Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects a multi-stage phishing pattern attributed to Star Blizzard (also known as Callisto Group or COLDRIVER). The attack involves an initial email containing no attachments to establish trust or initiate a thread, followed by a subsequent reply-thread email containing both an archive file (ZIP/RAR) and an image file. This technique is designed to bypass email security scanners by hiding the archive password within the image attachment or obscuring the malicious payload context.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects potential DNS tunneling or command-and-control (C2) traffic by identifying abnormally long DNS query names, which often indicate encoded data channels, and suspicious usage of TXT or NULL DNS records, which are frequently used by tools like Cobalt Strike, dnscat2, and iodine for C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects successful RDP (Remote Desktop Protocol) logon events (Event ID 4624, Logon Type 10) where the source IP address is outside the predefined internal network ranges. This behavior is indicative of potential lateral movement, where an attacker attempts to access internal systems from an external, non-corporate source.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects HTTP redirect chains originating from common webmail providers to URLs containing suspicious login-related keywords or obfuscated brand look-alike domains, which is indicative of credential harvesting or phishing activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects Log4Shell (CVE-2021-44228) exploitation attempts by identifying JNDI lookup patterns (e.g., ldap://, rmi://, dns://) and common obfuscation techniques within HTTP headers, user-agents, and query parameters, which could lead to remote code execution.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized processes requesting memory access to lsass.exe with read permissions commonly associated with credential dumping techniques like Mimikatz. It identifies remote handle requests to lsass.exe, which are frequently used by tools deployed via network services or remote execution methods to extract credentials from memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects a high volume of failed SSH password authentication attempts from a single source IP address against one or more target hosts within a short time window, which is indicative of an SSH brute-force attack.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects Android device management (MDM) components (specifically 'com.corp.mdm') re-launching registration or sticky services upon system events such as boot completion, quick-boot, or package updates. This monitoring is intended to identify persistent components that maintain functionality across device restarts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
Detects unauthorized or suspicious use of USSD codes by the corporate MDM agent to modify call-forwarding settings. This activity is indicative of a compromise where an attacker uses an MDM-controlled device to intercept calls or divert communications.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
KQL Query from file: HBO Max PasteSwitch IOC Detected
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
14044
Detects the addition of new members to a GitHub organization or team outside of standard business hours. This behavior is correlated with potential subsequent grants of repository administrative access or read access to secrets, characteristic of attacker patterns attempting to gain unauthorized access to cloud environments and OAuth tokens via CI/CD pipelines or VCS platforms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a single Salesforce user or connected-app session performing an anomalous volume of SOQL queries against sensitive objects including Case, Account, Contact, and Opportunity. This behavior is indicative of mass data enumeration and potential exfiltration, as observed in historical incidents where attackers targeted CRM platforms to extract embedded secrets and sensitive record data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects OAuth application consent events in Entra ID where the application display name mimics legitimate services like Salesforce or Data Loader while requesting high-risk API scopes (full_access, offline_access, api). This behavior is characteristic of phishing-driven OAuth grant campaigns, such as those observed by the ShinyHunters group.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Monitors SaaS application integration service accounts (e.g., Salesforce connected apps) by establishing baselines for API call volume and accessed object types. The rule alerts on anomalous spikes in usage or deviations in the scope of accessed data objects, which could indicate the abuse of compromised OAuth tokens following a vendor supply-chain compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous anti-forensic behavior where a Salesforce Bulk API query job is deleted shortly after its creation or completion. This sequence is often associated with efforts to obscure data exfiltration activities by removing the metadata trail of bulk data exports.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous Salesforce API export patterns where a user or connected application maintains a daily record export volume below typical burst thresholds, yet accumulates a high total volume over a rolling 7-day period. This pattern mimics 'low-and-slow' data exfiltration techniques used by actors like ShinyHunters to evade standard volume-based DLP alerts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects the use of native Windows administration utilities (vssadmin, wbadmin, bcdedit, wmic) to delete volume shadow copies, backup catalogs, or disable system recovery configurations. The rule specifically monitors for patterns where these commands are executed across multiple hosts or in rapid succession by the same account, behavior frequently observed during the precursor stages of ransomware deployment, such as the ShinyHunters ShinySp1d3r campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects an Android device registration attempt to a known malicious C2 IP address using parameters characteristic of a mobile device management (MDM) implant. The rule looks for a POST request to a specific registration endpoint containing device identifiers like deviceId, manufacturer, model, and osVersion.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
Detects Salesforce Experience Cloud guest user sessions performing queries or reads on objects not within the authorized allowlist. This behavior, characterized by an abnormal volume of records retrieved or anomalous query patterns, is consistent with attempts to exploit misconfigured guest profile permissions to access internal sensitive data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous large-scale data export operations in Google BigQuery (via jobs.insert or jobs.query) performed by identities (service accounts, API keys) not previously observed in the environment. This activity is indicative of credential abuse where stolen third-party analytics or monitoring service tokens are utilized for illicit data exfiltration, a behavior consistent with tactics employed by threat actors such as ShinyHunters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous large-scale data export operations in Google BigQuery (via jobs.insert or jobs.query) performed by identities (service accounts, API keys) not previously observed in the environment. This activity is indicative of credential abuse where stolen third-party analytics or monitoring service tokens are utilized for illicit data exfiltration, a behavior consistent with tactics employed by threat actors such as ShinyHunters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000