Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
105
After the initial FileFix paste-and-execute step, observed campaigns chain into a secondary download of the real payload using LOLBins or PowerShell web clients.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Acronis reported a multilingual FileFix phishing site using anti-analysis techniques and advanced obfuscation, chaining into a Go-based loader with string encryption before deploying StealC.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule detects a behavioral chain characteristic of the KongTuke/LandUpdate808 threat actor group. It identifies the correlation between a browser initiating a network connection to a domain with a low-reputation top-level domain (TLD) and that same browser process launching 'explorer.exe' within a 60-second window. This behavior is associated with social engineering lures (fake CAPTCHA) that encourage users to execute clipboard commands, which trigger file-picker dialogs via explorer.exe to facilitate follow-on malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
FileFix JavaScript silently writes the malicious command to the clipboard the instant the lure button is clicked, producing a much shorter human-reaction interval between browser launch and shell spawn than a manually typed path would allow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
A July 2026 incident used Polygon smart contracts (EtherHiding) for dynamic payload routing/C2 following a ClickFix/FileFix-style lure driven by compromised WordPress credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the creation of registry keys associated with the installation of Chrome or Edge browser extensions, specifically targeting the behavior exhibited by the CrashFix malware which masquerades as an ad blocker to achieve persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects anomalous Telnet (TCP port 23) traffic associated with Mirai-variant botnet propagation, such as scanning for new targets or inbound compromise attempts, often following cPanel/WHM vulnerabilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
005
This rule detects high-confidence phishing emails that were delivered to either the Inbox or Junk folder. It explicitly filters out messages that have been explicitly allowed by organization-level policies, user-level actions, or specific safe-sender bypass mechanisms, ensuring the alert focuses on malicious emails that bypassed standard security filters without an authorized exception.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
003
This rule detects high-confidence phishing emails that were delivered to either the Inbox or Junk folder. It explicitly filters out messages that have been explicitly allowed by organization-level policies, user-level actions, or specific safe-sender bypass mechanisms, ensuring the alert focuses on malicious emails that bypassed standard security filters without an authorized exception.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
103
Detects potential abuse of stolen OAuth session tokens, where refresh tokens are used to authenticate after a user has performed a password reset. This rule identifies accounts that continue to sign in from previously unseen devices or IP addresses within 24 hours post-password reset, a technique consistent with session persistence mechanisms used by adversary tools and platforms like EvilTokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
This rule detects scenarios where a user completes a device-code authentication flow, followed immediately (within 10 minutes) by the registration of an unmanaged, non-compliant device to their account. This behavior is indicative of potential token theft (e.g., EvilTokens) where an adversary uses a stolen token to register their own device as a persistent, unmanaged entity, bypassing standard corporate device enrollment controls.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
103
Detects the creation of an email inbox rule that includes both a concealment/deletion action and an external forwarding destination, occurring within 4 hours of a high-risk or compromised device-code authentication event. This pattern is indicative of account takeover where an attacker establishes persistence and exfiltration while hiding their activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
003
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
Detects reconnaissance and lateral movement activity via kubectl. The rule monitors for the enumeration of Kubernetes secrets or configmaps, and the deployment or application of privileged workloads featuring flags such as hostPath mounts, privileged execution, hostNetwork, or hostPID.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects HTTP and TLS activity associated with the DSCourier malware, specifically identifying attempts to retrieve configuration files disguised as common non-executable extensions (.jpg, .txt) or utilizing non-standard network ports like 8443, which are characteristic of this threat's command and control behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the use of 'winget configure' to retrieve and apply a Desired State Configuration (DSC) file from a remote HTTPS URL. This behavior can be abused to execute malicious configuration scripts directly from the internet.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the creation of a 'SystemIn.lnk' persistence shortcut on Windows systems using PowerShell and the WScript.Shell COM object. This activity is associated with the QUICAgent backdoor, part of the QUICSILVER operation, which uses temporary PowerShell scripts to establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the execution of AutoIt3.exe or AutoIt-related scripts (.a3x, .au3) spawned by mshta.exe. MSHTA is a legitimate utility that can be abused to proxy the execution of malicious code, and in this context, it may be used to launch AutoIt scripts to evade security controls or execute payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects memory allocation (VirtualAlloc/AllocateVirtualMemory) or protection (VirtualProtect/ProtectVirtualMemory) API calls performed with 'EXECUTE_READWRITE' permissions where the call stack is missing, unbacked, or contains unknown modules. This behavior is highly indicative of code injection techniques where an adversary attempts to execute shellcode or reflectively load a payload into memory while attempting to hide the origin of the execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004