Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects the execution of PowerShell via a shortcut (.lnk) file that attempts to download and execute remote content using 'Invoke-WebRequest'. The command lines use common obfuscation techniques like 'Hidden' window style and 'Bypass' execution policy, targeting specific known malicious URL patterns or filename keywords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
305
Detects the execution of cloud CLI tools (aws, az, gcloud) using Unix shells (bash, sh) to perform sensitive operations such as listing secrets, keys, or metadata, which may indicate credential discovery or exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
001
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
Detects clicks on sponsored search engine ads that redirect users to Google Cloud Storage (GCS) buckets with names or paths designed to impersonate the 'Ledger' brand. These artifacts are indicative of a malvertising campaign using typosquatted storage paths to deliver malicious payloads or credential harvesting pages.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
001
Detects network navigation to Google Sites pages that match patterns associated with known Ledger-impersonating phishing campaigns. These sites are often reached through redirect chains involving Google Ads, cloud storage, and rotating domains.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
Detects activity from known Storm-3168 (JADEPUFFER) campaign IP addresses across Azure control-plane, sign-in, and App Service logs. The rule monitors for malicious indicators in Azure Activity logs, Azure Sign-in logs, and Service Principal sign-ins, as well as specific sensitive URI paths (e.g., shells, admin login paths) within App Service HTTP logs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
Detects a suspicious sequence of behavior where an Azure service principal authenticates and immediately performs broad reconnaissance (enumeration) across multiple subscriptions and resource types. This pattern is often indicative of an adversary using a compromised service principal credential to map out an environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
Detects a service principal attempting to delete multiple Azure SQL databases in a short timeframe, resulting in failures. This pattern is characteristic of malicious data destruction activity, such as that observed in Storm-3168 (JADEPUFFER) campaigns, but accounts for the possibility of misconfigured infrastructure-as-code pipelines by requiring a high volume of failed requests across distinct resources.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
This rule detects reconnaissance activity targeting Azure App Service instances, specifically looking for attempts to access web-shell-like files, WordPress administration paths, PHP-CGI endpoints, or LangFlow code validation paths. It identifies potential Storm-3168 actor infrastructure through known IOCs or through patterns of high-volume, path-diverse HTTP requests that deviate from typical noise, helping to distinguish targeted probing from common internet background scanning.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
This rule detects reconnaissance activity targeting Azure App Service instances, specifically looking for attempts to access web-shell-like files, WordPress administration paths, PHP-CGI endpoints, or LangFlow code validation paths. It identifies potential Storm-3168 actor infrastructure through known IOCs or through patterns of high-volume, path-diverse HTTP requests that deviate from typical noise, helping to distinguish targeted probing from common internet background scanning.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
101
Detects a precursor pattern identified as JADEPUFFER, where a failed 'ListKeys' operation (indicating an attempt to discover or access keys for a non-existent storage account) is immediately followed by a burst of destructive delete operations on critical cloud resources (e.g., storage, databases, key vaults) by the same actor.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
001
Detects a suspicious pattern often associated with Storm-3168 (JADEPUFFER) activity: prolonged, high-volume Azure resource enumeration by one service principal, followed shortly by a second service principal performing rapid, multi-subscription enumeration from the same source IP address.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
001