Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
203
Detects the creation of a Windows scheduled task via schtasks.exe where the initiating process is located in common user-writable temporary or non-standard directories (e.g., AppData, Temp, or Public folders). This behavior is often indicative of malicious persistence mechanisms being established by a dropper or stage-one malware payload.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
000
Detects a behavioral chain where a process establishes persistence using a 'WindowsUpdate' Registry Run key or a scheduled task, followed within five minutes by an outbound network connection from the same process. The rule specifically excludes cases where a ZIP file was written to disk, identifying potential in-memory staging for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
000
This rule detects outgoing HTTP POST requests that contain a ZIP file with a filename prefix of 'StolenData_' in the request body. This is a known behavior of the TokenGrabber stealer family, which exfiltrates collected victim data (e.g., browser credentials, session tokens) to a remote server, often via a Discord webhook or similar infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
TokenGrabber Builder: Webhook XOR/Base64 Obfuscation Artifacts - detects webhook.txt persistence, XOR 0x5A + Base64 webhook obfuscation, WEBHOOK_PLACEHOLDER injection, and the _x() decode routine used to recover the exfiltration endpoint
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized processes (excluding firefox.exe and explorer.exe) accessing or modifying sensitive Firefox browser profile files, specifically places.sqlite (history/bookmarks) and cookies.sqlite (session cookies). This activity is often indicative of credential or session hijacking attempts by malware or malicious scripts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects a sequence of activity where a process queries Windows Registry keys related to installed Python versions, followed shortly by the invocation of Python-to-executable compilation tools like Nuitka or PyInstaller. This pattern is indicative of an adversary or developer performing interpreter discovery before compiling a payload into a standalone executable.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects a suspicious sequence of events where a process creates a scheduled task named 'WindowsUpdate' followed by execution of 'netsh' commands to dump wireless profiles or clear keys within a 15-minute window. This behavioral pattern is often associated with credential-stealing malware attempting to establish persistence and harvest sensitive information.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized processes attempting to access Discord's local storage (LevelDB) where authentication tokens are stored, followed by a network request to the Discord API user validation endpoint, which is a pattern indicative of token extraction and liveness testing by malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
003
Detects sensitive cPanel/WHM administrative commands or system file modifications occurring within one hour of a suspected authentication bypass event, indicative of potential post-exploitation activity related to CVE-2026-41940.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
004
Detects network and DNS activity associated with the SideCopy threat group, specifically monitoring for connections to known C2 domains, C2 IP addresses, or the usage of port 5863 typically associated with the ReverseRAT backdoor.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
303
Detects execution and network activity related to the PamStealer / Wavel malware campaign, including the JXA dropper and associated C2 infrastructure. The rule monitors for known malicious file hashes (e.g., JXA dropper, pkgunpack utility) and network connections to identified lure, distribution, and C2 domains and URLs used by the campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects PamStealer-style browser credential theft on macOS. The detection logic identifies the forced termination of browser helper processes using 'pkill' (which releases SQLite file locks) followed by the execution of a 'KcHelper' binary that uses specific environment markers (e.g., KC_PASS) to bypass keychain authorization prompts and steal stored browser credentials.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects a successful login attempt by the user account 'p2pwn' targeting port 37777. Port 37777 is commonly associated with DVR/NVR surveillance equipment and is frequently targeted by brute-force attacks and botnets attempting to gain unauthorized access to embedded devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
005
Detects network activity related to the exploitation of the CVE-2025-31702 vulnerability in Dahua P2P Relay services. The rules monitor for probe attempts, device parameter fetching (randsalt), serial number enumeration bursts, and successful no-auth channel responses, indicating a bypass of authentication mechanisms on vulnerable Dahua devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
005
Detects exfiltration of sensitive information, including Dahua camera credentials and internal identifiers, to the Telegram Bot API over HTTPS. These rules monitor for specific API endpoints (/sendPhoto) and common credential patterns (Login:, Password:, Model:) or indicators (Shodan links, VKontakte references) within HTTP POST requests directed toward api.telegram.org.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
105
Detects exfiltration of sensitive information, including Dahua camera credentials and internal identifiers, to the Telegram Bot API over HTTPS. These rules monitor for specific API endpoints (/sendPhoto) and common credential patterns (Login:, Password:, Model:) or indicators (Shodan links, VKontakte references) within HTTP POST requests directed toward api.telegram.org.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
005
Detects the use of PowerShell to load .NET assemblies into memory using System.Reflection.Assembly::Load combined with indicators often associated with fileless payload execution, such as GZip decompression, AES decryption, or method invocation (EntryPoint.Invoke, GetType).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
105
Detects attempts to impair or disable Microsoft Defender Antivirus through unauthorized exclusion paths, Registry modifications, tampering with protection settings, or forcing policy updates.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
105
Detects command-line activity indicating an attempt to bypass or tamper with Anti-Malware Scan Interface (AMSI) functionality. The rule flags processes invoking GetProcAddress or LoadLibrary to resolve and manipulate AMSI-specific functions like AmsiScanBuffer or AmsiScanString within amsi.dll, a common technique for disabling runtime script scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
105