Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,144 detections

Detects HTTP traffic patterns associated with a custom 'RatHat' malware variant utilizing Google's Gemini API for command and control or remote automation. The rule identifies the initial POST request to the API with specific generation parameters (temperature 0.1, 256 tokens) and the corresponding JSON-formatted coordinate response from the server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a potential TeamFiltration-style compromise where multiple accounts with no history of successful authentication and no MFA enforced authenticate successfully within a 7-minute burst window. This behavior is indicative of an adversary mass-testing or accessing newly compromised dormant or un-secured service accounts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
002
Detects network connections to known public DNS-over-HTTPS (DoH) resolvers, specifically cloudflare-dns.com and dns.google, as well as non-browser processes performing HTTPS requests to these IPs. Such traffic patterns are often indicative of Command and Control (C2) communication utilizing DoH to bypass network-level DNS filtering and monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network connections to known public DNS-over-HTTPS (DoH) resolvers, specifically cloudflare-dns.com and dns.google, as well as non-browser processes performing HTTPS requests to these IPs. Such traffic patterns are often indicative of Command and Control (C2) communication utilizing DoH to bypass network-level DNS filtering and monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects user account sign-in attempts originating from a country not observed in the previous 30 days, or from an ISP flagged as a VPN, proxy, or hosting/cloud provider. This behavior is consistent with an adversary utilizing stolen credentials or session tokens through anonymity infrastructure to bypass conditional access policies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the execution of PowerShell commands using '[scriptblock]::Create' in conjunction with character array decoding or large negative integer-array patterns. This technique is commonly used to deobfuscate and execute obfuscated PowerShell scripts at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the execution of PowerShell commands using '[scriptblock]::Create' in conjunction with character array decoding or large negative integer-array patterns. This technique is commonly used to deobfuscate and execute obfuscated PowerShell scripts at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the execution of known Canon or Stardock software binaries (COTFileReadApp.exe, DeElevate64.exe) when spawned by msiexec.exe from non-standard locations such as Temp or AppData directories. This pattern is indicative of potential defense evasion, where adversaries leverage legitimate software to proxy execution or potentially perform side-loading activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the creation of Windows Registry Run keys with names mimicking known applications (e.g., 'Canon Configuration Reader' or 'Stardock DeElevation Tool'). These naming patterns are highly suspicious and indicative of attempts to achieve persistence or perform defense evasion via registry-based autostart execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects outbound network traffic to known public BNB Smart Chain (BSC) data seed nodes using JSON-RPC 'eth_call' methods or TLS connections. This pattern is indicative of malware using blockchain infrastructure as a dead drop resolver for C2 command retrieval or configuration updates.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects execution of msiexec.exe via the Windows Run dialog (launched by explorer.exe) that utilizes a remote URL for an MSI installer alongside suspicious property flags ('ORG_NOTE', 'passive'). This pattern is associated with 'ClickFix' social engineering campaigns where users are instructed to copy-paste commands to 'fix' a display issue, leading to the execution of malicious installers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where identified RAT-associated or potentially malicious parent processes spawn command-line interpreters (e.g., cmd, powershell) or execute archive management commands, which is indicative of secondary stage payload deployment or automated execution following initial compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network connection attempts to known public DNS-over-HTTPS (DoH) resolvers from specific binaries identified as host processes for SectopRAT, a malware often associated with ClickFix social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the creation of files associated with Psychedelic Stealer's persistence mechanism. The malware establishes persistence by installing a malicious native messaging host configuration file (com.lunex.explorer.json) and associated malicious scripts (host.ps1 or host.bat), which allows it to intercept and manipulate web browser native messaging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the creation of files associated with Psychedelic Stealer's persistence mechanism. The malware establishes persistence by installing a malicious native messaging host configuration file (com.lunex.explorer.json) and associated malicious scripts (host.ps1 or host.bat), which allows it to intercept and manipulate web browser native messaging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the use of PowerShell with a hidden window ('-w hidden') to execute the 'Add-MpPreference' cmdlet to configure Windows Defender exclusions. This combination is often indicative of malicious activity, such as attempting to bypass security controls stealthily following a UAC bypass or initial access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule detects the creation of a scheduled task named 'psychedelicloveUtils' on Windows systems. This specific task name is associated with the persistence mechanism of the Psychedelic Stealer malware. The detection leverages command-line monitoring for the task creation request and identifies related file-system modifications in the Windows task registry structure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects suspicious execution patterns involving msiexec where a PowerShell process launches or is the parent of an MSI installation occurring from the %TEMP% directory with a GUID-based filename, or when msiexec executes an application from within %AppData%\Local\Programs. This pattern is often associated with fileless malware, ClickFix-style social engineering attacks, or suspicious persistence/installation behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where an unexpected process loads both 'amsi.dll' and .NET runtime modules ('clr.dll' or 'mscoree.dll'). This behavior is frequently associated with malicious, position-independent shellcode that attempts to disable AMSI scanning and host the CLR in-memory to execute malicious .NET assemblies or payloads, avoiding standard .NET execution environments like PowerShell or msbuild.exe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the execution of known remote-access or screen-sharing software (e.g., TeamViewer, AnyDesk, RDP) within 30 minutes of launching common video conferencing applications (e.g., Zoom, Teams, Google Meet). This pattern is consistent with an adversary remotely assisting an unauthorized user during a live coding interview or similar assessment process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
204
Detects a specific behavioral chain associated with the CHOSEN BRICK implant. This rule identifies when a suspected malicious process writes image/screenshot files (.png, .jpg, .bmp) to disk, followed by a network connection to the Telegram Bot API within a 15-minute window, suggesting potential data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004