Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,144 detections
Filters
Last updated
All Time
Detection languages
23,200
16,898
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,788
4,478
Categories
20,100
11,460
5,732
4,980
4,798
Platforms
39,725
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,036
15,419
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a suspected anti-debugging and anti-instrumentation sequence on Android devices. This rule identifies instances where 'getprop' is used to query system properties related to device security (ro.debuggable, ro.secure) followed shortly by a local network probe to the standard Frida instrumentation server port (27042). This combination is indicative of malware gating its execution to ensure it is not running within a controlled or debugged environment.
Detects outbound network requests from non-standard Android application processes to Google's generative-AI API endpoints (e.g., Gemini). This behavior is indicative of malware, such as RatHat, attempting to exfiltrate accessibility information or UI trees to an LLM to facilitate automated screen interaction and navigation.
Detects malicious persistence activity on Android devices originating from an ADB or shell context (UID 2000). The rule monitors for a sequential pattern: the silent re-installation of the 'RatHat' APK package via 'pm install' commands, followed by the modification of system security settings to re-grant Accessibility Service permissions.
Detects the sequential activation of Android Accessibility services followed by Device Administrator activation by the same application within a short timeframe. This behavior is indicative of sophisticated Android malware, such as RatHat, establishing persistence and preventing uninstallation by combining Accessibility-based control with Device Admin-based device management capabilities (e.g., remote wipe or anti-uninstall).
Detects the sequential activation of Android Accessibility services followed by Device Administrator activation by the same application within a short timeframe. This behavior is indicative of sophisticated Android malware, such as RatHat, establishing persistence and preventing uninstallation by combining Accessibility-based control with Device Admin-based device management capabilities (e.g., remote wipe or anti-uninstall).
Detects a malicious sequence of actions originating from an Android Accessibility Service, specifically the 'SystemHelperService'. The activity involves the programmatic enablement of Developer Options and Wireless Debugging, followed by the unauthorized extraction of an ADB pairing PIN from the screen, bypassing user interaction requirements.
Detects a specific sequence of Android Debug Bridge (ADB) commands typical of malicious Android agents, specifically those running with elevated privileges (UID 2000/shell/root). The rule identifies combinations of permission grants, battery optimization bypasses, and package tampering (disabling or uninstalling) occurring within the same context.
Detects a specific sequence of Android Debug Bridge (ADB) commands typical of malicious Android agents, specifically those running with elevated privileges (UID 2000/shell/root). The rule identifies combinations of permission grants, battery optimization bypasses, and package tampering (disabling or uninstalling) occurring within the same context.
Detects a specific sequence of commands indicative of the RatHat malware on Android, involving waking the device followed by automated unlock gestures or PIN input and password retrieval commands.
Detects non-Telegram applications communicating with the Telegram Bot API (api.telegram.org), which may indicate unauthorized data exfiltration, command-and-control (C2) activity, malware communications, or abuse of Telegram as an attacker-controlled channel.
Detects the staging of a potential RatHat malware component by observing a native Go binary being moved into /data/local/tmp via ADB shell (uid 2000), followed by an associated service binding to local port 7912 within a 5-minute window. This sequence is characteristic of the deployment process for this specific Android threat.
Detects the use of the 'nsenter' utility to target the PID 1 namespace with host-level namespace flags. This technique is used by the CARBONATO botnet to escape from a privileged Docker container and execute commands on the underlying host system, leveraging the host filesystem mount.
This rule detects unauthorized attempts to create privileged containers via the Docker API, specifically identifying the use of the 'net-setup' string often associated with the CARBONATO worm. Such activity indicates potential propagation or lateral movement within a containerized environment by attempting to deploy containers with elevated permissions.
Detects unauthorized file creation within the /root/.hermes/loot/ directory and specific path combinations associated with the CARBONATO botnet's Hermes Agent. This activity is indicative of credential harvesting, specifically the exfiltration of AI API keys for various LLM providers.
Detects the execution of the XMRig cryptominer masquerading as the legitimate systemd-logind service. The rule identifies suspicious command-line arguments indicative of mining activity, or instances where systemd-logind is spawned from unauthorized parent processes such as shell interpreters, container engines, or nsenter, which is often characteristic of post-exploitation activity like privileged Docker container escapes.
Detects instances where a Node.js process (node.exe) initiates command-line interpreters (cmd.exe, powershell.exe) with specific arguments or command lines associated with administrative or potentially obfuscated/automated script execution. This is a common pattern for post-exploitation activities or legitimate administrative automation.
Detects unauthorized access to unauthenticated Docker registry API endpoints on port 5000. This rule identifies catalog enumeration and the pulling of malicious container images associated with the CARBONATO botnet, including the retrieval of image manifests and configuration files that expose sensitive environment variables and credentials.
Detects persistence mechanisms used by the CARBONATO botnet on Linux-based Docker hosts. The rule monitors for the application of immutable file attributes using 'chattr +i' on identified watchdog binaries (specifically '.docker-network-monitor'), the creation of malicious cron jobs, the enabling of suspicious systemd timers ('docker-network-resolver'), and the execution of specific persistence-related shell scripts.
Detects the CARBONATO botnet using two distinct persistence and evasion techniques: masquerading user-space processes as kernel worker threads by setting command line arguments to '[kworker/u2:0]', or disguising mining binaries as the systemd-logind service. Legitimate kernel threads are spawned by PID 2 and lack an executable path, while the legitimate systemd-logind is expected to be spawned by systemd/init.
Detects the presence of Node.js runtime files (node.exe, index.js) or script-based agents (vbs, ps1) located within user-profile paths (AppData) that mimic legitimate Windows system folders. This pattern is characteristic of masquerading techniques used to stage or run malicious agents under the guise of system components.
Detects the compilation of a Managed Object Format (MOF) file using mofcomp.exe from the temporary directory of the MSSQL service account. This behavior is indicative of an attacker leveraging the xp_cmdshell procedure in MSSQL to deploy a malicious MOF file, which registers a WMI permanent event subscription to establish persistence or facilitate secondary payload execution.

