Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
002
Detects network communication to domains and specific file paths associated with the MacSync macOS stealer, which is used for malware dropper delivery and command-and-control (C2) operations. The rule monitors DeviceNetworkEvents for indicators such as specific malicious URLs, iCloud path abuse, and C2 infrastructure interaction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
302
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
11 days ago
002
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
002
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
002
Detects the execution of zsh with potentially suspicious command-line arguments (e.g., usage of curl, pipes, or osascript) occurring within a 15-minute window of network activity connecting to iCloud CalDAV servers. This behavior pattern may indicate unauthorized data access or exfiltration via legitimate cloud services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
202
Detects modifications to the .zshrc configuration file followed by shell commands interacting with the file, or the execution of commands that source the .repair-run script within a shell environment. This pattern is indicative of potential persistence mechanisms where an adversary modifies startup scripts to maintain access or execute malicious code upon shell initialization.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
202
This rule detects modifications or creation of Git hooks ('pre-commit', 'post-checkout') within local repository directories. Attackers can leverage these hooks as an execution trigger for arbitrary code whenever standard Git actions occur, facilitating persistence or privilege escalation on compromised developer machines.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
002
Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
7 days ago
000
Detects outbound network connections to domains, URLs, and IP:Port combinations identified as malicious in the ThreatFox OSINT feed. This rule covers various commodity malware C2 and payload delivery infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
7 days ago
000
This rule identifies Linux-based devices that are vulnerable to specific security flaws tracked under CVE-2026-64507 and CVE-2026-64508. It correlates vulnerability assessment data with device inventory to highlight exposed systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects repeated, silent authentication events in Microsoft 365 where MFA challenges are absent, consistent with the use of stolen session or refresh tokens (e.g., EvilTokens) to maintain persistent, unauthorized access to user accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
18 days ago
0013
This rule monitors for the installation of specific known-malicious or suspicious NPM packages that are commonly used in supply chain attacks. It identifies the execution of npm (or node) commands to install or add packages explicitly listed as malicious by security research, which may indicate a supply chain compromise or an attempt to introduce unauthorized code into the development environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
106
Detects the presence of specific Go build path metadata associated with the sckit Go implant, including modules and internal package structures, within an executable or file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
This rule detects outbound network beaconing from the SCKit malware to known command-and-control (C2) domains hosted on skyleen.fr or to a specific malicious IP address (139.84.223.178). The rule monitors both TLS SNI indicators in HTTPS traffic and direct IP connections to identify compromised hosts communicating with the attacker's infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the creation of a malicious GitHub Actions workflow file named 'runtime-update.yml', a known tactic used by the Sckit supply-chain worm. The worm injects this workflow to automate persistence and further propagation of the Go-based implant within CI/CD pipelines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the creation of a 'ca-roots.pem' file within a hidden '.sckit' directory on Linux systems. This behavior is associated with the 'sckit' supply-chain malware (e.g., delivered via malicious npm packages like @memtensor/memos-cloud-openclaw-plugin), which uses this bundled certificate to enable HTTPS Command and Control (C2) communication in environments where standard system CA stores are unavailable.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
This rule monitors application, build system, and dependency scanning logs for references to known-malicious versions of the @memtensor/memos-cloud-openclaw-plugin (npm) and MemoryOS (PyPI) packages. These versions contain the sckit Go worm and are associated with automated supply chain attacks involving the reuse of stolen credentials, indicated by the 'exact-ref-one-use-NPM_TOKEN' marker.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects npm package publish events that lack 'gitHead' provenance metadata. The absence of this field indicates that the package was likely published from a developer's local machine rather than through an authorized CI/CD pipeline, a technique used in supply chain attacks to bypass CI-gated controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the execution of the sckit Go implant, linked to the MemTensor supply chain compromise, during its host-profiling stage. The rule monitors for the 'sckit' binary being executed with 'stage0' and '--config64' command-line arguments, or being spawned by legitimate runtime interpreters like Node.js or Python, indicating an attempt to profile host information (timezone, language, privileges) and subsequent self-deletion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects instances where a Google Cloud Config Connector (KCC) service account performs a SetIamPolicy operation that grants high-privilege roles (roles/owner or roles/resourcemanager.organizationAdmin) at the organization or folder scope. This activity often indicates an out-of-band configuration change, a compromised CI/CD pipeline, or an unauthorized escalation, as legitimate KCC changes should be tracked via GitOps records.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003