Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

This rule monitors for network connections to known malicious domains or IP addresses, and for the presence or execution of files with known malicious file hashes (MD5, SHA1, SHA256). It consolidates detections from network traffic, file events, and process execution logs over a 30-day lookback period.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
102
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
002
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
002
This rule detects the presence of files matching known SHA256 hashes associated with the GhostCode phishing kit. It monitors for these files both in email attachments and on local device filesystems to identify potential delivery and execution of malicious phishing payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
7013
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
004
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
16 days ago
002
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
18 days ago
004
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
004
Detects potentially malicious script execution chains where a user launches a JavaScript file (.js/.jse) from commonly abused directories (Downloads, Documents, Desktop, AppData, WinRAR temporary folders) via wscript.exe, which subsequently spawns PowerShell and establishes an external network connection within a short time window. This behavior is commonly associated with malware loaders, phishing attachments, and initial access payloads.
avatar
Ajay Kumar@Karanajay
avatar
Detections.ai Community
16 days ago
202
Detects the presence of a specific Russian-language error string ("Не удалось сгенерировать HWID") within binary files, which is characteristic of the HWID generation mechanism used by Vidar Stealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the spawning of command-line interfaces such as cmd.exe, powershell.exe, or pwsh.exe as child processes of the SharePoint web application worker process (w3wp.exe). This behavior is highly irregular for a web server process and is indicative of potential exploitation, such as remote code execution (RCE) via web application vulnerabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects malicious deserialization attempts targeting Microsoft SharePoint, specifically leveraging System.Data.Services.Internal.ExpandedWrapper combined with LosFormatter and System.Xaml.XamlServices. This signature is indicative of exploitation attempts related to CVE-2026-65660, allowing an attacker to achieve remote code execution by bypassing SafeControls restrictions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects potential malicious PowerShell activity involving suspicious file paths in 'C:\Users\Public\' and the use of 'UPLOAD' command strings, which may indicate the staging and execution of payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects network connections from workstation subnets to domain controllers using administrative protocols such as SMB (445), RPC (135), RDP (3389), or WinRM (5985/5986). This activity is indicative of lateral movement attempts by an adversary attempting to reach critical infrastructure from a compromised workstation in a flat or poorly segmented environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects an exploitation attempt against the SharePoint WebPartPagesWebService using the GetWebPartPageConnectionInfo method. The rule monitors for suspicious input patterns such as 'Register' and 'ignoreParentFrozen' within the URI query, which are indicative of a directive injection vulnerability.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects an attempt to exploit a quote-injection vulnerability within the SharePoint ToolPane.aspx page, specifically targeting the Register directive to bypass SafeControls restrictions. This pattern is commonly used for remote code execution or unauthorized application behavior modifications by manipulating server-side parsing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the presence of specific ysoserial gadget chain strings (ActivitySurrogateSelector/ActivitySurrogateDisableTypeCheck) indicative of deserialization attacks targeting Microsoft SharePoint via System.Web.UI.LosFormatter. This typically occurs in memory within w3wp.exe processes following an initial RCE exploit, such as those targeting EditingPageParser or ToolPane.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Page 153 of 1871