Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
Detects anomalous, bulk file access activity targeting browser credential databases, cryptocurrency wallet data, and application-specific configuration stores, characteristic of the SectopRAT 'DeployBrowserKey' command.
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
Detects the execution of RatHat, a Go-based Android native daemon masquerading as 'liblocal-service.so'. The rule identifies the malware's use of ADB-derived shell commands to bypass Android Doze mode, prioritize background execution, and tamper with installed applications via pm (package manager) commands.
Detects the specific command-line sequence used by SectopRAT for self-deletion. The malware uses 'choice' to create a delay followed by a 'del' command to remove its own executable, a technique for deleting files after the process has terminated.
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
This rule detects the suspicious pattern of a process reading a 'pool.db' file followed immediately by the loading of .NET Common Language Runtime (CLR) modules (clr.dll or mscoreei.dll). This behavior is characteristic of fileless execution chains where a secondary payload is retrieved and executed directly in memory.
Detects the SectopRAT shellcode execution stage by identifying the concurrent access of a specific encrypted database file (Activation.Desktop.db) and the loading of a malicious DLL (stp_aim_x64_vc15.dll) on the same device within a 5-minute window. This behavior suggests the decryption and execution of shellcode via DLL callback abuse.
Detects the ReportDump.exe process initiating a network connection on port 15847 followed by the loading of GDI/User32 libraries shortly thereafter. This behavior is indicative of SectopRAT establishing a command-and-control channel and initializing screen capture capabilities.
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
Detects instances where common AI agent orchestration runtimes (e.g., LangChain, AutoGPT, CrewAI) spawn command-line or scripting interpreters as child processes. This behavior is highly suspicious and often indicative of malicious command execution triggered by prompt injection attacks, where an adversary manipulates the agent into executing arbitrary system commands.
This rule detects the installation of common AI agent and orchestration frameworks (e.g., LangChain, AutoGen, CrewAI) using command-line package managers (pip, npm, conda) that point to non-standard or unverified package indexes. This behavior is a common indicator of a potential software supply-chain compromise, where an adversary attempts to inject malicious code by forcing the installation of packages from an attacker-controlled source.
Detects command-line operations indicative of bulk data export, dumping, or unauthorized scanning against vector databases (e.g., Pinecone, Chroma, Milvus, Qdrant) and caching backends (e.g., Redis). Such activities may indicate an adversary attempting to exfiltrate training data, embeddings, or context stored within an AI agent's memory backend.
Detects scenarios where common download utilities are used to fetch a file from the internet, followed by the immediate execution or loading of that same file within a 10-minute window, indicative of an Ingress Tool Transfer followed by execution.
Detects anomalous, high-volume enumeration activity (List/Get/Read operations) performed by a single identity across multiple Azure resource providers within a short time window, indicative of automated reconnaissance by a compromised service principal or managed identity.
Detects suspicious process activity or file access patterns originating from within a container that indicate an attempt to escape to the host. This includes monitoring for the use of tools like nsenter, unshare, and mount, attempts to interact with the docker.sock, or attempts to access critical host paths like /proc/1/root or /host/etc, excluding events originating from authorized container management processes.
This rule detects automated browser-based processes (such as chromedriver, msedgedriver, geckodriver, playwright, or node/python scripts leveraging browser automation frameworks) initiating network connections to domains or URLs identified in active threat intelligence as malicious. This behavior is indicative of an AI agent or automated script being steered toward attacker-controlled infrastructure, potentially for drive-by compromise or exploitation.


