Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects egress to the NeedyMantis C2 domain corp.tripswithengine[.]com across three vantage points: TLS SNI (port 443), DNS resolution, and HTTP Host header. Each content match is anchored to the start of its buffer ('startswith') so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') cannot match — only this exact domain or a genuine subdomain of it triggers.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
The EntraIdSignInEvents table exposes the JA4 fingerprint in the GatewayJA4 field. But looking at the complete fingerprint alone does not tell us much. The interesting part starts when we break it down. With a simple KQL query, we can separate the TLS version, SNI, number of cipher suites, extensions and ALPN, together with the cipher and extension hashes. Then we can see how many sign-ins, users, IPs and countries are behind each JA4. The idea is simple: understand what is normal first, then look for what is different.
avatar
Sergio Albea@Sergio_Albea
avatar
01 | 🇨🇭 Swiss Cyber Hunters
20 days ago
6016
Detects the execution of PowerShell or PowerShell ISE where the parent process is the console host (conhost.exe) and the command-line arguments are either missing, empty, or represent an bare execution of the binary. This pattern is commonly associated with fileless execution techniques where attackers attempt to hide command-line arguments or evade logging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects execution patterns indicative of 'ClickFix' social engineering, where a user is tricked into copying a command to their clipboard and executing it directly in a terminal. The rule monitors for processes that read clipboard contents (via PowerShell or clip.exe) and simultaneously invoke shell interpreters to execute the retrieved data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized processes attempting to access sensitive browser profile files, such as login credentials, cookies, and session state files. This behavior is indicative of credential harvesting or session theft by malicious software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects execution of rundll32.exe or regsvr32.exe when spawned by powershell.exe or mshta.exe, specifically targeting DLLs located in common user-writable or temporary directories (AppData, ProgramData, Downloads). This pattern is consistent with the delivery of CastleLoader shellcode loaders following ClickFix-style social engineering lures.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the deployment of NetSupport Manager (client32.exe) or related components when initiated by common scripting interpreters such as PowerShell, MSHTA, or CMD. This behavior is indicative of a ClickFix-style social engineering attack where a user is coerced into executing malicious commands to deploy remote access tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects illicit OAuth consent grant events where an application is granted high-risk delegated permissions. This behavior is indicative of consent phishing or 'ConsentFix' tradecraft, where attackers trick users into granting permissions to a malicious application, thereby enabling unauthorized access to mail and file data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects illicit OAuth consent grant events where an application is granted high-risk delegated permissions. This behavior is indicative of consent phishing or 'ConsentFix' tradecraft, where attackers trick users into granting permissions to a malicious application, thereby enabling unauthorized access to mail and file data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the use of legitimate Windows system binaries (LOLBins) such as curl.exe, certutil.exe, or bitsadmin.exe to download files. These binaries are monitored when spawned directly from common entry-point processes like explorer.exe, cmd.exe, or powershell.exe, which is characteristic of second-stage payload retrieval in ClickFix social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects Azure AD / Entra ID sign-in events that utilize the OAuth 2.0 device code authentication flow. This protocol, designed for input-constrained devices, is frequently exploited by adversary-in-the-middle phishing kits (e.g., EvilTokens) to trick users into authorizing a malicious session, effectively bypassing traditional MFA by obtaining an active session token.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects indicators of Browser-in-the-Browser (BitB) phishing attacks within web proxy traffic. It monitors for suspicious HTML markup mimicking browser UI elements, such as fake title bars and URL bars, as well as specific window dimensions and authentication lures that deviate from known legitimate identity provider patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000