Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
6 days ago
000
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
6 days ago
000
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
6 days ago
000
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects anomalous, bulk file access activity targeting browser credential databases, cryptocurrency wallet data, and application-specific configuration stores, characteristic of the SectopRAT 'DeployBrowserKey' command.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects the execution of RatHat, a Go-based Android native daemon masquerading as 'liblocal-service.so'. The rule identifies the malware's use of ADB-derived shell commands to bypass Android Doze mode, prioritize background execution, and tamper with installed applications via pm (package manager) commands.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects the specific command-line sequence used by SectopRAT for self-deletion. The malware uses 'choice' to create a delay followed by a 'del' command to remove its own executable, a technique for deleting files after the process has terminated.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
This rule detects the suspicious pattern of a process reading a 'pool.db' file followed immediately by the loading of .NET Common Language Runtime (CLR) modules (clr.dll or mscoreei.dll). This behavior is characteristic of fileless execution chains where a secondary payload is retrieved and executed directly in memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects the SectopRAT shellcode execution stage by identifying the concurrent access of a specific encrypted database file (Activation.Desktop.db) and the loading of a malicious DLL (stp_aim_x64_vc15.dll) on the same device within a 5-minute window. This behavior suggests the decryption and execution of shellcode via DLL callback abuse.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects the ReportDump.exe process initiating a network connection on port 15847 followed by the loading of GDI/User32 libraries shortly thereafter. This behavior is indicative of SectopRAT establishing a command-and-control channel and initializing screen capture capabilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
1010
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
307
Detects instances where common AI agent orchestration runtimes (e.g., LangChain, AutoGPT, CrewAI) spawn command-line or scripting interpreters as child processes. This behavior is highly suspicious and often indicative of malicious command execution triggered by prompt injection attacks, where an adversary manipulates the agent into executing arbitrary system commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects the installation of common AI agent and orchestration frameworks (e.g., LangChain, AutoGen, CrewAI) using command-line package managers (pip, npm, conda) that point to non-standard or unverified package indexes. This behavior is a common indicator of a potential software supply-chain compromise, where an adversary attempts to inject malicious code by forcing the installation of packages from an attacker-controlled source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects command-line operations indicative of bulk data export, dumping, or unauthorized scanning against vector databases (e.g., Pinecone, Chroma, Milvus, Qdrant) and caching backends (e.g., Redis). Such activities may indicate an adversary attempting to exfiltrate training data, embeddings, or context stored within an AI agent's memory backend.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects scenarios where common download utilities are used to fetch a file from the internet, followed by the immediate execution or loading of that same file within a 10-minute window, indicative of an Ingress Tool Transfer followed by execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous, high-volume enumeration activity (List/Get/Read operations) performed by a single identity across multiple Azure resource providers within a short time window, indicative of automated reconnaissance by a compromised service principal or managed identity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects suspicious process activity or file access patterns originating from within a container that indicate an attempt to escape to the host. This includes monitoring for the use of tools like nsenter, unshare, and mount, attempts to interact with the docker.sock, or attempts to access critical host paths like /proc/1/root or /host/etc, excluding events originating from authorized container management processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
This rule detects automated browser-based processes (such as chromedriver, msedgedriver, geckodriver, playwright, or node/python scripts leveraging browser automation frameworks) initiating network connections to domains or URLs identified in active threat intelligence as malicious. This behavior is indicative of an AI agent or automated script being steered toward attacker-controlled infrastructure, potentially for drive-by compromise or exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000