Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where processes other than standard web browsers attempt to access sensitive browser data files, such as cookies, login data, and browser state files. This behavior is a common indicator of credential theft or browser session hijacking, often performed by stealer malware like OnyxC2.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects a suspicious process pattern where an executable running from a staging directory (Temp or Downloads) spawns a child process of itself, followed by a registry modification performed by that child process. This behavior is indicative of malicious loaders, such as OnyxC2, that sideload components and establish runtime configurations before C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects persistence establishment for the NetSupport Manager remote access tool (client32.exe) via common Windows techniques including registry run keys, Winlogon configuration, service creation, and scheduled tasks. This activity is often associated with the abuse of legitimate RMM software as a covert remote access implant, frequently following initial access via PowerShell or script-based loaders.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the creation or modification of Windows Registry Run/RunOnce keys that reference msbuild.exe without typical build arguments. This is often used by adversaries to maintain persistence by executing malicious XML-based projects or inline C#/VB code via a trusted system utility.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where the MSBuild.exe process is subjected to image replacement or tampering, a behavior often associated with process hollowing or malicious code injection techniques aimed at evading security defenses by masquerading as a legitimate developer utility.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
002
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
102
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
002
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
Detects anomalous network polling patterns consistent with 'EvilTokens' or similar adversary-in-the-middle (AiTM) OAuth phishing kits. The rule identifies web browsers performing high-frequency, low-interval polling (3-6s) against non-reputable/unseen domains (the attacker-controlled status endpoint) immediately preceding or following successful Microsoft OAuth device-code authentication sequences.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
102
Detects anomalous network polling patterns consistent with 'EvilTokens' or similar adversary-in-the-middle (AiTM) OAuth phishing kits. The rule identifies web browsers performing high-frequency, low-interval polling (3-6s) against non-reputable/unseen domains (the attacker-controlled status endpoint) immediately preceding or following successful Microsoft OAuth device-code authentication sequences.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
002
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
002
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
1011
Detects the execution of PowerShell or Unix shell commands (such as those containing encoded arguments, IEX, or clipboard reading) that are initiated by GUI-based applications or interactive shell environments like Windows Explorer, terminal emulators, or runtime brokers, often indicating potential malicious command injection or living-off-the-land activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
3010
Detects the execution of Windows Script Host (WScript.exe or CScript.exe) that creates a file or folder starting with 'Libs_' within the 'C:\Users\Public\' directory. This activity is often associated with attackers staging payloads, configuration files, or tools in publicly writable folders to evade detection.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
16 days ago
002
Detects suspicious file activity where a script or process creates a staging folder within 'C:\Users\Public\' and subsequently writes potential decoy PDF files or compressed archive payloads to that same directory. This behavior is indicative of a dropper or secondary stage malware delivery mechanism utilizing world-writable directories for staging.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
16 days ago
102
Detects instances where the Notepad++ executable is launched from a location within the C:\Users\Public\ directory, specifically when the parent process is a Windows scripting engine (wscript.exe or cscript.exe). This pattern is often indicative of an adversary executing a malicious payload staged in a common public directory using script-based wrappers to bypass execution policy or maintain stealth.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
16 days ago
002
Detects the deletion of a specific file named 'Evernote.zip' located within the 'C:\Users\Public\' directory when executed by Windows Script Host (wscript.exe or cscript.exe). This activity is often associated with the cleanup of second-stage archives used during malicious operations.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
16 days ago
002
This rule detects instances where Windows script hosts (wscript.exe or cscript.exe) create directories with suspicious naming conventions (starting with 'Libs_' or containing 'Temp Documents') within the 'C:\Users\Public\' directory. This activity is often associated with the staging of malicious payloads or collected data prior to exfiltration or execution.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
16 days ago
002
Detects instances where the Windows Script Host (wscript.exe) spawns a process to open a PDF file located within the Public user's 'Temp Documents' directory. This behavior is indicative of a potential malware staging or execution attempt where an adversary attempts to open a malicious document from a publicly accessible folder to bypass user suspicion or execute malicious content.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
16 days ago
002
This rule detects non-standard processes attempting to access sensitive web browser files (e.g., 'Login Data', 'Cookies', 'key4.db') that are typically only accessed by legitimate web browsers. It excludes known browser processes and trusted security or sync applications to identify potential credential theft attempts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
106
Page 159 of 1871