Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,144 detections

Detects low-prevalence processes executing from non-standard directories that communicate with the same domain across multiple destination IP addresses over HTTPS (443) or DNS (53) within a short period. This behavior may indicate the use of Domain Generation Algorithms (DGA), fast-flux infrastructure, malware beaconing, or resilient command-and-control (C2) communications.
avatar
Ajay Kumar@Karanajay
avatar
Detections.ai Community
13 days ago
103
Detects CARBONATO botnet activity where malicious processes are masquerading as legitimate Linux system components. This includes XMRig mining software running as /usr/sbin/systemd-logind, process arguments attempting to mimic kernel kworker threads, or processes running from directories associated with netd-svc/resolved container images.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule detects a multi-tool attack chain involving the Cairn autonomous exploitation engine and the Hermes Agent. It flags the co-occurrence of outbound network traffic to both the DeepSeek API (Cairn engine) and the Anthropic Claude API (Hermes Agent) from the same host within a one-hour window. This behavior is indicative of an automated, AI-driven post-exploitation orchestration campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects evidence of persistence mechanisms targeting Docker environments on Linux systems. The rule identifies suspicious modifications using crontab, systemctl (service creation/start), and chattr (to make files immutable), specifically monitoring for artifacts related to '.docker-network-monitor' and 'docker-network-resolver'. It flags systems where multiple such configuration changes occur within a single day.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects evidence of cryptocurrency mining (XMRig) and suspicious process masquerading on Linux systems, alongside container-related events referencing known malicious or suspicious strings such as 'GH0ST_C2' or 'fsociety'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects an endpoint initiating outbound network connections to three or more distinct LLM provider APIs (DeepSeek, Qwen, Mistral, Gemini) within a short timeframe (15-minute windows). This behavior aligns with the multi-provider voting mechanism used by the CLOSEDQUORUM post-compromise framework to autonomously determine subsequent actions using diverse generative AI models.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects malicious interactions with an unauthenticated Docker daemon API, specifically identifying the creation of privileged containers with host bind mounts, the deployment of containers with specific naming conventions for network reconnaissance (netns-probe/net-setup), subsequent container start events, and the use of the Docker exec API to perform host namespace escapes via nsenter.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the execution of the CARBONATO malware watchdog process (.docker-network-monitor) which performs container redeployment operations, indicating an active backdoor and persistent threat attempting to restore its presence within a Docker environment after initial cleanup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a suspected automated exploitation sequence where a web storefront file (e.g., .phtml, .js, .php) is modified to inject malicious script code (skimmer), followed by an unauthorized SQL DELETE operation on sensitive database tables containing payment, customer, or order information, originating from the same host within a 6-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects evidence of the CARBONATO post-exploitation pattern, specifically identifying the installation of a Hermes Agent by monitoring the creation of a 'SOUL.md' persona file within a '.hermes' folder, followed by correlated outbound network traffic to a specific LLM gateway or known Vercel proxy infrastructure used for command relay.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the deployment of the CARBONATO botnet's Hermes Agent within containerized environments. The rule identifies specific artifacts such as the 'SOUL.md' persona configuration, 'netd-svc' container references, and indicators of AI-focused credential theft (e.g., searching for OpenAI or Anthropic API keys) orchestrated by the GH0ST AI agent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects anomalous activity associated with the CARBONATO worm, specifically monitoring for unauthorized creation of 'net-setup' containers or pulling 'system/resolved' images via the Docker API port 2375. Additionally, the rule identifies rapid, sequential network scanning behavior targeting the Docker API port across internal IP ranges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects unauthorized access attempts to a Docker Registry API on port 5000. The rule identifies attempts to enumerate the image catalog and extract sensitive environment variable information from configuration blobs, which may contain hardcoded credentials or indicators of compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network communication associated with the CARBONATO Hermes Agent, including direct C2 beaconing to a hardcoded IP on port 8989 and TLS connections to Vercel-hosted proxy infrastructure identifying as 'carbonato-proxy'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects outbound connections to a known malicious C2 infrastructure associated with the CARBONATO threat actor. The rule identifies both established SSH sessions using the OpenSSH implementation and the initiation of outbound TCP connections on ports dynamically determined by an MD5 hash, which is a known behavior of this actor's C2 communication strategy.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the downloading of Android application packages (.apk) from potentially untrusted or non-official third-party portals, which are often used in smishing or malvertising campaigns to deliver malicious applications to user devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule monitors for suspicious interactions with Android device drivers via the 'getevent' utility, often used to capture raw input, combined with unusual file access patterns involving 'locateValues.json' and potential data exfiltration attempts to specific internal API endpoints.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a specific command and control (C2) communication pattern characteristic of RatHat malware, involving the retrieval of HTML overlay templates followed by the submission of captured form or credential data from the same device within a one-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects malicious persistence activity on Android devices originating from an ADB or shell context (UID 2000). The rule monitors for a sequential pattern: the silent re-installation of the 'RatHat' APK package via 'pm install' commands, followed by the modification of system security settings to re-grant Accessibility Service permissions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a suspected anti-debugging and anti-instrumentation sequence on Android devices. This rule identifies instances where 'getprop' is used to query system properties related to device security (ro.debuggable, ro.secure) followed shortly by a local network probe to the standard Frida instrumentation server port (27042). This combination is indicative of malware gating its execution to ensure it is not running within a controlled or debugged environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a suspected anti-debugging and anti-instrumentation sequence on Android devices. This rule identifies instances where 'getprop' is used to query system properties related to device security (ro.debuggable, ro.secure) followed shortly by a local network probe to the standard Frida instrumentation server port (27042). This combination is indicative of malware gating its execution to ensure it is not running within a controlled or debugged environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000