Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects file artifacts referencing InvisibleFerret, a Python-based backdoor used by WaterPlum/North Korean IT worker actors for persistent access to victim networks
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
002
Detects file artifacts referencing InvisibleFerret, a Python-based backdoor used by WaterPlum/North Korean IT worker actors for persistent access to victim networks
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
002
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
000
Detects the mounting of a USB storage device on an endpoint, which can be a precursor to data exfiltration or the introduction of malicious files.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
27 days ago
2010
This rule detects interaction with specific infrastructure identified as deceptive dating applications. It monitors network communication, sign-in attempts, email interactions, and endpoint execution associated with known malicious domains (e.g., archat.us, heyhru.com, sitin.ai), specific IP addresses (38.129.138.244), and unique package identifiers (com.cavalier.nalo, com.qiga.vio). The detection logic spans across DeviceNetworkEvents, EntraIdSignInEvents, EmailUrlInfo, EmailEvents, DeviceEvents, and DeviceProcessEvents to identify exposure to these Indicators of Compromise (IOCs) across both network and endpoint layers.
avatar
F S@Fsdr
avatar
Detections.ai Community
26 days ago
708
This rule monitors for network and email activity associated with known fraudulent AI reseller infrastructure. It aggregates data from device network connections, email URL inspections, and email header analysis to identify potential interactions with malicious domains known to facilitate AI-related fraud.
avatar
F S@Fsdr
avatar
Detections.ai Community
26 days ago
408
Detects the malicious OIC_Invitation_General_Official.lnk sample used as the entrypoint for PlugX infection chain
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
002
Detects execution of the PlugX side-loaded host process (Jarte.exe / GRrte.exe) from the JartePortable directory. This process performs in-memory host/system profiling (GetComputerNameW, GetVersionEx, system directory queries) via the decoded PlugX core (T1082), which is not directly visible as command-line telemetry.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
002
Detects the execution of known Jarte-derived host processes (GRrte.exe or Jarte.exe) which are commonly leveraged as side-loading proxies for the PlugX remote access trojan. The rule flags the process initiation as a proxy indicator for the subsequent execution of PlugX's modular payload, which performs system enumeration and process discovery.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
21 days ago
002
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
001
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
005
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
001
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
001
Page 251 of 1871