Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects HTTP POST requests directed to the URI path '/api/credentials' over the non-standard TCP port 8133, which is indicative of AMOS (Atomic macOS) Stealer exfiltrating stolen credentials to a C2 server.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
002
Detects network activity associated with the AMOS (Atomic macOS Stealer) malware, specifically identifying C2 communication patterns such as heartbeat beacons and agent tasking requests occurring over non-standard port 8133.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
002
Detects architecture-specific Mach-O 64-bit AMOS Stealer binaries dropped by the Macfinger ClickFix first-stage shell script, requiring multiple distinctive C2 endpoint strings alongside Mach-O magic and size constraints to reduce false positives
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
102
Detects the use of download utilities (curl or wget) from terminal shells with command-line arguments containing 'force=1' and architecture-specific identifiers (e.g., arm64, x86_64). This pattern matches the execution chain commonly associated with ClickFix-based AMOS malware distribution, where users are tricked into pasting commands to download and execute architecture-specific payloads.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
202
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
202
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
002
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
002
Detects the execution of 'setup.js' by the node.js runtime when initiated by 'npm install' or 'postinstall' hooks. This behavior is a common indicator of a malicious supply chain attack where a compromised or malicious npm package executes unauthorized code during the package installation or setup phase.
avatar
mate rix@materix
avatar
Detections.ai Community
17 days ago
1013
Detects unauthorized modification or deletion of AWS Bedrock model invocation logging configurations. Adversaries may use this technique to disable visibility into LLM usage or redirect logs to an attacker-controlled storage location to hide subsequent malicious activity.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
8 days ago
101
This rule detects scenarios where a node-based package manager (npm or npx) executes an 'install' command, which is immediately followed by the spawning of unexpected child processes such as interpreters (python, powershell, cmd, wscript, cscript, mshta) or network tools (curl). This behavior is characteristic of malicious npm packages used in supply chain attacks to deliver secondary payloads like BeaverTail, InvisibleFerret, or similar threats.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
206
Detects anomalous authentication patterns where multiple distinct user identities authenticate from the same source IP (often a VPN or proxy) within a short timeframe, characteristic of North Korean IT worker laptop-farm or identity-mule operations where a single operator manages multiple contractor accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
216
Detects anomalous access to AWS Bedrock Knowledge Bases, identifying a pattern of initial reconnaissance (enumerating bases and data sources) followed by high-volume querying (Retrieve/RetrieveAndGenerate). This sequence is indicative of an attacker attempting to map out backend storage configurations and subsequently exfiltrate indexed document content.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
8 days ago
101
Detects reconnaissance and situational-awareness collection commands (e.g., tasklist, systeminfo, wmic, powershell) executed by processes matching suspected persistence artifacts associated with known malicious activity (specifically referencing potential Telegram C2 tasking). The rule monitors common discovery utilities spawned by suspicious process names or paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
006
Detects unauthorized modification or deletion of AWS Bedrock guardrails. Adversaries may delete or degrade these guardrails (lowering sensitivity to 'NONE' or 'LOW') to bypass content filters, PII redaction, and safety controls, enabling toxic output generation or data exfiltration via LLM applications.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
8 days ago
101
This rule detects the creation of a file within the SysWOW64 directory followed by an immediate modification or creation of a Windows Run registry key within a 10-minute window. This behavior is indicative of a persistence mechanism where a malicious file is dropped to a system directory and registered for execution at system startup or user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
106
Detects a coordinated malicious installation chain involving the creation of specific mutexes, establishment of persistence via Windows Registry Run keys, and subsequent tampering with Microsoft Defender exclusions using PowerShell. This sequence is indicative of the CHOSEN BRICK malware installation process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
006
Detects the use of long-lived AWS IAM access keys (AKIA) to perform critical AWS Bedrock operations such as enabling foundation model access (PutUseCaseForModelAccess, CreateFoundationModelAgreement). Such sensitive configurations are typically expected to be performed via the AWS Console using federated credentials; the use of long-lived keys for these specific actions is a strong indicator of potential compromise and unauthorized resource enablement.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
8 days ago
101
Detects execution of the CHOSEN BRICK implant (process names smdqservice.exe or winappx.exe) initiating a network connection to Telegram infrastructure (C2) followed by a network connection to a cloud object-storage provider (vultrobjects.com, storjshare.io, or backblazeb2.com) for data exfiltration within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
006
Detects instances where a privileged account (such as an administrator or helpdesk user) removes MFA security information or resets a password for a target account, followed shortly (within 4 hours) by a sign-in attempt from that same target account exhibiting risk characteristics such as impossible travel or unfamiliar features. This pattern is often associated with social engineering attacks, such as those attributed to Scattered Spider, where an attacker coerces support staff to disable MFA protections for an account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
103
Detects instances where a user account triggers a risky sign-in event (flagged by identity protection) and subsequently uses the same session or token to authenticate successfully from a different network location or IP address within two hours. This behavior suggests that a malicious actor may be leveraging a compromised session token that should have been revoked, potentially indicating a failure of continuous access evaluation or token revocation mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
003
Detects potential Adversary-in-the-Middle (AiTM) activity by identifying a successful interactive MFA-protected sign-in followed within 15 minutes by a non-interactive (refresh token) sign-in for the same user from a different IP address, ASN, or User-Agent. This pattern is indicative of session hijacking where an attacker reuses a stolen session token.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
003