Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
Detects rapid mass-cloning or downloading of private GitHub repositories shortly after an OAuth token authorization, originating from IP addresses or countries not previously associated with the user account. This behavior is indicative of unauthorized bulk data extraction using compromised credentials, consistent with threat actor activity (e.g., TeamPCP/UNC6780).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
0011
Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
This rule monitors for the creation of known Neo-reGeorg web shell files ('tunnel.jsp', 'tunnel.jspx') within common web server directory paths, such as 'webapps', 'applications', 'wlserver', 'PSHTTP', 'PORTAL', or 'webserv'. Neo-reGeorg is a popular tunneling web shell used by adversaries to facilitate persistent access and proxy traffic into a compromised environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects the execution of the SIDEEYE backdoor (Ple64.exe) when it is spawned by web-based processes such as Java (WebLogic) or shell interpreters (cmd.exe/powershell.exe) invoked by web-based parents. This behavior is indicative of a web shell exploitation attempt.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects a sequence of Tox P2P protocol packets consisting of a Cookie Request, Cookie Response, and Crypto Handshake within a single network flow. This pattern is indicative of the Tox P2P protocol, which is sometimes abused by malware (e.g., AvisLoader) for command-and-control (C2) communications to evade traditional network inspection.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
002