Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects outbound HTTP POST requests associated with the Telepuz modular loader. The rule monitors for specific URI patterns, request body parameters, and suspicious User-Agent strings indicative of PowerShell or MSHTA command-and-control communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
101
Detects outbound HTTP POST requests associated with Cicada3301 ransomware affiliate check-in behavior. The rule monitors for a specific 'X-Session-Id' HTTP header and a corresponding 'affiliate_id' parameter within the request body, which are indicative of malicious C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
201
Detects outbound network traffic from internal servers to known Remote Monitoring and Management (RMM) platforms (AnyDesk, ScreenConnect, Atera). This activity is often used by adversaries to establish covert command and control (C2) channels and remote access to internal resources.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
501
Detects network activity related to the BEAST ransomware targeting VMware ESXi systems. The rule identifies attempts to stage encryption operations via SSH, including detecting references to known filenames ('encryptor.elf', 'beast_esxi') and the use of the 'vim-cmd' utility to power off virtual machines as part of the preparation for file encryption.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
101
Detects outbound HTTP PUT requests characteristic of data exfiltration associated with Qilin ransomware. The rule monitors for the use of command-line tools like s5cmd or rclone for uploading data, often used during the double extortion phase where stolen data is uploaded to leak sites.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
201
Detects web traffic containing indicators of 'ClickFix' social engineering attacks. These attacks present a fake 'CAPTCHA' or verification prompt to the user and instruct them to copy and paste a malicious script (involving PowerShell or mshta) into their system terminal.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
201
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
100
Detects a specific SharePoint markup injection technique targeting the EditingPageParser type-check mechanism. An attacker smuggles a 'Register' directive into a crafted WebPartMarkup POST request using the 'publishingribbon' Tagprefix to bypass SafeControl validation.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
104
This rule detects potential post-exploitation activity following a SharePoint XamlServices.Parse() deserialization attack. It monitors the w3wp.exe (IIS worker process) for the loading of suspicious .NET deserialization-related assemblies (e.g., System.Xaml.dll) followed by the execution of a shell process (cmd.exe, powershell.exe, etc.) within a short window, which is indicative of fileless web shell activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
004
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
100
Detects periodic outbound network connections (beaconing) to rare remote destinations initiated by processes running from non-standard or user-writable locations. The rule calculates the interval coefficient of variation (CV) between successful connections to identify regular, consistent patterns indicative of command and control communication while excluding known legitimate update and service traffic.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
100
This rule monitors for network connections and process activities associated with known malicious indicators, including file hashes, C2 IP addresses, domains, and specific URLs. It maps these activities to identify potential command and control communication or other malicious network activity occurring on endpoints.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
100
This rule detects potentially malicious command execution initiated by web browsers (Chrome, Edge, Firefox, Safari, Opera). It identifies scenarios where browsers spawn PowerShell on Windows with encoded command arguments or spawn shells (zsh, bash, sh) on macOS while piping commands retrieved via curl or wget, which is a common pattern for dropper and fileless malware delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
5016
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
100
Detects indicators of compromise related to the TraderTraitor (KelpDAO) threat actor, including specific file hashes, malicious process paths, C2 network infrastructure (IPs and domains), and malicious TLS certificates. The rule uses filename-path matching to reduce noise from legitimate macOS binaries.
avatar
Arnold Chan@slaz
avatar
SlimKQL
14 days ago
004
Detects specific malicious Mach-O binary payloads associated with the Atomic macOS Stealer (AMOS) discovered in the Macfinger ClickFix campaign. The rule uses static file hashes to identify these specific samples.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
201
Detects an outbound network connection initiated by 'rnpkeys.exe' when executing from a non-standard 'ProgramData\keyroll' directory. This behavior is associated with the early stages of a Command and Control (C2) registration sequence, where an encrypted loader initiates network contact before subsequent staged communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects known components of the Sauron malware, including MSI installers, side-loaded executables (rnpkeys.exe), and malicious DLLs (rnp.dll, tdwp.dll) by matching known SHA-256 file hashes. It also includes a YARA rule for detecting PE binaries containing the string 'Sauron'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects the presence of MSI installer packages associated with the Sauron Loader malware, which stage malicious files (rnpkeys.exe, rnp.dll, and tdwp.dll) into the C:\ProgramData\keyroll directory to facilitate DLL side-loading.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001