Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
004
This rule detects network traffic containing the specific 'Xwormmm' string in the payload, which serves as a handshake or banner characteristic of XWorm command-and-control (C2) communications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects incoming TLS traffic from an external network where the TLS server certificate's Subject Common Name (CN) field matches 'AsyncRAT Server'. This pattern is a known indicator of a beaconing session initiated by AsyncRAT remote access trojan servers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
This rule detects network traffic patterns associated with the Lumma Stealer malware performing endpoint fingerprinting. It monitors for GET requests to the URI path '/api/set_agent' which contains a 32-character hexadecimal string, characteristic of the malware's C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
This rule detects network traffic indicative of the RisePro malware communicating with its Command and Control (C2) infrastructure. It specifically looks for the 'clientsendfile' string within the payload, which acts as a keepalive signal or heartbeat for the RisePro implant.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects network traffic associated with the RisePro malware family, specifically identifying the use of 'serversendfile' commands, which indicates data exfiltration or file transfer activity via a command-and-control channel.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
This rule detects outgoing HTTP POST requests to discord.com API webhooks, specifically containing patterns characteristic of XWorm malware, such as exfiltrating machine information identified by Username and IP fields.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
This rule detects potential command-and-control (C2) communication associated with the Pikabot malware. The detection looks for outbound HTTP POST requests to external networks that lack a 'Content-Type' header and contain a non-empty, specifically sized request body, which are behavioral indicators consistent with Pikabot beaconing activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects outbound HTTP POST requests to known blockchain RPC endpoints (bsc-dataseed and rpc.ankr.com) that utilize the 'eth_call' method. This behavior is associated with the ClearFake malware strain using the EtherHiding technique, where malicious scripts or payloads are hidden or retrieved via blockchain smart contracts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
This rule monitors HTTP traffic for requests containing 'bp.dat', which is associated with the registration phase of the Latrodectus malware downloader. It detects both URI-based and request body-based attempts by an infected host to register with a command and control server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects outbound network traffic containing the hardcoded user-agent string 'Remcos', which is indicative of a Remcos RAT beacon communicating with a command-and-control (C2) server. The rule inspects HTTP requests to identify this specific malware signature within the established communication flow.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects HTTP GET requests originating from internal hosts to external destinations where the User-Agent string contains 'AutoIt'. This behavior is indicative of the DarkGate malware downloading additional payloads or components using AutoIt scripting capabilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
405
Detects the installation of a specific known malicious npm package named 'tw-pkgprobe-7731' via the command line, which may indicate a supply chain compromise or an attempt to execute malicious code within a development environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
502
Detects Node.js processes establishing network connections to common webhook relay and collection services, which may indicate data exfiltration or credential theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects DNS queries for the domain 'pdf.gusercontent.com', which is known to be used as a lookalike domain for Google-related services to deceive users. This pattern is often indicative of malicious infrastructure used for credential harvesting, phishing, or malware delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects unauthorized outbound network traffic from browser processes to the lookalike domain 'pdf.gusercontent.com'. This domain is associated with a malicious Firefox browser extension, 'PDF Identity Verifier', which is designed to exfiltrate session telemetry and data from Google account sessions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects requests to the FedCM (Federated Credential Management) well-known configuration endpoint (.well-known/web-identity) that originate from referrers containing 'gusercontent.com', often used in phishing or credential harvesting campaigns to simulate legitimate Google authentication flows.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
This rule detects PowerShell commands that attempt to reassemble a Base64-encoded payload from multiple concatenated variable fragments. It specifically looks for patterns where filler characters ('*' or '?') are stripped from the payload before it is passed to the [Convert]::FromBase64String method. This technique is commonly used to evade static string analysis and signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
205
Detects the Windows Character Map utility (charmap.exe) loading suspicious modules such as amsi.dll or clr.dll followed by a process execution involving PowerShell or an unidentified command string, which is indicative of DLL side-loading or process hollowing techniques for malicious code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
105
Detects the execution of PowerShell with encoded commands that explicitly perform base64 string decoding using 'FromBase64String'. This pattern is frequently used to obfuscate scripts or payloads, often seen in downloader stagers or malicious scripts to bypass security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002