Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects browser-side network activity involving known command-and-control or subscription API domains associated with a malicious VPN browser extension proxy campaign. The rule monitors for beaconing behavior from popular web browsers (Chrome, Edge, Brave) to specific domains utilized by the campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects network traffic attempting to connect to known proxy farm fallback hostnames using TLS SNI or HTTP CONNECT methods. These hostnames are often associated with command-and-control infrastructure designed to proxy traffic and mask the true destination of communications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
004
Detects network connection attempts to known typosquatted domains (thecovnresation.com/net) commonly associated with the CLEANGULP malware beaconing activity, specifically targeting the /beacon/pre-register URI path.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
004
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
004
Flags conditional access policy edits (MFA exclusions, trusted-location additions) occurring shortly after a support-desk-driven identity reset on the same tenant/admin account — the step attackers use to lock in access after a vishing-driven MFA bypass.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
203
Joins password reset events to subsequent legacy-protocol (IMAP/POP/SMTP/ActiveSync) or non-interactive sign-ins for the same user, catching attackers who pivot to less-monitored protocols immediately after a vished self-service reset.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
303
Flags MFA method deletions performed by an actor other than the account owner, especially when followed by registration of a new authenticator — the signature of a helpdesk agent socially engineered into swapping a victim's MFA factor.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
203
Sequence detection for the three-step chain — credential reset, MFA/authenticator reset, new device registration — completing within 40 minutes for one user, directly modeling the Scattered Spider/UNC3944 speed-to-domain-admin playbook from Mandiant M-Trends 2026.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
203
Flags Temporary Access Pass issuance to accounts holding privileged directory roles, especially when issued by Tier-1 support rather than a PIM-approved workflow — TAP is the modern equivalent of the helpdesk MFA bypass abused in Scattered Spider-style intrusions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
203
Flags FIDO2/passkey registrations initiated or facilitated by a helpdesk/support identity for another user's account, matching Okta's advisory on threat actor O-UNC-066 ('Pink' leak site) and the ShinyHunters O-UNC-037 campaign that mimicked Microsoft's passkey enrollment flow to register attacker-controlled passkeys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
203
Detects evidence of a SharePoint pre-authentication RCE exploit chain where an adversary injects a malicious Namespace containing an ExpandedWrapper-wrapped XamlServices payload (e.g., ObjectDataProvider or LosFormatter gadget) into the w3wp.exe worker process. This specifically looks for command-line arguments indicative of deserialization-based exploit attempts targeting SharePoint web server components.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
405
This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
6 days ago
000
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
6 days ago
000
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
6 days ago
000
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects anomalous, bulk file access activity targeting browser credential databases, cryptocurrency wallet data, and application-specific configuration stores, characteristic of the SectopRAT 'DeployBrowserKey' command.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects the execution of RatHat, a Go-based Android native daemon masquerading as 'liblocal-service.so'. The rule identifies the malware's use of ADB-derived shell commands to bypass Android Doze mode, prioritize background execution, and tamper with installed applications via pm (package manager) commands.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000