Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,144 detections
Filters
Last updated
All Time
Detection languages
23,200
16,898
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,788
4,478
Categories
20,100
11,460
5,732
4,980
4,798
Platforms
39,725
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,036
15,419
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects low-prevalence processes executing from non-standard directories that communicate with the same domain across multiple destination IP addresses over HTTPS (443) or DNS (53) within a short period. This behavior may indicate the use of Domain Generation Algorithms (DGA), fast-flux infrastructure, malware beaconing, or resilient command-and-control (C2) communications.
Detects CARBONATO botnet activity where malicious processes are masquerading as legitimate Linux system components. This includes XMRig mining software running as /usr/sbin/systemd-logind, process arguments attempting to mimic kernel kworker threads, or processes running from directories associated with netd-svc/resolved container images.
This rule detects a multi-tool attack chain involving the Cairn autonomous exploitation engine and the Hermes Agent. It flags the co-occurrence of outbound network traffic to both the DeepSeek API (Cairn engine) and the Anthropic Claude API (Hermes Agent) from the same host within a one-hour window. This behavior is indicative of an automated, AI-driven post-exploitation orchestration campaign.
Detects evidence of persistence mechanisms targeting Docker environments on Linux systems. The rule identifies suspicious modifications using crontab, systemctl (service creation/start), and chattr (to make files immutable), specifically monitoring for artifacts related to '.docker-network-monitor' and 'docker-network-resolver'. It flags systems where multiple such configuration changes occur within a single day.
Detects evidence of cryptocurrency mining (XMRig) and suspicious process masquerading on Linux systems, alongside container-related events referencing known malicious or suspicious strings such as 'GH0ST_C2' or 'fsociety'.
Detects an endpoint initiating outbound network connections to three or more distinct LLM provider APIs (DeepSeek, Qwen, Mistral, Gemini) within a short timeframe (15-minute windows). This behavior aligns with the multi-provider voting mechanism used by the CLOSEDQUORUM post-compromise framework to autonomously determine subsequent actions using diverse generative AI models.
Detects malicious interactions with an unauthenticated Docker daemon API, specifically identifying the creation of privileged containers with host bind mounts, the deployment of containers with specific naming conventions for network reconnaissance (netns-probe/net-setup), subsequent container start events, and the use of the Docker exec API to perform host namespace escapes via nsenter.
Detects the execution of the CARBONATO malware watchdog process (.docker-network-monitor) which performs container redeployment operations, indicating an active backdoor and persistent threat attempting to restore its presence within a Docker environment after initial cleanup.
Detects a suspected automated exploitation sequence where a web storefront file (e.g., .phtml, .js, .php) is modified to inject malicious script code (skimmer), followed by an unauthorized SQL DELETE operation on sensitive database tables containing payment, customer, or order information, originating from the same host within a 6-hour window.
Detects evidence of the CARBONATO post-exploitation pattern, specifically identifying the installation of a Hermes Agent by monitoring the creation of a 'SOUL.md' persona file within a '.hermes' folder, followed by correlated outbound network traffic to a specific LLM gateway or known Vercel proxy infrastructure used for command relay.
Detects the deployment of the CARBONATO botnet's Hermes Agent within containerized environments. The rule identifies specific artifacts such as the 'SOUL.md' persona configuration, 'netd-svc' container references, and indicators of AI-focused credential theft (e.g., searching for OpenAI or Anthropic API keys) orchestrated by the GH0ST AI agent.
Detects anomalous activity associated with the CARBONATO worm, specifically monitoring for unauthorized creation of 'net-setup' containers or pulling 'system/resolved' images via the Docker API port 2375. Additionally, the rule identifies rapid, sequential network scanning behavior targeting the Docker API port across internal IP ranges.
Detects unauthorized access attempts to a Docker Registry API on port 5000. The rule identifies attempts to enumerate the image catalog and extract sensitive environment variable information from configuration blobs, which may contain hardcoded credentials or indicators of compromise.
Detects network communication associated with the CARBONATO Hermes Agent, including direct C2 beaconing to a hardcoded IP on port 8989 and TLS connections to Vercel-hosted proxy infrastructure identifying as 'carbonato-proxy'.
Detects outbound connections to a known malicious C2 infrastructure associated with the CARBONATO threat actor. The rule identifies both established SSH sessions using the OpenSSH implementation and the initiation of outbound TCP connections on ports dynamically determined by an MD5 hash, which is a known behavior of this actor's C2 communication strategy.
Detects the downloading of Android application packages (.apk) from potentially untrusted or non-official third-party portals, which are often used in smishing or malvertising campaigns to deliver malicious applications to user devices.
This rule monitors for suspicious interactions with Android device drivers via the 'getevent' utility, often used to capture raw input, combined with unusual file access patterns involving 'locateValues.json' and potential data exfiltration attempts to specific internal API endpoints.
Detects a specific command and control (C2) communication pattern characteristic of RatHat malware, involving the retrieval of HTML overlay templates followed by the submission of captured form or credential data from the same device within a one-hour window.
Detects malicious persistence activity on Android devices originating from an ADB or shell context (UID 2000). The rule monitors for a sequential pattern: the silent re-installation of the 'RatHat' APK package via 'pm install' commands, followed by the modification of system security settings to re-grant Accessibility Service permissions.
Detects a suspected anti-debugging and anti-instrumentation sequence on Android devices. This rule identifies instances where 'getprop' is used to query system properties related to device security (ro.debuggable, ro.secure) followed shortly by a local network probe to the standard Frida instrumentation server port (27042). This combination is indicative of malware gating its execution to ensure it is not running within a controlled or debugged environment.
Detects a suspected anti-debugging and anti-instrumentation sequence on Android devices. This rule identifies instances where 'getprop' is used to query system properties related to device security (ro.debuggable, ro.secure) followed shortly by a local network probe to the standard Frida instrumentation server port (27042). This combination is indicative of malware gating its execution to ensure it is not running within a controlled or debugged environment.

