Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,144 detections

Detects a suspected anti-debugging and anti-instrumentation sequence on Android devices. This rule identifies instances where 'getprop' is used to query system properties related to device security (ro.debuggable, ro.secure) followed shortly by a local network probe to the standard Frida instrumentation server port (27042). This combination is indicative of malware gating its execution to ensure it is not running within a controlled or debugged environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects outbound network requests from non-standard Android application processes to Google's generative-AI API endpoints (e.g., Gemini). This behavior is indicative of malware, such as RatHat, attempting to exfiltrate accessibility information or UI trees to an LLM to facilitate automated screen interaction and navigation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects malicious persistence activity on Android devices originating from an ADB or shell context (UID 2000). The rule monitors for a sequential pattern: the silent re-installation of the 'RatHat' APK package via 'pm install' commands, followed by the modification of system security settings to re-grant Accessibility Service permissions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the sequential activation of Android Accessibility services followed by Device Administrator activation by the same application within a short timeframe. This behavior is indicative of sophisticated Android malware, such as RatHat, establishing persistence and preventing uninstallation by combining Accessibility-based control with Device Admin-based device management capabilities (e.g., remote wipe or anti-uninstall).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the sequential activation of Android Accessibility services followed by Device Administrator activation by the same application within a short timeframe. This behavior is indicative of sophisticated Android malware, such as RatHat, establishing persistence and preventing uninstallation by combining Accessibility-based control with Device Admin-based device management capabilities (e.g., remote wipe or anti-uninstall).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a malicious sequence of actions originating from an Android Accessibility Service, specifically the 'SystemHelperService'. The activity involves the programmatic enablement of Developer Options and Wireless Debugging, followed by the unauthorized extraction of an ADB pairing PIN from the screen, bypassing user interaction requirements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a specific sequence of Android Debug Bridge (ADB) commands typical of malicious Android agents, specifically those running with elevated privileges (UID 2000/shell/root). The rule identifies combinations of permission grants, battery optimization bypasses, and package tampering (disabling or uninstalling) occurring within the same context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a specific sequence of Android Debug Bridge (ADB) commands typical of malicious Android agents, specifically those running with elevated privileges (UID 2000/shell/root). The rule identifies combinations of permission grants, battery optimization bypasses, and package tampering (disabling or uninstalling) occurring within the same context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a specific sequence of commands indicative of the RatHat malware on Android, involving waking the device followed by automated unlock gestures or PIN input and password retrieval commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects non-Telegram applications communicating with the Telegram Bot API (api.telegram.org), which may indicate unauthorized data exfiltration, command-and-control (C2) activity, malware communications, or abuse of Telegram as an attacker-controlled channel.
avatar
Ajay Kumar@Karanajay
avatar
Detections.ai Community
13 days ago
103
Detects the staging of a potential RatHat malware component by observing a native Go binary being moved into /data/local/tmp via ADB shell (uid 2000), followed by an associated service binding to local port 7912 within a 5-minute window. This sequence is characteristic of the deployment process for this specific Android threat.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the use of the 'nsenter' utility to target the PID 1 namespace with host-level namespace flags. This technique is used by the CARBONATO botnet to escape from a privileged Docker container and execute commands on the underlying host system, leveraging the host filesystem mount.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule detects unauthorized attempts to create privileged containers via the Docker API, specifically identifying the use of the 'net-setup' string often associated with the CARBONATO worm. Such activity indicates potential propagation or lateral movement within a containerized environment by attempting to deploy containers with elevated permissions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects unauthorized file creation within the /root/.hermes/loot/ directory and specific path combinations associated with the CARBONATO botnet's Hermes Agent. This activity is indicative of credential harvesting, specifically the exfiltration of AI API keys for various LLM providers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the execution of the XMRig cryptominer masquerading as the legitimate systemd-logind service. The rule identifies suspicious command-line arguments indicative of mining activity, or instances where systemd-logind is spawned from unauthorized parent processes such as shell interpreters, container engines, or nsenter, which is often characteristic of post-exploitation activity like privileged Docker container escapes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where a Node.js process (node.exe) initiates command-line interpreters (cmd.exe, powershell.exe) with specific arguments or command lines associated with administrative or potentially obfuscated/automated script execution. This is a common pattern for post-exploitation activities or legitimate administrative automation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects unauthorized access to unauthenticated Docker registry API endpoints on port 5000. This rule identifies catalog enumeration and the pulling of malicious container images associated with the CARBONATO botnet, including the retrieval of image manifests and configuration files that expose sensitive environment variables and credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects persistence mechanisms used by the CARBONATO botnet on Linux-based Docker hosts. The rule monitors for the application of immutable file attributes using 'chattr +i' on identified watchdog binaries (specifically '.docker-network-monitor'), the creation of malicious cron jobs, the enabling of suspicious systemd timers ('docker-network-resolver'), and the execution of specific persistence-related shell scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the CARBONATO botnet using two distinct persistence and evasion techniques: masquerading user-space processes as kernel worker threads by setting command line arguments to '[kworker/u2:0]', or disguising mining binaries as the systemd-logind service. Legitimate kernel threads are spawned by PID 2 and lack an executable path, while the legitimate systemd-logind is expected to be spawned by systemd/init.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the presence of Node.js runtime files (node.exe, index.js) or script-based agents (vbs, ps1) located within user-profile paths (AppData) that mimic legitimate Windows system folders. This pattern is characteristic of masquerading techniques used to stage or run malicious agents under the guise of system components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the compilation of a Managed Object Format (MOF) file using mofcomp.exe from the temporary directory of the MSSQL service account. This behavior is indicative of an attacker leveraging the xp_cmdshell procedure in MSSQL to deploy a malicious MOF file, which registers a WMI permanent event subscription to establish persistence or facilitate secondary payload execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000