Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects AvisLoader Windows loader requiring both decoy non-executable packer-named sections and an embedded c-toxcore developer build path to co-occur in a valid PE
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
000
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
000
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
000
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
000
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
000
Detects outbound HTTP requests to identified scam infrastructure (e.g., herokuapp domains) containing platform-specific query parameters (win or mac). This behavior is indicative of a user interacting with a malicious site that is delivering an OS-tailored locker or malware payload.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
000
Detects outbound HTTP requests to identified scam infrastructure (e.g., herokuapp domains) containing platform-specific query parameters (win or mac). This behavior is indicative of a user interacting with a malicious site that is delivering an OS-tailored locker or malware payload.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
000
Detects endpoint network connections to Heroku-hosted domains containing Google Ads tracking parameters (gclid, gad_source, gad_campaignid). This activity is associated with the initial staging phase of 'ShopEase' style malware delivery chains, where users are directed to decoy pages that prepare the environment for subsequent malicious browser-based actions.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
000
Detects outbound HTTP requests to identified scam infrastructure (e.g., herokuapp domains) containing platform-specific query parameters (win or mac). This behavior is indicative of a user interacting with a malicious site that is delivering an OS-tailored locker or malware payload.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
Detects endpoint network connections to Heroku-hosted domains containing Google Ads tracking parameters (gclid, gad_source, gad_campaignid). This activity is associated with the initial staging phase of 'ShopEase' style malware delivery chains, where users are directed to decoy pages that prepare the environment for subsequent malicious browser-based actions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
000
Detects anomalous, rapid execution of a high volume of diverse offensive security tools (scanners, exploitation frameworks, and C2 agents) from a single parent process within a short window, which is characteristic of automated LLM-driven orchestration or scripted attack tool chaining.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects outbound HTTPS connections to major generative AI inference endpoints originating from non-browser, non-development tool processes at regular intervals. This activity is indicative of beaconing behavior, where malware (specifically families like LAMEHUG) leverages LLM APIs for dynamic command generation, payload obfuscation, or C2 instruction retrieval, bypassing traditional security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects coordinated activity patterns across multiple distinct tenant environments within a one-hour window. The rule looks for shared infrastructure (C2 domains), malicious tool hashes, or specific agentic-CLI command line signatures (e.g., related to orchestration, reconnaissance, or exfiltration) that suggest an AI-orchestrated actor or automated attack campaign affecting multiple organizations simultaneously.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects the execution of common remote monitoring and management (RMM) software on a host shortly after the associated user account underwent a password or MFA reset, a pattern indicative of help-desk impersonation (vishing) followed by unauthorized remote access setup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
000
Detects malformed HEIF/HEIC image files with anomalous ftyp/box structure consistent with the libheif memory corruption exploit (CVE-2026-32882) used against Discourse forum image upload endpoints
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
003
This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
103
This rule detects network connections to domains and IP addresses associated with known malicious TLS CA infrastructure (TLC DV TLS CA) identified by JA4X fingerprints. It monitors endpoint network telemetry for communication with identified command-and-control (C2) servers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
005
Detects the creation or modification of Registry keys within 'Image File Execution Options' (IFEO) intended to associate a debugger with security-critical or monitoring binaries (e.g., Sysmon, Filebeat). This technique is used for defense evasion and persistence by intercepting or preventing the execution of security tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects attempts to terminate or delete security-related services and logging agents, such as Sysmon, Filebeat, and various endpoint protection agents, using legitimate Windows system utilities like taskkill, sc, or wmic.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Detects modifications to the creation time of web-accessible script files (.aspx, .php, .asp, .jsp) located in common web directories (wwwroot, inetpub). Adversaries often use timestomping to hide the creation of backdoored web shells, making them appear older and potentially bypassing forensic or integrity-checking mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
001
Page 202 of 1871