Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects incoming spearphishing emails that contain a ZIP archive attachment. The rule alerts if the archive contains an LNK file with a double extension (e.g., .pdf.lnk) or if the email subject contains specific social engineering lures related to food pricing or peace negotiations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects network communication to 'imageurlgenerator.com' where a VBScript downloader is attempting to retrieve a staged payload. The request pattern targets specific URI structures resembling GUID-based identifiers ending in '.txt', which is characteristic of the XHOPLESS malware delivery chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects PowerShell processes using .NET screen capture libraries (System.Windows.Forms/Drawing) to generate image files in common staging directories like Temp or Public folders, which is a common pattern for malicious screen capture exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the installation of known AI-powered coding assistant extensions (e.g., Copilot, Tabnine, Cursor) on a device, followed by significant source-code repository cloning or archival activity by Git within two hours. This pattern is potentially indicative of intellectual property theft or sensitive source code exfiltration facilitated by a newly introduced AI tool.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects high-privilege user accounts (e.g., executives, administrators) undergoing a credential or MFA reset, followed by an atypical sign-in event within a two-hour window. This pattern is indicative of potential account takeover or identity-compromise scenarios, often associated with help-desk vishing attacks where an attacker induces a user or administrator to reset credentials or MFA methods.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
302
Detects a multi-stage malware execution pattern consistent with VelvetCake activity. This includes staging text-based files in C:\Users\Public, downloading PowerShell scripts to temporary directories, executing the script via PowerShell, and subsequently deleting both the staged text files (except for specific allowed filenames) and the payload script.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the execution of Windows Script Host (wscript.exe/cscript.exe) loading WMI-related modules (wbemprox.dll, wbemcomn.dll, etc.). This pattern is often indicative of scripts attempting to query WMI for system information, environment configuration, or locale data, which is a common reconnaissance technique used by malware to identify the victim environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects the use of command-line tools such as rclone, aws CLI, gsutil, and curl to upload files associated with machine learning models (e.g., weights, checkpoints, training datasets) to public cloud storage or AI model hosting platforms. This pattern may indicate the exfiltration of sensitive proprietary AI research or training data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
101
Detects suspicious HTTP requests directed at SharePoint applications containing a malformed Register directive. The rule identifies attempts to leverage the 'publishingribbon' Tagprefix combined with unauthorized namespaces (e.g., System.Xaml, System.Windows.Data) to bypass the EditingPageParser.InitializeRegisterTable safelist check, a common technique for SharePoint remote code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
This rule detects a malicious execution sequence often associated with VBScript droppers. It identifies the execution of a process (specifically notepad++.exe) from a dynamically named staging directory under C:\Users\Public\, followed within 10 minutes by the deletion of the associated staging archive (Evernote.zip).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
This rule detects network traffic patterns associated with the ARToken phishing campaign, specifically identifying access to lure pages hosted on 'workers.dev' domains with 'docviewer' in the hostname and 'turnstile' challenge responses in the HTTP body, which is used for anti-analysis/evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects network traffic patterns associated with the ORAX/OraxRDP AiTM (Adversary-in-the-Middle) phishing toolkit. The rule monitors for specific SignalR WebSocket upgrade requests and session-related GraphQL commands (such as MirrorChallenge, Init, and Input) used to facilitate MFA relay and web session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects successful Entra ID sign-in events that utilize the OAuth 2.0 device authorization grant (device code) flow. This authentication mechanism is frequently abused by attackers to perform device code phishing (e.g., ARToken attacks), where victims are tricked into entering a malicious user code on a legitimate Microsoft login portal to facilitate token theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects a suspicious pattern where a user authenticates via device code and, within a short timeframe (two hours), registers a new device to their account. This behavior is indicative of the 'ARToken' persistence pattern, where an adversary uses a stolen session to bind a rogue device to the victim's account, potentially to mint a Primary Refresh Token (PRT) for persistent access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects phishing emails that utilize document-themed subjects (e.g., invoices, shared documents) containing Windows Internet Shortcut (.url) attachments that redirect users to Cloudflare Workers-based 'docviewer' pages, often linked in conjunction with suspicious SharePoint file shares.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
This rule detects interactive or user-triggered execution of PowerShell carrying indicators of payload downloading, inline evaluation, or Base64 encoding. Because explorer.exe is the parent process, it typically signifies a payload delivered via email/web that a user opened directly such as an .lnk shortcut.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detection & Hunting Community
13 days ago
303
This rule detects interactive or user-triggered execution of PowerShell carrying indicators of payload downloading, inline evaluation, or Base64 encoding. Because explorer.exe is the parent process, it typically signifies a payload delivered via email/web that a user opened directly such as an .lnk shortcut.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
13 days ago
203
This rule detects network traffic patterns associated with the ARToken PhaaS backend infrastructure. It identifies specific fixed URI paths and cross-affiliate API route contracts used by the backend service, as well as known indicators of compromise for affiliate infrastructure, to monitor for potential credential harvesting or adversary-controlled service interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects HTTP traffic where a common automated scanner or sandbox user agent triggers an immediate redirect to 'about:blank', a common technique used by phishing kits to hide content from automated security analysis tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects sign-in events within Microsoft Entra ID (formerly Azure AD) that utilize the 'deviceCode' authentication protocol. This OAuth 2.0 flow is designed for devices with limited input (e.g., smart TVs, IoT devices, CLI tools) but is frequently abused by attackers in 'device code phishing' campaigns to obtain access tokens by tricking users into entering a code on a malicious site.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003
Detects instances where a process not associated with standard web browsers accesses, copies, or modifies sensitive browser files such as cookies, local storage, or session tokens. This behavior is highly indicative of information-stealer malware (e.g., Vidar, Lumma, RedLine) attempting to exfiltrate session data for account hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
003