Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects Network, File, or Process events associated with known C2 IOCs
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
101
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
101
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
001
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
003
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
002
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
002
This rule detects persistence mechanisms involving the creation or modification of a specific Windows Registry Run key ('ComponentTask33Agent') within the HKEY_CURRENT_USER hive, or the execution of PowerShell commands targeting this specific registry value. This is indicative of malware, such as the ChainScript Node.js RAT, attempting to maintain access across user reboots by abusing standard Windows autostart configuration points.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
001
This rule detects persistence mechanisms involving the creation or modification of a specific Windows Registry Run key ('ComponentTask33Agent') within the HKEY_CURRENT_USER hive, or the execution of PowerShell commands targeting this specific registry value. This is indicative of malware, such as the ChainScript Node.js RAT, attempting to maintain access across user reboots by abusing standard Windows autostart configuration points.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
001
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
002
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
002
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
002
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
002
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
002
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
002
This rule detects potential persistence mechanisms and suspicious execution patterns associated with the ChainScript malware. It specifically monitors for the creation of scheduled tasks using PowerShell with indicators like 'StreamServiceSharedBridge.ps1' or 'ComponentTask33Agent', and the execution of VBScript-based agents via wscript.exe. It also flags tasks configured with specific execution time limits often associated with this malware's behavior.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
101
This rule detects potential persistence mechanisms and suspicious execution patterns associated with the ChainScript malware. It specifically monitors for the creation of scheduled tasks using PowerShell with indicators like 'StreamServiceSharedBridge.ps1' or 'ComponentTask33Agent', and the execution of VBScript-based agents via wscript.exe. It also flags tasks configured with specific execution time limits often associated with this malware's behavior.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
19 days ago
001
Detects EDRKiller.exe or WarsawKiller.exe binaries and the associated wsftprm.sys BYOVD driver used by The Gentlemen threat actor to terminate security product processes
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Page 238 of 1871