Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
Detects HTTP requests containing malicious JDBC strings targeting PaperCut NG/MF print management software, which are indicative of attempts to exploit authentication bypass and remote code execution vulnerabilities (CVE-2026-81578, CVE-2026-82078).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
102
Detects HTTP POST requests directed at Grav CMS endpoints where the __unique_form_id__ parameter contains directory traversal sequences (e.g., ../). This behavior is indicative of attempted exploitation of CVE-2026-42608, aimed at bypassing file system restrictions to write files to unauthorized locations outside the application's expected form data directory.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
001
This rule detects malicious HTTP POST requests attempting a path traversal attack against Grav CMS, specifically targeting the __unique_form_id__ parameter. The rule looks for directory traversal sequences ('..') following the parameter, which is characteristic of attempts to read sensitive files outside the intended web directory.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
001
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
001
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
001
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
avatar
Arnold Chan@slaz
avatar
Hunters
10 days ago
001
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
10 days ago
001
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
001
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
101
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
001
Detects SectopRAT (Arechclient2) .NET RAT binaries deployed via tampered libcef.dll / JetBrains helper DLL sideloading that harvest browser credentials, cookies, credit card data, and files. Tightened to require combined sideload+family+target indicators plus .NET CLR import evidence, avoiding standalone generic strings.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
001
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
Detects HTTP GET requests to '/api.php?t=' containing a 13-digit timestamp identifier, followed by a response body containing 'download_link'. This pattern is indicative of the SilverFox malware relaying instructions or stage-two payload delivery.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
Detects DNS queries, TLS SNI headers, and HTTP host headers associated with the known exfiltration domain 't.m-kosche.com' linked to the Mini Shai-Hulud malware.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
001
Detects unauthorized execution of a Bun runtime executing an 'index.js' payload within a GitHub Actions workflow context, specifically targeting known compromised action paths (e.g., issues-helper, maintain-one-comment). The detection requires correlation with either sensitive environment/secret access or anomalous outbound network activity originating from the same process, indicating potential credential theft or C2 communication by a malicious CI/CD pipeline component.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
001
Detects emails that appear to have been injected or sent using the 'swaks' SMTP testing tool rather than a standard Mail User Agent (MUA). The rule identifies this activity by looking for the 'swaks' signature in the 'X-Mailer' header or by matching a specific 'Message-Id' pattern typical of swaks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects incoming email messages where the Reply-To header address domain differs from the Sender From address domain. This technique is commonly used in phishing attacks to redirect victim replies to an attacker-controlled mailbox while maintaining a spoofed appearance in the original sender field.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
This rule detects potential phishing attempts where the sender's display name is formatted as an email address and the sender's domain uses a capital 'I' character to mimic a well-known service provider (typosquatting/homoglyph attack), such as 'gmaiI.com'. It identifies discrepancies between the actual sender domain and the normalized domain name after character replacement.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
002
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
102