Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects Node.js or Python processes exhibiting suspicious behavior consistent with information-stealing malware (such as BeaverTail or InvisibleFerret). The rule monitors for these processes accessing sensitive files, including browser credentials, cookies, browser extension wallet settings, cryptocurrency wallet files, and various identification document image types, followed by the execution of archiving utilities (e.g., zip, rar, 7z) to stage the collected data for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
103
Detects the creation or modification of registry entries within the 'HKCU\...\Run' hive that point to executables located in suspicious or atypical directories such as 'ProgramData', 'Users\All Users', or specific non-standard application paths often used by malware for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the use of PowerShell to modify Microsoft Defender preferences by adding exclusion paths, processes, or extensions shortly after the creation of Registry Run keys. This sequence is characteristic of post-exploitation activity where an adversary establishes persistence and subsequently attempts to neutralize security software monitoring of their malicious payloads to avoid detection during future execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
This rule detects the creation of a file within the SysWOW64 directory followed by an immediate modification or creation of a Windows Run registry key within a 10-minute window. This behavior is indicative of a persistence mechanism where a malicious file is dropped to a system directory and registered for execution at system startup or user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
103
Detects execution of the CHOSEN BRICK implant (process names smdqservice.exe or winappx.exe) initiating a network connection to Telegram infrastructure (C2) followed by a network connection to a cloud object-storage provider (vultrobjects.com, storjshare.io, or backblazeb2.com) for data exfiltration within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
004
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
003
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
003
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
003
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
003
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
104
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
102
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
102
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
002
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
002
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
002
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
Page 146 of 1871