Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects network connections from monitored devices to known cryptomining pool IP addresses and domain names. It monitors DeviceNetworkEvents for indicators of compromise (IOCs) associated with cryptomining activities, identifying potential resource hijacking on internal endpoints.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
001
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
001
This rule detects network connections to known cryptomining pool IP addresses and domain names, as well as file or process executions matching specific hashes associated with known miner samples. It monitors for communication to command-and-control (C2) servers potentially used for cryptomining operations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
001
Detects unauthorized devices or processes attempting to communicate with the Telegram Bot API (/sendMessage or /sendDocument) and monitors for credential-related terms within the request metadata. This often indicates the use of Telegram as a command-and-control (C2) channel for data exfiltration or credential theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
3045
Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
1 month ago
27027
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
006
The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.
If confirmed malicious, this activity could allow attackers to execute arbitrary commands, exfiltrate data, or maintain long-term access to the compromised system, posing a severe threat to the organization's security.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 month ago
6045
Detects instances where the legitimate Windows Character Map utility (charmap.exe) is spawned by suspicious processes or PowerShell, and subsequently loads clr.dll. This behavior is indicative of potential DLL sideloading or process injection techniques used by malware to execute arbitrary code within a trusted system process context.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
25 days ago
105
Detects network communication with identified C2 infrastructure associated with VectraRAT, Amadey, and ClickFix campaigns, as well as the presence of a specific 'callback.json' artifact in temporary directories, which is commonly used for C2 address overrides.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
26 days ago
106
Detects network communication with identified C2 infrastructure associated with VectraRAT, Amadey, and ClickFix campaigns, as well as the presence of a specific 'callback.json' artifact in temporary directories, which is commonly used for C2 address overrides.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
106
Detects browser extension manifest.json files requesting declarativeNetRequest and content_scripts/host_permissions covering AI assistant vendor domains (BragJack attack class)
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
003
Detects browser extension manifest.json files requesting declarativeNetRequest and content_scripts/host_permissions covering AI assistant vendor domains (BragJack attack class)
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
003
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
203
Detects instances where a browser process (chrome.exe) accesses the microphone or camera within a 2-minute temporal window of communicating with 'gemini.google.com'. This rule is intended to identify potential unauthorized use of system peripherals in the context of an AI-agent session.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
303
Detects instances where a browser process (chrome.exe) accesses the microphone or camera within a 2-minute temporal window of communicating with 'gemini.google.com'. This rule is intended to identify potential unauthorized use of system peripherals in the context of an AI-agent session.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
003
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
103
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
003
Detects rapid AI agent state transitions (from 'think' to 'act') within Microsoft Edge processes, specifically identifying potential exploitation of the CVE-2026-55945 race condition vulnerability, which could be used to force the unauthorized execution of an injected prompt.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
203
Detects rapid AI agent state transitions (from 'think' to 'act') within Microsoft Edge processes, specifically identifying potential exploitation of the CVE-2026-55945 race condition vulnerability, which could be used to force the unauthorized execution of an injected prompt.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
003
Detects rapid AI agent state transitions (from 'think' to 'act') within Microsoft Edge processes, specifically identifying potential exploitation of the CVE-2026-55945 race condition vulnerability, which could be used to force the unauthorized execution of an injected prompt.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
003
Detects high-frequency, automated interactions with popular AI assistant web interfaces (e.g., Gemini, Perplexity, Claude, Copilot) from common browser processes. This pattern often indicates unauthorized automated data submission or scraping, which may follow or facilitate automated exfiltration of browser-resident data.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
003
Page 269 of 1871