Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects potential exploitation attempts targeting vulnerabilities within the libheif image processing library. It monitors for image processing binaries (e.g., convert, magick) executing with command-line arguments related to HEIF/HEIC files, followed by multiple application crash events (SIGSEGV, coredumps) associated with libheif on the same device within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
002
Detects the modification of AI agent configuration files (e.g., mcp.json, config.json) followed shortly by the agent spawning a child process that matches typical Model Context Protocol (MCP) server execution patterns. This behavior may indicate an attacker has modified the configuration to inject malicious server commands or tools that the AI agent will execute upon next initialization, effectively achieving persistent code execution via the agent's legitimate functionality.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
000
Detects web server processes (e.g., Apache, Nginx, PHP-FPM, IIS) launching suspicious shell or system administration utilities. This behavior is indicative of a web server compromise, potentially involving the use of web shells or the exploitation of public-facing web applications to execute arbitrary commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
24 days ago
205
This rule correlates a suspicious process execution (identified by specific command-line indicators), with subsequent persistence modification in Windows Registry Run/RunOnce keys, and a subsequent external network connection (excluding internal IP ranges). The activity is captured within a 15-minute window, suggesting a multi-stage attack pattern involving execution, establishing persistence, and initiating C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
This rule detects the presence of specific SilverFox malware payload files by matching their SHA256 hashes against known indicators of compromise. This identification is typically used for file integrity monitoring, endpoint scanning, or gateway-based file filtering to prevent malicious code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
003
Detects high-frequency, automated interactions with popular AI assistant web interfaces (e.g., Gemini, Perplexity, Claude, Copilot) from common browser processes. This pattern often indicates unauthorized automated data submission or scraping, which may follow or facilitate automated exfiltration of browser-resident data.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
004
Detects high-frequency, automated interactions with popular AI assistant web interfaces (e.g., Gemini, Perplexity, Claude, Copilot) from common browser processes. This pattern often indicates unauthorized automated data submission or scraping, which may follow or facilitate automated exfiltration of browser-resident data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
004
Detects evidence of CRPx0 ClickFix ransomware execution by monitoring the HKCU RunMRU registry key for patterns indicating the execution of obfuscated or malicious commands (PowerShell, curl, or base64 encoded strings) consistent with clipboard-hijacking social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
26 days ago
008
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
003
Detects instances where a process named msedge.exe is running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a common location used by attackers to hide malicious executables by masquerading them as legitimate browser processes, particularly when the process command line includes arguments like 'preview' or 'thumbnail' which are often used to blend in with background system activity.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
003
Detects instances where a process named msedge.exe is running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a common location used by attackers to hide malicious executables by masquerading them as legitimate browser processes, particularly when the process command line includes arguments like 'preview' or 'thumbnail' which are often used to blend in with background system activity.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
003
This rule detects a multi-stage malicious behavior chain: the execution of a suspected loader (identified by hash or specific mutex), followed by network communication to a known C2 domain or IP, and concluded by the placement of a file in the Windows Telemetry folder (typically mimicking msedge.exe). The events are correlated within a short time window (2 hours between each stage) on the same device.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
003
Detects process and file creation activity matching known MovieReaper loader and downstream module file hashes (MD5/SHA256). C2 IP/domain network indicators for this campaign require a separate network_connection-category rule, since Sigma logsource categories cannot be mixed within a single rule.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
103
This rule detects the presence of the Amatera (ACR Stealer) loader by identifying characteristic indicators, including specific Telegra.ph dead-drop URLs, domain-fronting artifacts using github.com, and hardcoded C2 IP addresses. It also identifies credential theft targeting by searching for artifacts related to password managers such as KeePass, Bitwarden, WinAuth, and Authy, combined with the presence of C2 communication indicators.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects the creation of the file 'nb_hook_dbg.txt' within 'C:\Windows\Temp\', which is a specific debug artifact generated by the PIVOTPIPE loader during the initialization of its HookGate subsystem. This subsystem is responsible for implementing indirect system calls to bypass user-mode EDR hooks by decoding syscall numbers at runtime and utilizing the WoW64 transition.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects instances where PowerShell.exe is launched directly from the Windows Run dialog (explorer.exe as parent) with command-line arguments indicative of a ClickFix/ClearFake social engineering attack. This typically involves the user pasting malicious code, which often includes references to WebDAV UNC paths or external domains used for malicious delivery, into the Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
003
This rule detects suspicious process injection activity directed at explorer.exe. It looks for cases where explorer.exe is initiated by a non-standard parent process and performs remote thread creation, thread context manipulation, or process image mapping, which are common techniques used by malware to hide execution within a legitimate system process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
30 days ago
12025
Detects instances where an executable file (exe, dll, js, cjs) deletes itself within 30 seconds of execution. This is a common technique used by malware to remove its installation artifact after spawning a persistent process or to evade signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
101
Detects the execution of known potentially malicious or unauthorized tools, specifically 'client32.exe' and variations of 'hypersnap.exe'. These binaries may be used by attackers for remote access, surveillance, or unauthorized data capture.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
001
Page 243 of 1871