Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects high-risk GitHub events indicating data or asset exposure, such as creating public repositories with specific naming conventions, changing private repositories to public, or creating new gists, which could indicate exfiltration of sensitive assets or information.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects a suspicious pattern where an AI coding agent or user creates a public GitHub repository with specific naming conventions (e.g., 'sweeper-demo', 'gitshot-images') and subsequently pushes content containing sensitive terms like 'screenshot' within a short timeframe. This behavior is indicative of potential data exfiltration of internal development screenshots to a public repository.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects the creation or exposure of public repositories, releases, or gists under a personal GitHub account that utilize naming conventions associated with the 'PixelLeak' workaround. This technique allows adversaries to make previously private screenshots, recordings, or internal assets publicly accessible by hosting them in public personal repositories or releases.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects sign-in attempts originating from IP address ranges known to be utilized by the TeamFiltration tool for password spraying operations against Azure environments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
6 days ago
000
Detects HTTP POST requests directed at Grav CMS endpoints where the __unique_form_id__ parameter contains directory traversal sequences (e.g., ../). This behavior is indicative of attempted exploitation of CVE-2026-42608, aimed at bypassing file system restrictions to write files to unauthorized locations outside the application's expected form data directory.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
002
Detects HTTP POST requests directed at Grav CMS endpoints where the __unique_form_id__ parameter contains directory traversal sequences (e.g., ../). This behavior is indicative of attempted exploitation of CVE-2026-42608, aimed at bypassing file system restrictions to write files to unauthorized locations outside the application's expected form data directory.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
002
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
8 days ago
001
This rule detects malicious HTTP POST requests attempting a path traversal attack against Grav CMS, specifically targeting the __unique_form_id__ parameter. The rule looks for directory traversal sequences ('..') following the parameter, which is characteristic of attempts to read sensitive files outside the intended web directory.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
002
This rule detects malicious HTTP POST requests attempting a path traversal attack against Grav CMS, specifically targeting the __unique_form_id__ parameter. The rule looks for directory traversal sequences ('..') following the parameter, which is characteristic of attempts to read sensitive files outside the intended web directory.
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
002
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
002
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
002
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
002