Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
102
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
102
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects evidence of potential credential dumping from the Local Security Authority Subsystem Service (LSASS) process. The rule monitors for two distinct behaviors: the use of MemProcFS with device memory access flags targeting a RAW file, and the creation of files containing 'lsass.exe', 'minidump', and 'readme.txt' in their paths or filenames, which is characteristic of certain post-exploitation toolkits that harvest LSASS memory.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
22 days ago
002
Detects the execution of PowerShell commands that reference the 'nyx' script from 'raw.githubusercontent.com', combined with common download and execution patterns such as 'Invoke-Expression' or 'Invoke-WebRequest'. This activity is consistent with retrieving and executing remote post-exploitation scripts.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
22 days ago
002
Detects the execution of Python scripts named 'exploit.py' or 'exp.py', which are common naming conventions associated with proof-of-concept or exploit code.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
22 days ago
002
Detects execution and file artifacts associated with the 'fscan' network scanning tool, which is commonly used for internal network discovery and vulnerability scanning. The rule monitors for the presence of the fscan binary or evidence of its output files, specifically 'result.txt', often in combination with scanning parameters like port strings or target service references.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects the execution of PrintSpoofer or its derivatives, often used to perform privilege escalation on Windows systems by abusing the Print Spooler service. The rule also covers the download of the tool via PowerShell.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects the execution of 1C:Enterprise business automation software processes (1cv8.exe, 1cv8c.exe, rphost.exe) using specific suspicious external processing files (epf) such as 'Obrabotka_bez_svedeniy.epf' or 'ExternalProcessing1'. This includes detection of the file creation event to identify potential persistence or execution of malicious automation scripts within the 1C environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
This rule detects potential unauthorized activity originating from 1C Enterprise processes (rphost.exe, rmngr.exe, 1cv8.exe, 1cv8c.exe) when involving specific keywords like '1C-Shell.dt' or 'KRAUD'. It specifically monitors for the subsequent execution of local user account management commands (net user, net localgroup, New-LocalUser) by the 1C server process (rphost.exe) within an hour of the initial suspicious event.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
This rule detects potentially suspicious activity involving the 1C Enterprise software suite. It monitors for the execution of 'rmngr.exe' with debug flags or the spawning of processes by 'rphost.exe' that involve suspicious command files named with a 'v8_5fed' prefix located in temporary directories, which is indicative of potential exploitation attempts or unauthorized script execution within the application environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects the use of sc.exe or cplsupport.exe with command-line arguments often associated with service installation, configuration, or modification. This behavior may indicate an adversary attempting to establish persistence or escalate privileges by creating or modifying Windows services.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
002
Detects HTML files utilizing the 'GhostCode' technique to hide malicious phishing redirects. The technique involves a password-protected HTML lure that uses JavaScript (Web Crypto API) to derive an AES-256-GCM key from a user-provided password via PBKDF2, decrypt an embedded ciphertext payload, and dynamically redirect the user to a concealed phishing URL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Detects the presence and execution of components related to the 'GhostCode' activity, specifically the installation of a rogue self-signed root certificate authority (CA) masquerading as Google Trust Services and the subsequent configuration of a local TLS-intercepting proxy. The detection monitors for the creation of specific archive files, modification of the system certificate store, addition of local firewall rules, and modification of the local hosts file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Detects infostealer malware (e.g., Vidar, Lumma, RedLine) that specifically searches for Claude/Anthropic session cookies, API tokens, and generic browser-based credential storage artifacts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
Detects evidence of ONYXC2 malware activity by correlating process-related events (mutex creation, remote thread injection, named pipes) with suspicious registry key or value modifications containing the 'ONYXC2' indicator within a 5-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
000
This rule detects when a DLL containing 'python' in its filename is loaded by a process that is not an identified Python interpreter or the dropbox.exe application. The rule specifically filters for these DLLs being larger than 10MB, which may indicate the use of embedded Python environments to facilitate malicious code execution or side-loading.
avatar
F S@Fsdr
avatar
Detections.ai Community
23 days ago
203
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
000
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
000
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
000
Page 268 of 1871