Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation of a DLL file within the 'ProgramData\CrossDevice\' directory. This path is associated with a dangling COM InprocServer32 registration and does not exist by default. The creation of files in this location by non-privileged processes is indicative of staging malicious DLLs for exploitation of COM-based privilege escalation chains, specifically CVE-2026-66804 and CVE-2026-50343.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
This rule detects the presence of Vidar Stealer version 2.0+ by identifying the specific ARX-based (Addition-Rotation-XOR) stream cipher implementation. The detection logic searches for stable cryptographic constants (FNV-1a prime and golden-ratio constants), unique per-build ARX transformation constants, and specific post-decryption artifacts in the file's binary content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the accumulator-based virtual machine (VM) skeleton used by Vidar Stealer (v2.0+) to obfuscate its internal configuration and strings. The rule specifically identifies a combination of bit-manipulation and arithmetic primitives (ROR, ROL, NOT, IMUL, ADD, SUB, XOR) acting as a dispatcher pattern within highly entropic executable sections, which is a characteristic behavioral artifact of the Vidar Stealer obfuscation engine.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the presence of specific .NET deserialization gadget chain components (ExpandedWrapper, XamlServices, ObjectDataProvider, LosFormatter) within application traffic or logs, which are indicative of exploitation attempts targeting SharePoint pre-authentication remote code execution vulnerabilities like CVE-2026-65660.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects malicious HTTP POST requests targeting SharePoint servers that attempt to inject 'Register' directives into pages or manipulate WebPartPage ToolPane markup, indicative of attempts to bypass SafeControls or exploit vulnerable SharePoint features for code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects JavaScript code within HTML pages designed to block browser developer tools (F12, Inspect, View Source) using keydown event listeners. This technique is commonly associated with ClickFix-style phishing campaigns to prevent users or security analysts from inspecting malicious page content or fake CAPTCHA overlays.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects network activity associated with the ErrTraffic malware, specifically targeting JSON-RPC 'eth_call' requests to Polygon blockchain smart contracts used for C2 resolution and subsequent DNS queries to known malicious domains used for C2 infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects malicious exploitation attempts against the SharePoint WebPartPages.asmx SOAP endpoint. Attackers use this endpoint to bypass security patches by invoking template-parsing functions like GetWebPartPageConnectionInfo, which facilitates Register-directive injection and XamlServices deserialization chains for remote code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the execution of a malicious Electron-based installer masquerading as Anthropic's Claude AI (ClaudeOpus5-desktop.exe). The rule monitors for the specific filename or known malicious hashes, as well as the spawning of an embedded malicious loader process associated with the RevStealer infection chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects RevStealer malware attempting to use blockchain infrastructure for C2 communication or failover. The rules identify specific 'eth_call' JSON-RPC method calls to Polygon smart contracts containing hardcoded indicators, as well as TLS connections to known public RPC providers used as fallback C2 infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects spoofed emails carrying a .patch attachment sent to a GitLab incoming-email merge-request address. Requires Microsoft's composite authentication verdict (CompAuth: fail) -- a lower-noise spoofing signal than raw SPF/DKIM/DMARC -- and excludes sender/recipient pairs already seen corresponding with that token address in the prior 30 days to suppress recurring legitimate contributors.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
002
Detects spoofed emails carrying a .patch attachment sent to a GitLab incoming-email merge-request address. Requires Microsoft's composite authentication verdict (CompAuth: fail) -- a lower-noise spoofing signal than raw SPF/DKIM/DMARC -- and excludes sender/recipient pairs already seen corresponding with that token address in the prior 30 days to suppress recurring legitimate contributors.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
002
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
002
This rule detects the creation or modification of a DLL file within the 'ProgramData\CrossDevice' directory, or the modification of a specific COM CLSID InprocServer32 registry key associated with 'CrossDevice.Streaming.Source.dll'. This behavior is indicative of potential COM hijacking or persistence mechanisms targeting the CrossDevice streaming framework.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
103
Detects a suspicious behavior chain characteristic of information stealers like Vidar. The process first modifies the Windows Registry to disable the Windows Error Reporting (WER) UI (an anti-analysis technique to suppress crash dialogs) and shortly thereafter initiates an outbound network connection to a public IP, likely for C2 communication or data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
104
Detects high-volume, broad enumeration of sensitive Microsoft Graph API endpoints (users, groups, directory objects, applications, and mail folders) from a single host or user. This behavior is indicative of automated reconnaissance or post-compromise discovery of cloud identity environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
3010
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
104
The following analytic detects potential data exfiltration using plain HTTP POST requests. It leverages network traffic logs, specifically monitoring the `stream_http` data source for POST methods containing suspicious form data such as "wermgr.exe" or "svchost.exe". This activity is significant because it is commonly associated with malware like Trickbot, trojans, keyloggers, or APT adversaries, which use plain text HTTP POST requests to communicate with remote C2 servers. If confirmed malicious, this activity could lead to unauthorized data exfiltration, compromising sensitive information and potentially leading to further network infiltration.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
104
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
14 days ago
103
Detects GitHub repository actions (git.clone, oauth_authorization.create, repo.download_zip) from actor IPs not seen for that user in the prior 30 days, requiring either 3+ actions or activity across 2+ distinct repositories from the new IP within the same day. Aggregating to burst/multi-repo behavior (rather than alerting on a single new-IP event) filters out one-off false positives from travel, VPNs, or dynamic IP reassignment while still surfacing sustained anomalous access patterns consistent with account compromise or bulk exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
007