Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
102
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
002
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
002
This rule detects a correlation between the creation or modification of a specific file name ('nloemfbihmhm') and the subsequent execution of processes from the 'Temp' directory involving related filenames ('kojuyn.ini', 'ogftogcyiblzjccmcbnw.exe', or 'nloemfbihmhm') within a 5-minute window. This behavior is indicative of a multi-stage execution chain, often used by malware to drop and execute secondary payloads.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detection & Hunting Community
25 days ago
3010
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
002
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
102
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
102
Detects the execution of the AnyDesk installer when triggered by a process spawned from common web browsers. This pattern is often observed when users download and execute remote access software from the internet.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects instances where the AnyDesk remote support application initiates a Windows command shell (cmd.exe) or executes a batch (.bat) file. This behavior is often associated with remote access tools being used to execute arbitrary commands on a target system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
102
Detects successful user logins to accounts with names containing support-related terminology such as 'IT Support', 'Help Desk', or 'IT Department'. These accounts are often highly privileged or sensitive targets for credential abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
This rule monitors for the installation of the 'indexed-btree' JavaScript package via common package managers (npm, yarn, pnpm) or its presence within a 'node_modules' directory. This specific package has been associated with supply chain attacks where malicious code is embedded within dependencies to compromise build systems or environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects instances where the RemoteApp Gateway broker process (wkspbroker.exe) loads the 'radcui.dll' module from the 'AppData\Local\Microsoft\RemoteApp\Gateway' directory. This behavior, especially when accompanied by configuration artifacts like 'config.json' or 'comsrv.dat' in the same path, is indicative of potential DLL side-loading or application hijacking, as these components are typically expected to reside in system-protected directories rather than user-writable local paths.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects a suspicious Node.js process pattern characterized by the execution of 'sharedLoad.min.js' or detached child processes, followed by rapid outbound network communication to known messaging platforms (Slack, Telegram). This behavior is indicative of the indexed-btree malware family, which exfiltrates host fingerprint data including architecture, hostname, and system metrics.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects instances where node.js or npm processes spawn child processes that subsequently perform write operations into Windows startup folders or registry run keys within a one-hour window. This behavior is indicative of a second-stage payload execution and persistence mechanism often leveraged by threat actors.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the execution of a specific batch file named 'KB85809588.bat', either directly or via the Windows Command Shell (cmd.exe) and Console Host (conhost.exe). This pattern is often indicative of malicious scripts or automated tasks executed as part of an attack chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the modification or creation of COM InProcServer32 registry keys within HKCU or HKU hives where the associated server value points to a DLL located in the AppData directory. This pattern is commonly used for persistence and privilege escalation via COM hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
102
This rule detects the presence of the malicious indexed-btree npm package by searching for its obfuscated runtime loader triggered via BTree.prototype.set. The malware attempts to spawn a detached Node.js process to execute a secondary payload (sharedLoad.min.js) instead of relying on standard installation scripts, allowing it to maintain persistence and bypass simple static analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects modifications to the 'InProcServer32' registry key within HKCU\Software\Classes\CLSID. This activity, which involves pointing a CLSID to a library file located in non-standard user-writable directories (like AppData), is a common technique for COM object hijacking used to achieve persistence or code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
Detects the execution of AnyDesk shortly after a Microsoft Teams meeting or call initiation on the same host. This pattern is commonly observed in social engineering attacks where an adversary convinces a user to use remote access software during a live support or phishing call.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
002
This rule monitors for network connections, firewall traffic, and Entra ID authentication events involving known malicious IP addresses (the 'Wall of Shame'). The rule specifically flags interactions occurring over common VPN ports, suggesting potential unauthorized access or persistence attempts via VPN services.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
27 days ago
9017
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
104
Page 194 of 1871