Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects HTML files that employ FlipBook branding as a lure for password-gated smuggling. The detection identifies client-side JavaScript logic that uses PBKDF2 and AES-GCM to decrypt a hidden redirect URL after user interaction with a password prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004
Detects instances where the Redis server process or the Redis AOF check utility writes directly to common SSH authorized_keys file paths. This behavior is indicative of an attacker exploiting a Redis misconfiguration or vulnerability (e.g., Redis RCE) to establish persistence by injecting an unauthorized SSH key.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004
This rule detects potential exploitation of CVE-2026-86134, a NULL pointer dereference vulnerability in WatchGuard Fireware. It identifies a burst of authentication-related requests (login, authd, management) targeting a device, followed by system logs indicating a service crash, daemon restart, or core dump within a short correlation window. This behavior is indicative of a Denial of Service attack.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
6 days ago
000
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
204
Detects anomalous post-authentication reconnaissance activities against the Microsoft Graph API, specifically the enumeration of directory objects, roles, or service principals. The rule triggers when a user account performs multi-endpoint enumeration via the Graph API within 30 minutes of a successful authentication session initiated via a device code flow that was flagged with elevated risk signals. This behavior is consistent with post-compromise reconnaissance techniques such as 'EvilTokens', where an adversary attempts to map the environment after gaining access.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
204
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
16 days ago
008
This rule detects suspicious activity involving macOS LaunchAgents and files within the 'Application Support/System' directory, often associated with persistence or malicious background execution. The detection looks for the creation or modification of specific plist files (e.g., com.apple.finder.agent.plist) or git-related files in Application Support, correlated with process execution of commands like 'sysnotif-repair', 'launchctl' manipulating agents, or git operations involving custom hooks paths.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
102
This rule detects HTTP POST requests characteristic of the curlRAT malware used by DPRK-affiliated threat actors. The detection looks for a specific POST body format containing 'name=', '&value=', and '&type=' parameters, which indicates C2 communication patterns commonly associated with this specific backdoor.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects anomalous HTTP traffic directed to githubusercontent.com containing a custom, non-standard request header 'aohvcoehfg'. This pattern is associated with Kimsuky threat actor activity, specifically related to the 'GitPower' operation involving C2 communication via GitHub repositories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
The following analytic detects when all virtual machines on an ESXi host are abruptly terminated, which may indicate malicious activity such as a deliberate denial-of-service, ransomware staging, or an attempt to destroy critical workloads.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
006