Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
004
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
004
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
006
Detects the presence of zero-width, non-printing, or bidirectional-override Unicode characters in command lines, commonly used for obfuscation or prompt injection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
003
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
203
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
203
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
Detects high-volume file download, access, or preview activity originating from known anonymous proxy services. This behavior is indicative of potential data exfiltration or unauthorized mass data collection from cloud storage applications.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
20 days ago
9023
This rule monitors for DNS queries and network connections to known infrastructure domains associated with the threat group UTA0565. It acts as an indicator of compromise (IOC) sweep to identify internal systems attempting to communicate with malicious command-and-control (C2) servers identified by typosquatting and registration-pattern analysis.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
104
Detects accounts showing a spike in requests to public generative-AI services compared to their historical baseline, combined with anomalous indicators like multiple source IPs, regions, or off-hours activity.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
003
Detects the installation of Windows services (Event ID 4697 or 7045) where the service binary path points to command interpreters (PowerShell, cmd.exe) or suspicious directories such as Temp, user profile paths, or file extensions associated with scripts (.ps1, .vbs, .bat). This behavior is often indicative of persistence mechanisms or lateral movement attempts where an attacker attempts to execute arbitrary code via a service.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
14 days ago
304
This rule detects the execution of processes that use file names mimicking legitimate security or system services, such as 'Credential Guard.exe' or 'Window Security Health Services.exe'. These names are often used by adversaries for masquerading to evade detection by blending in with legitimate system activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
100
Detects a suspicious sequence of events where a process modifies a Windows Registry Run key to ensure execution at logon, followed shortly by the same executable file being copied into the current user's startup folder. This pattern is often used by malware to establish persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
103
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
103
Detects suspicious HTTP POST requests to a URI path '/collect' containing specific telemetry parameters ('visitorId', 'timeOnPage', 'stage') characteristic of the 'ClickFix' social engineering campaign. This behavior is used by threat actors to simulate fake bot-protection challenges to trick users into executing malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
201
Detects the execution of known remote access and support tools (Quick Assist, Microsoft Remote Assistance, or AnyDesk) on a host that has recently received a high volume of emails (over 50). This behavior often aligns with social engineering campaigns where a user is instructed to download or launch a remote support tool under false pretenses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects the exfiltration behavior of the Sauron Loader, where a process tree associated with rnpkeys.exe or its modules (rnp.dll, tdwp.dll) within the C:\ProgramData\keyroll directory performs a burst of numerous small HTTPS POST requests to a single destination. This pattern is characteristic of a screenshot image being fragmented into small chunks and exfiltrated.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects the execution of suspected Sauron Loader components staged in C:\ProgramData\keyroll\ (rnpkeys.exe or tdwp.dll) followed by an outbound network connection from the same host within a 2-minute window. This behavior correlates the staging of malicious binaries with the loader's automated outbound registration attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
101
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
003
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
003