Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects outbound network connections from internal devices to a set of known malicious IP addresses (217.156.122.129, 37.221.66.43) across commonly abused command-and-control ports (8080, 3480, 9998, 9999, 4444).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
205
Detects outbound network connections from internal devices to a set of known malicious IP addresses (217.156.122.129, 37.221.66.43) across commonly abused command-and-control ports (8080, 3480, 9998, 9999, 4444).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
105
Detects OtterCookie JavaScript-based RAT/infostealer malware artifacts associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
003
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
003
Detects periodic outbound network connections (beaconing) to rare remote destinations initiated by processes running from non-standard or user-writable locations. The rule calculates the interval coefficient of variation (CV) between successful connections to identify regular, consistent patterns indicative of command and control communication while excluding known legitimate update and service traffic.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
003
Detects DragonForce ransomware attempting to identify accessible SMB network shares by executing 'net view' commands. This activity is a precursor to encrypting files on reachable administrative shares (e.g., C$) while excluding system-specific shares like ADMIN$.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
304
Detects file operations (open, read, write, rename) involving common sensitive credential files (e.g., .kdbx password databases, .ovpn and .pcf configuration files, .pem, and .ssh directory contents) by processes not authorized to interact with these files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects modifications to registry keys associated with the 'ms-settings' COM object, specifically targeting the shell open command or DelegateExecute value. This technique, commonly referred to as 'ms-settings' hijacking, is used by adversaries to achieve persistence or elevated execution by redirecting legitimate COM object references to malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects modifications to registry keys associated with the 'ms-settings' COM object, specifically targeting the shell open command or DelegateExecute value. This technique, commonly referred to as 'ms-settings' hijacking, is used by adversaries to achieve persistence or elevated execution by redirecting legitimate COM object references to malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
This rule identifies potential network scanning or propagation activity by detecting a single host initiating SMB (TCP 445) connections to a high number (more than 20) of unique destination IP addresses within a given timeframe. This behavior is often indicative of internal reconnaissance, lateral movement, or worm-like propagation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
This rule detects the execution of processes that contain the command line argument 'Found sid:', which is commonly associated with security identifier (SID) enumeration or lookup tools/scripts, such as those used by security researchers or attackers during reconnaissance.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
This rule detects potentially malicious PowerShell activity executed from Windows Explorer with obfuscated arguments (-enc, -w hidden) in conjunction with access to the Windows RunMRU registry key, which tracks commands executed via the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
Detects instances where browser extensions, potentially AI-assisted (e.g., Claude, Gemini), trigger automated mail actions (send, forward, summarize) to non-standard, external domains. This behavior may indicate an unauthorized agent attempting to exfiltrate or manipulate email content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
105
Detects execution of PowerShell with a hidden window and base64-encoded command arguments that targets the file 'WindowsUpdate.log'. This pattern is associated with the CRPx0 (ClickFix) ransomware, where it attempts to drop or interact with a stager file disguised as a legitimate Windows update log file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
004
This rule detects instances where PowerShell is used to download or execute remote monitoring and management (RMM) tools or remote access software binaries (e.g., AnyDesk, TeamViewer, Atera). This pattern is often indicative of an adversary attempting to establish persistent remote access to a compromised system after initial intrusion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
104
Detects malicious manipulation of browser-based AI agents where process command-line arguments indicate an attempt to instruct the agent to access, summarize, and exfiltrate email messages from a user's webmail account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
305
This rule monitors for interactions with known malicious files (by SHA256 hash), connections to confirmed C2 infrastructure (specific IP address and domains), or requests to known malicious URLs. It aggregates indicators across file, process, network, and web browsing telemetry to identify potential threats or compromised systems communicating with known attacker infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
001
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
001
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
101
This rule detects potential malicious activity by monitoring for known indicators of compromise, including specific SHA256 file hashes, a known malicious IP address, and URLs associated with identified threats. The detection spans file creation/execution, network connections, and URL visits to block or alert on interactions with suspicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
18 days ago
001
This rule detects potential malicious activity by monitoring for known indicators of compromise, including specific SHA256 file hashes, a known malicious IP address, and URLs associated with identified threats. The detection spans file creation/execution, network connections, and URL visits to block or alert on interactions with suspicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
18 days ago
001
Page 207 of 1871