Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects outbound network requests to VAPI.ai APIs that are associated with the initiation of AI-powered voice agents. This telemetry can indicate the use of automation or malicious scripts, such as those used by AnonyMousKIT to launch persona-based voice phishing (vishing) campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects sustained WebSocket connections to known C2 infrastructure associated with the JWR phishing framework. The rule identifies long-running sessions or frequent reconnection patterns characteristic of a live human operator interacting with a victim, as opposed to automated, one-time form submissions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the AnonyMousKIT vishing activity pattern by monitoring Twilio API call creation events followed by specific status or gather webhook callbacks from the same host within a one-hour window, consistent with automated voice phishing to collect DTMF-entered passcodes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the specific network-observable behavior of the JWR client engine. The rule identifies a device loading the engine script (main.js) followed within a short time window by either a fallback redirection to a_index.html or the initiation of a WebSocket connection using a specific obfuscated path pattern associated with JWR command and control.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the specific C2/WebSocket instruction sequence utilized by the JWR/Outsider phishing kit operators. The rule monitors DeviceNetworkEvents for characteristic outbound URL query parameters that indicate progress through a phishing interaction, including initial info collection (to_info), card data submission (to_card), and subsequent verification or outcome steps.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects DNS lookups, email URL clicks, and network connections involving lookalike domains that mimic Singaporean government or infrastructure services (e.g., LTA, OneMotoring, ERP, Gov.sg). It employs a regex-based pattern match for common brand-keywords combined with high-risk top-level domains, identifying potential phishing activity associated with the JWR framework that utilizes algorithmically varied, single-suffix rotated lookalike domains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects network connections to specific domains and domain patterns that mimic legitimate entities (e.g., NinjaVan, EmiratesPost). The detection logic identifies direct matches to known malicious infrastructure and uses regular expressions to catch permutation-based typosquatting, which are common indicators of phishing or credential harvesting campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects SVG files containing embedded ECMAScript that executes a client-side redirect to a known AiTM phishing or C2 domain, specifically targeting the Mirage2FA delivery mechanism.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects HTML, XHTML, or SVG files used in Mirage2FA phishing campaigns. These files act as stagers by constructing hidden iframes to load remote JavaScript payloads from '/api/xls/' paths, utilizing specific placeholder tokens and obfuscation techniques such as XOR deobfuscation (0xAD) and custom function wrappers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects a multi-stage local execution chain associated with the Mirage2FA malware. The activity begins with WinRAR extracting an HTML stager from an Outlook quarantine directory, followed by rundll32.exe invoking shell32.dll to open the stager, and concluding with a spawned Microsoft Edge process executing the local HTML file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects the initialization stage of a Mirage2FA phishing attack, characterized by the execution of a locally saved HTML file in a web browser, closely followed by an outbound network connection to the ipify.org API for victim IP geolocation and fingerprinting before the malicious sign-in page is rendered.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects the specific fingerprinting sequence associated with Mirage2FA AiTM phishing campaigns. The detection triggers when a process downloads a specific JavaScript loader from an '/xls/' path, followed closely within two minutes by an IP/geolocation lookup request to common services (api.ipify.org, api.country.is, api.ipgeolocation.io), which is a characteristic precursor to credential interception.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
101
Detects the use of a malicious 'borlndmm.dll' file intended for DLL side-loading to deploy the OnyxC2 stealer payload. The rule identifies files masquerading as NVIDIA graphics libraries or Borland memory managers that contain embedded encrypted payloads, matching known indicators for OnyxC2 activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where a non-browser process accesses multiple distinct browser credential or session artifacts (such as Login Data, Cookies, or Local State) across different browser profiles in a short period. This behavior is indicative of credential harvesting activities, often associated with C2 frameworks or post-exploitation tools attempting to steal session cookies, 2FA backup codes, or saved passwords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
202
Detects the specific behavior associated with the OnyxC2 C2 framework where a process re-spawns a child instance of itself, followed by a rapid registry modification by that child process. This pattern serves as a marker for the ONYXC2 loader configuration stage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects a suspicious staging behavior associated with OnyxC2 premium-tier malware. The detection identifies a process respawning itself—a common precursor to hidden VNC or credential access activity—followed by the execution of Microsoft Edge with specific utility flags typically used to masquerade as an indexing component. This pattern is characteristic of techniques used to hijack authenticated browser sessions for C2 purposes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects unauthorized processes attempting to access the memory of the Local Security Authority Subsystem Service (LSASS) with high-privilege access masks, a technique commonly used for credential dumping to harvest passwords and authentication tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the execution of ServiceModelReg.exe from the standard .NET Framework directories. While this utility is a legitimate tool used for registering and configuring WCF components, its abuse has been observed in the wild by threat actors, including the OnyxC2 malware, to leverage built-in Windows utilities for suspicious activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the presence of an OnyxC2 sideloaded DLL, identified by the filename 'borlndmm.dll', masquerading as an NVIDIA graphics library. The rule identifies suspicious files that are unusually large (50MB-200MB) with high entropy, suggesting an encrypted payload appended to the file. It also looks for associations with known loaders like 'ABRSubProcess.exe' or 'Setup_File_92.118.3096.exe' and the 'ACCA software S.p.A.' digital signature.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where processes other than standard web browsers attempt to access sensitive browser data files, such as cookies, login data, and browser state files. This behavior is a common indicator of credential theft or browser session hijacking, often performed by stealer malware like OnyxC2.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Page 158 of 1871