Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule monitors for two distinct suspicious patterns: first, the interaction between Claude Desktop and the CEF (Chromium Embedded Framework) library, which may indicate unauthorized plugin or extension loading; second, the execution of non-standard binaries initiated by various JetBrains IDE processes located outside of standard program directories, which could indicate process hollowing or unauthorized tool execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
This rule monitors for two distinct suspicious patterns: first, the interaction between Claude Desktop and the CEF (Chromium Embedded Framework) library, which may indicate unauthorized plugin or extension loading; second, the execution of non-standard binaries initiated by various JetBrains IDE processes located outside of standard program directories, which could indicate process hollowing or unauthorized tool execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Detects the execution of the 'bun' JavaScript runtime invoking 'index.js' in the context of an npm package installation. This pattern is characteristic of the Shai-Hulud worm, which leverages the npm preinstall lifecycle hook to execute malicious code. The rule identifies suspicious process lineage where 'npm' spawns 'bun' for immediate payload execution, allowing for detection of the technique rather than specific artifacts.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
29 days ago
5017
Detects the execution of Microsoft Teams client processes on endpoints associated with user accounts that have already been flagged as compromised via authentication anomalies. This rule acts as a pivot and investigation tool for tracking potentially malicious activity within Teams on impacted hosts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
24 days ago
004
This rule detects the use of specific tools associated with credential dumping and memory forensics, including Dokan driver installations for file system mounting, the use of DumpIt for creating memory dumps, and the subsequent analysis of these dumps using MemProcFS to access sensitive process memory information such as LSASS minidumps.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
002
Detects potential C2 activity associated with MQTTDoor or MatrixDoor malware by monitoring suspicious network traffic patterns. This includes unauthorized processes connecting to MQTT brokers (hivemq.com), non-chat applications interacting with a Matrix homeserver, and geo-location lookups (ip-api.com) occurring shortly after process execution.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
002
Detects outbound network connections from internal devices to a set of known malicious IP addresses (45.151.45.31 and 46.166.79.31) which may indicate command and control communication or other malicious activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
002
This rule detects the execution of suspicious command lines involving 'evilsocket/nyx' and the use of 'iex' (Invoke-Expression) within PowerShell or common download utilities (curl, wget). It also correlates this with network connections to 'raw.githubusercontent.com' fetching 'nyx.ps1', which is a common pattern for downloading and executing malicious scripts in memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
002
This rule detects the use of specific tools associated with credential dumping and memory forensics, including Dokan driver installations for file system mounting, the use of DumpIt for creating memory dumps, and the subsequent analysis of these dumps using MemProcFS to access sensitive process memory information such as LSASS minidumps.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
002
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
002
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
102
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
002
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
102
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
002
Detects evidence of potential credential dumping from the Local Security Authority Subsystem Service (LSASS) process. The rule monitors for two distinct behaviors: the use of MemProcFS with device memory access flags targeting a RAW file, and the creation of files containing 'lsass.exe', 'minidump', and 'readme.txt' in their paths or filenames, which is characteristic of certain post-exploitation toolkits that harvest LSASS memory.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
21 days ago
002
Detects the execution of PowerShell commands that reference the 'nyx' script from 'raw.githubusercontent.com', combined with common download and execution patterns such as 'Invoke-Expression' or 'Invoke-WebRequest'. This activity is consistent with retrieving and executing remote post-exploitation scripts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
002
Detects the execution of Python scripts named 'exploit.py' or 'exp.py', which are common naming conventions associated with proof-of-concept or exploit code.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
21 days ago
002
Detects execution and file artifacts associated with the 'fscan' network scanning tool, which is commonly used for internal network discovery and vulnerability scanning. The rule monitors for the presence of the fscan binary or evidence of its output files, specifically 'result.txt', often in combination with scanning parameters like port strings or target service references.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
002
Detects the execution of PrintSpoofer or its derivatives, often used to perform privilege escalation on Windows systems by abusing the Print Spooler service. The rule also covers the download of the tool via PowerShell.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
002
Detects the execution of 1C:Enterprise business automation software processes (1cv8.exe, 1cv8c.exe, rphost.exe) using specific suspicious external processing files (epf) such as 'Obrabotka_bez_svedeniy.epf' or 'ExternalProcessing1'. This includes detection of the file creation event to identify potential persistence or execution of malicious automation scripts within the 1C environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
002
This rule detects potential unauthorized activity originating from 1C Enterprise processes (rphost.exe, rmngr.exe, 1cv8.exe, 1cv8c.exe) when involving specific keywords like '1C-Shell.dt' or 'KRAUD'. It specifically monitors for the subsequent execution of local user account management commands (net user, net localgroup, New-LocalUser) by the 1C server process (rphost.exe) within an hour of the initial suspicious event.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
002
Page 266 of 1871