Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
002
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
002
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
002
Detects the creation of files named 'parser.js' or 'loader.js' within hidden or suspicious VSCode directories (e.g., .npm/.vscode/ or AppData/VSCode/). The detection also flags potential signs of malicious intent, such as the existence of a 'package.json' file nearby or the presence of 'tokenapp' in the file path, which are often indicative of the GHAPPIER implant behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the execution of rundll32.exe with a command line containing 'DavWWWRoot', indicating the loading of a DLL from a remote WebDAV share. This is a common technique used by attackers to execute remote malicious code while bypassing local execution policies or attempting to evade local file-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects anomalous, high-frequency access to clipboard APIs (GetClipboardData/SetClipboardData) by non-standard, unrecognized processes. The rule specifically monitors for patterns consistent with clipper malware, which polls the clipboard for cryptocurrency address formats and replaces them with attacker-controlled addresses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
This rule identifies processes that delete themselves shortly after execution. It joins process creation events with file deletion events on the same device, filtering for cases where the initiating process file name, ID, and hash match the deleted file, and where the deletion occurs within 120 seconds of the process creation. This behavior is commonly associated with malware or adversary tools attempting to remove traces of their activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
104
Detects the execution of PowerShell via explorer.exe (typically initiated through the Windows Run dialog) where the command line references a WebDAV UNC path (containing DavWWWRoot). This behavior is characteristic of 'ClickFix' social engineering attacks, where users are coerced into copying and pasting commands into the Run dialog that trigger remote script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
004
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
002
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
Page 147 of 1871