Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects outbound network requests to VAPI.ai APIs that are associated with the initiation of AI-powered voice agents. This telemetry can indicate the use of automation or malicious scripts, such as those used by AnonyMousKIT to launch persona-based voice phishing (vishing) campaigns.
Detects sustained WebSocket connections to known C2 infrastructure associated with the JWR phishing framework. The rule identifies long-running sessions or frequent reconnection patterns characteristic of a live human operator interacting with a victim, as opposed to automated, one-time form submissions.
Detects the AnonyMousKIT vishing activity pattern by monitoring Twilio API call creation events followed by specific status or gather webhook callbacks from the same host within a one-hour window, consistent with automated voice phishing to collect DTMF-entered passcodes.
Detects the specific network-observable behavior of the JWR client engine. The rule identifies a device loading the engine script (main.js) followed within a short time window by either a fallback redirection to a_index.html or the initiation of a WebSocket connection using a specific obfuscated path pattern associated with JWR command and control.
Detects the specific C2/WebSocket instruction sequence utilized by the JWR/Outsider phishing kit operators. The rule monitors DeviceNetworkEvents for characteristic outbound URL query parameters that indicate progress through a phishing interaction, including initial info collection (to_info), card data submission (to_card), and subsequent verification or outcome steps.
This rule detects DNS lookups, email URL clicks, and network connections involving lookalike domains that mimic Singaporean government or infrastructure services (e.g., LTA, OneMotoring, ERP, Gov.sg). It employs a regex-based pattern match for common brand-keywords combined with high-risk top-level domains, identifying potential phishing activity associated with the JWR framework that utilizes algorithmically varied, single-suffix rotated lookalike domains.
This rule detects network connections to specific domains and domain patterns that mimic legitimate entities (e.g., NinjaVan, EmiratesPost). The detection logic identifies direct matches to known malicious infrastructure and uses regular expressions to catch permutation-based typosquatting, which are common indicators of phishing or credential harvesting campaigns.
Detects SVG files containing embedded ECMAScript that executes a client-side redirect to a known AiTM phishing or C2 domain, specifically targeting the Mirage2FA delivery mechanism.
Detects HTML, XHTML, or SVG files used in Mirage2FA phishing campaigns. These files act as stagers by constructing hidden iframes to load remote JavaScript payloads from '/api/xls/' paths, utilizing specific placeholder tokens and obfuscation techniques such as XOR deobfuscation (0xAD) and custom function wrappers.
Detects a multi-stage local execution chain associated with the Mirage2FA malware. The activity begins with WinRAR extracting an HTML stager from an Outlook quarantine directory, followed by rundll32.exe invoking shell32.dll to open the stager, and concluding with a spawned Microsoft Edge process executing the local HTML file.
Detects the initialization stage of a Mirage2FA phishing attack, characterized by the execution of a locally saved HTML file in a web browser, closely followed by an outbound network connection to the ipify.org API for victim IP geolocation and fingerprinting before the malicious sign-in page is rendered.
Detects the specific fingerprinting sequence associated with Mirage2FA AiTM phishing campaigns. The detection triggers when a process downloads a specific JavaScript loader from an '/xls/' path, followed closely within two minutes by an IP/geolocation lookup request to common services (api.ipify.org, api.country.is, api.ipgeolocation.io), which is a characteristic precursor to credential interception.
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
Detects the use of a malicious 'borlndmm.dll' file intended for DLL side-loading to deploy the OnyxC2 stealer payload. The rule identifies files masquerading as NVIDIA graphics libraries or Borland memory managers that contain embedded encrypted payloads, matching known indicators for OnyxC2 activity.
Detects instances where a non-browser process accesses multiple distinct browser credential or session artifacts (such as Login Data, Cookies, or Local State) across different browser profiles in a short period. This behavior is indicative of credential harvesting activities, often associated with C2 frameworks or post-exploitation tools attempting to steal session cookies, 2FA backup codes, or saved passwords.
Detects the specific behavior associated with the OnyxC2 C2 framework where a process re-spawns a child instance of itself, followed by a rapid registry modification by that child process. This pattern serves as a marker for the ONYXC2 loader configuration stage.
Detects a suspicious staging behavior associated with OnyxC2 premium-tier malware. The detection identifies a process respawning itself—a common precursor to hidden VNC or credential access activity—followed by the execution of Microsoft Edge with specific utility flags typically used to masquerade as an indexing component. This pattern is characteristic of techniques used to hijack authenticated browser sessions for C2 purposes.
Detects unauthorized processes attempting to access the memory of the Local Security Authority Subsystem Service (LSASS) with high-privilege access masks, a technique commonly used for credential dumping to harvest passwords and authentication tokens.
Detects the execution of ServiceModelReg.exe from the standard .NET Framework directories. While this utility is a legitimate tool used for registering and configuring WCF components, its abuse has been observed in the wild by threat actors, including the OnyxC2 malware, to leverage built-in Windows utilities for suspicious activities.
Detects the presence of an OnyxC2 sideloaded DLL, identified by the filename 'borlndmm.dll', masquerading as an NVIDIA graphics library. The rule identifies suspicious files that are unusually large (50MB-200MB) with high entropy, suggesting an encrypted payload appended to the file. It also looks for associations with known loaders like 'ABRSubProcess.exe' or 'Setup_File_92.118.3096.exe' and the 'ACCA software S.p.A.' digital signature.
Detects instances where processes other than standard web browsers attempt to access sensitive browser data files, such as cookies, login data, and browser state files. This behavior is a common indicator of credential theft or browser session hijacking, often performed by stealer malware like OnyxC2.
Page 158 of 1871

