Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
101
This rule monitors for the creation of known Neo-reGeorg web shell files ('tunnel.jsp', 'tunnel.jspx') within common web server directory paths, such as 'webapps', 'applications', 'wlserver', 'PSHTTP', 'PORTAL', or 'webserv'. Neo-reGeorg is a popular tunneling web shell used by adversaries to facilitate persistent access and proxy traffic into a compromised environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects the execution of the SIDEEYE backdoor (Ple64.exe) when it is spawned by web-based processes such as Java (WebLogic) or shell interpreters (cmd.exe/powershell.exe) invoked by web-based parents. This behavior is indicative of a web shell exploitation attempt.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
001
Detects a sequence of Tox P2P protocol packets consisting of a Cookie Request, Cookie Response, and Crypto Handshake within a single network flow. This pattern is indicative of the Tox P2P protocol, which is sometimes abused by malware (e.g., AvisLoader) for command-and-control (C2) communications to evade traditional network inspection.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
002
Detects network traffic attempting to exploit CVE-2021-33044, an authentication bypass vulnerability in Dahua NetKeyboard devices, by identifying specific login request strings used in the exploit chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
008
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
002
This rule detects a sequential multi-stage execution chain starting with msiexec.exe launching a hidden PowerShell script, followed by wscript.exe executing a VBScript agent, and finally node.exe executing a JavaScript file within a short time window. This pattern is indicative of a complex, multi-stage dropper or malware execution flow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects the loading of a known malicious 136KB browser injection helper DLL (SHA256: 75018b06c7105a1dca391805d17b402aed35ebd515b92d461236eafbd606cb40) into Google Chrome or Microsoft Edge processes. The rule further correlates this activity with command line arguments indicative of abusing the browser's elevation service, which is a technique often used for process injection or local privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects the deletion of Chrome registry keys related to extension integrity verification. This behavior is often associated with browser-based attacks, such as malware or malicious extensions attempting to tamper with browser security configurations to enable persistent browser hijacking or unauthorized extension modification.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
305
Detects the ChainScript RAT agent (executing as node.exe from specific masquerading directory paths) scanning for and enumerating cryptocurrency wallet files, browser-stored wallet extensions, and related sensitive configuration data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
205
Detects the execution of MSI installers from user-writable directories (e.g., Downloads, Temp, Public) that masquerade as legitimate software applications like Spotify, Zoom, or Microsoft Teams. This behavior is indicative of 'ClickFix' style social engineering lures, where users are prompted to download and execute malicious installers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
105
Detects the installation of a Windows service that mimics the legitimate NVIDIA File System Filter Driver (NvFsFilter). Adversaries, such as those associated with the Rapuncel infostealer, use this technique to establish persistence and evade security controls by masquerading as a common driver component.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
205
Detects HTTP proxy requests for ZIP archives where the Referer header indicates a navigation originated from a GitHub Pages (github.io) site, but the destination is not a GitHub domain. This behavior is indicative of a multi-hop redirect chain used in campaigns to deliver malicious payloads, such as infostealers, by abusing GitHub Pages to redirect users to external hosting for ZIP archive downloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects the loading of the malicious NvFsFilter driver (a BYOVD technique often used by the Rapuncel infostealer) followed immediately by a mass burst of process terminations, indicating an attempt to disable security software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects a suspected social engineering attack chain where a user communicates with a recruiter via messaging apps or browsers, subsequently clones or installs a malicious repository using 'npm' or 'VS Code', and triggers suspicious child process activity from 'node.exe'. This pattern is associated with the WaterPlum campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects Node.js or Python processes exhibiting behavior characteristic of information-stealing malware (such as the WaterPlum suite: BeaverTail, InvisibleFerret, OtterCookie, StoatWaffle). The rule monitors for these processes accessing sensitive files related to browser credentials, cryptocurrency wallets, scanned identification documents, or performing collection activities like keylogging and screen capturing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects user authentication events to recruitment, career, or applicant-tracking applications where the connection originates from an anonymizing proxy, VPN, or datacenter IP address. This behavior has been observed as a precursor to North Korean IT worker recruitment fraud, where attackers mask their true geographic location to gain unauthorized employment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
105
No description available.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects a specific behavioral chain associated with the CHOSEN BRICK implant. This rule identifies when a suspected malicious process writes image/screenshot files (.png, .jpg, .bmp) to disk, followed by a network connection to the Telegram Bot API within a 15-minute window, suggesting potential data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
This rule detects artifacts and behaviors associated with the WaterPlum/Contagious Interview (also known as DeceptiveDevelopment) malware suite, including BeaverTail, InvisibleFerret, and related payloads. The rule specifically targets the presence of embedded family-name strings, as well as the execution of suspicious npm package installations triggered by VS Code task automation (tasks.json) or trust prompts, common in fake technical interview attack scenarios.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002