Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
000
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
000
Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
109
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
508
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
17 days ago
101
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
17 days ago
001
Detects instances where a single process on a device communicates with two or more distinct hosted LLM provider APIs (OpenAI, Anthropic, DeepSeek, Google) within a 24-hour window. This behavior is indicative of multi-model orchestration or 'consensus' techniques, which may be employed by sophisticated implants for automated tasking, data processing, or evasion.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
17 days ago
001
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
203
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
003
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
003
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
103
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
103
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
103
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
003
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
203
Detects the execution of 'vsdbg.exe' or 'vsdbg.dll' from locations outside of the legitimate Microsoft Visual Studio installation directories. This behavior is indicative of potentially malicious usage of the Visual Studio debugger components for process injection or evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
003
Detects the loading of 'clr.dll' and 'System.Management.Automation.dll' (or related variants) by a process that is not a known PowerShell host. This behavior is indicative of a 'PSInline' execution technique, where an attacker leverages COM or direct assembly loading to execute PowerShell scripts or commands within a benign or malicious process to avoid spawning explicit powershell.exe processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
003
Detects the loading or execution of known SloppyRAT DLL samples. This malware is identified for its implementation of Hell's Gate-style indirect syscalls, utilizing techniques such as DJB2 API hashing and NTDLL stub parsing to evade EDR hooks. The rule monitors for specific file hashes and potential masquerading behaviors (e.g., hostfxr.dll) across image loading, file, and process events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
003
Detects anomalous network connections initiated by a node.exe process spawned by npm.exe within 2 minutes of a lifecycle script (preinstall or postinstall) execution. This behavior is indicative of malicious dependency installation where a compromised package attempts to exfiltrate data or fetch additional payloads immediately upon installation.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
004
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
004
Detects the creation of a scheduled task containing the string 'Google Chrome Update' in the command line, where the task is not the legitimate 'GoogleUpdateTaskMachine' task. The rule specifically targets tasks that execute PowerShell or arbitrary executables, which is a common persistence technique used by adversaries to mask malicious tasks as legitimate software updates.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
105
Page 197 of 1871