a hidden index.js payload, specifically associated with the compromised 'actions-cool/issues-helper' or 'actions-cool/maintain-one-comment' actions. The rule filters for process execution context tied to GitHub runner internals and validates that the Bun execution follows the pattern observed in these supply chain attacks.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
001
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
002
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
102
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
102
Detects the spawning of common administrative or script-execution tools as child processes from SharePoint-related processes (w3wp.exe or OWSTIMER.EXE). This behavior is often indicative of exploitation attempts targeting SharePoint application pools to execute arbitrary code.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
000
Page 134 of 1870