Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
16 days ago
008
This rule detects suspicious activity involving macOS LaunchAgents and files within the 'Application Support/System' directory, often associated with persistence or malicious background execution. The detection looks for the creation or modification of specific plist files (e.g., com.apple.finder.agent.plist) or git-related files in Application Support, correlated with process execution of commands like 'sysnotif-repair', 'launchctl' manipulating agents, or git operations involving custom hooks paths.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
102
This rule detects HTTP POST requests characteristic of the curlRAT malware used by DPRK-affiliated threat actors. The detection looks for a specific POST body format containing 'name=', '&value=', and '&type=' parameters, which indicates C2 communication patterns commonly associated with this specific backdoor.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects anomalous HTTP traffic directed to githubusercontent.com containing a custom, non-standard request header 'aohvcoehfg'. This pattern is associated with Kimsuky threat actor activity, specifically related to the 'GitPower' operation involving C2 communication via GitHub repositories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
The following analytic detects when all virtual machines on an ESXi host are abruptly terminated, which may indicate malicious activity such as a deliberate denial-of-service, ransomware staging, or an attempt to destroy critical workloads.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
006
This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
6 days ago
000
Detects the modification or creation of the registry key '.mollis' within Software\Classes, which is used by the Star Blizzard (RedFlick) CPL downloader to store an encrypted AES key. This activity is performed by common Windows processes such as control.exe, rundll32.exe, or regsvr32.exe.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
6 days ago
000
Detects the modification or creation of the registry key '.mollis' within Software\Classes, which is used by the Star Blizzard (RedFlick) CPL downloader to store an encrypted AES key. This activity is performed by common Windows processes such as control.exe, rundll32.exe, or regsvr32.exe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects phishing emails themed around Atlantic Council invitations that contain links attempting to lure users into installing iOS configuration profiles, often associated with malicious backdoors like DarkSword, attributed to the Star Blizzard (G1033) threat group.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects a specific multi-stage infection chain associated with Star Blizzard. The sequence begins with a command shell launched under conhost.exe executing SSH with PermitLocalCommand enabled, followed by the execution of a control panel (.cpl) file via control.exe within a two-hour window.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects credential-phishing attempts originating from Proton Mail addresses that result in a user clicking on a link. The rule correlates email delivery from known Proton Mail domains with subsequent URL click events to identify potential Adversary-in-the-Middle (AiTM) activity, often associated with the Star Blizzard (COLDRIVER) threat group.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects a multi-stage phishing pattern attributed to Star Blizzard (also known as Callisto Group or COLDRIVER). The attack involves an initial email containing no attachments to establish trust or initiate a thread, followed by a subsequent reply-thread email containing both an archive file (ZIP/RAR) and an image file. This technique is designed to bypass email security scanners by hiding the archive password within the image attachment or obscuring the malicious payload context.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects potential DNS tunneling or command-and-control (C2) traffic by identifying abnormally long DNS query names, which often indicate encoded data channels, and suspicious usage of TXT or NULL DNS records, which are frequently used by tools like Cobalt Strike, dnscat2, and iodine for C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects successful RDP (Remote Desktop Protocol) logon events (Event ID 4624, Logon Type 10) where the source IP address is outside the predefined internal network ranges. This behavior is indicative of potential lateral movement, where an attacker attempts to access internal systems from an external, non-corporate source.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000