Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
102
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
902
This rule performs a point-in-time sweep for known Indicators of Compromise (IOCs) associated with the NeedyMantis threat actor group. The detection logic searches for specific file, process, and image-load SHA256 hashes, communication with a known C2 domain (tripswithengine.com), and the use of a hard-coded user-agent string (Firefox/21.0) across various telemetry sources within the last 30 days.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
10 days ago
104
Detects the two Windows-networking-named DLLs the report confirms as sideloaded via the normal OS loader (WinSparkle.dll, libcurl.dll) plus vim64.dll (a filename Vim's real installer never produces at all). Path check now covers any location outside a small allowlist of known-legitimate vendor install folders, not just ProgramData, so it also catches the reported ProgramData\\USOShared, ProgramData\\VIM, and ProgramData\\TightVNC\\VIM placements. Known limitation: the one reported case where the malicious WinSparkle.dll sits at the exact canonical Program Files\\Poedit path cannot be distinguished by path alone -- that specific sideload is instead caught by the companion 'Extensionless Archive Paired with Same-Named DLL Drop' rule via the archive-pairing signal.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
10 days ago
214
Detects the execution of discovery or credential access utilities (e.g., whoami, net, reg, ldapsearch) spawned by Java-based server processes like java.exe or tomcat.exe. This activity is often indicative of an attacker leveraging a vulnerable web application to perform reconnaissance or credential harvesting on the host system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
102
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
002
Detects permanent WMI event subscriptions that are containing `CommandLineEventConsumer` or `ActiveScriptEventConsumer`. Due to their command execution capabilties, given WMI consumers are often leveraged by adversaries for both execution and persistence purposes.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
203
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
103
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
103
Detects unauthorized processes attempting to read or create sensitive browser credential files ('Login Data', 'Web Data', 'Cookies', 'logins.json', 'key4.db'). This activity is commonly associated with information-stealing malware (such as Lumma, StealC, Vidar, RedLine, and Amadey) that targets browser databases to extract stored secrets, often bypassing standard browser process access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
105
Detects a potential post-compromise lateral movement sequence where a host, previously identified as accessing sensitive browser credential files by an unauthorized process, subsequently initiates RDP or WinRM connections to other internal hosts using an account not previously observed performing interactive logons on that source host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Detects unauthorized access or modification attempts to common web browser credential storage files (such as 'Login Data' or 'key4.db') by processes other than standard, trusted web browsers (e.g., Chrome, Edge, Firefox). This behavior is indicative of credential harvesting, where an adversary attempts to steal saved login information from browser data stores.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Detects instances where a user account associated with a detected infostealer malware infection (e.g., Redline, Raccoon, Vidar) successfully authenticates to a cloud service from a suspicious network location, such as a VPN, residential proxy, or Tor exit node, within 24 hours of the infection alert.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Detects access to sensitive browser credential and cookie files by processes that are not recognized web browsers or their designated update components. This behavior is highly indicative of credential theft activity where an adversary is attempting to extract stored credentials or session cookies from local browser storage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
302
Detects instances where the Windows Terminal application (or related processes like OpenConsole) spawns suspicious command-line utilities such as PowerShell, CMD, curl, or certutil with indicators of potential download activity or command-line obfuscation. This pattern is often indicative of interactive adversary activity attempting to stage tools or execute payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
902
Detects execution of common script interpreters (mshta, powershell, cmd, wscript) from typical UI-based process launch sources (explorer, RunDlg) when the command line includes indicators of malicious activity such as hidden window flags, obfuscated content, or remote URL downloads. This pattern is characteristic of ClickFix-style social engineering attacks where users are tricked into copying and executing malicious commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
502
Detects unauthorized access by a non-browser process to Chromium-based 'Cookies' SQLite database files, which are used by browsers like Chrome, Edge, and Brave. This behavior is a strong indicator of credential theft or session hijacking, as attackers target these files to extract session cookies and bypass MFA for cloud services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
002
This rule detects the suspicious archival of browser credential files (e.g., Login Data, Cookies, wallet.dat) or the transmission of data to common command-and-control (C2) services such as Telegram, Discord, or raw IP addresses using common system tools like PowerShell, curl, or certutil.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
102
Page 19 of 1866