Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule detects unauthorized screen surveillance on Android devices by correlating the execution of the minicap binary with subsequent network activity indicative of screen data exfiltration to a command-and-control (C2) server. It specifically looks for connections to known exfiltration paths associated with screen monitoring or video uploads within 30 minutes of minicap process activity, effectively identifying surveillance that bypasses Android's MediaProjection consent mechanism.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects instances where an Android application, installed from a non-standard source (sideloaded via ADB or unknown sources), requests the BIND_ACCESSIBILITY_SERVICE permission for a service named 'SystemHelper'. This behavior is characteristic of mobile malware like Rathat that leverages accessibility services to gain unauthorized control over user credentials and bank accounts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the use of the 'getevent' command by a shell process to read raw touch input data from '/dev/input/event*'. This behavior is associated with Android malware attempting to capture user interaction or credentials by monitoring touch events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects network traffic associated with the RatHat malware family, which leverages the Gemini API to perform automated UI navigation on Android devices. The rule identifies both the outgoing prompt containing UI analysis instructions and the corresponding incoming API response containing coordinate-based navigation instructions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects network communication to specific API endpoints associated with the RatHat Android malware, which leverages accessibility services for overlay-based credential harvesting and data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects anomalous attempts to silently reinstall an APK or modify accessibility settings via a local ADB shell daemon (identified by specific local-service file paths). This behavior is characteristic of Android malware, such as RatHat, attempting to maintain persistence and gain unauthorized permissions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects network requests related to the RatHat Android malware, specifically focusing on the retrieval of the 'minicap' tool used for screen capture and the subsequent exfiltration of captured screen data or video chunks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects instances where an Android accessibility service named 'SystemHelper' programmatically modifies system settings to enable developer options, ADB debugging, or wireless debugging. This behavior is indicative of malicious applications attempting to gain unauthorized control over device configuration, often seen in Android banking trojans to facilitate command and control or data extraction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects instances where an Android application attempts to initiate an ADB wireless pairing process by connecting to the local loopback address (127.0.0.1). This behavior is characteristic of malicious applications, such as the RatHat malware, attempting to gain unauthorized ADB access to the device to bypass security sandboxes or manipulate device settings.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects the execution of known malicious binaries or disguised Go-based daemons (such as frpc, liblocal-service, or libmedia_codec) within the /data/local/tmp/ directory by the Android 'shell' user. This activity is indicative of Rathat malware or similar threats leveraging ADB for persistent C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects anomalous ADB commands used by the RatHat Android malware to achieve persistence. This includes adding apps to the battery optimization whitelist, changing application standby buckets to 'active' to bypass background restrictions, disabling specific user-mode applications, or modifying accessibility service configurations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects network activity associated with the 'RatHat' Android malware, specifically identifying attempts to retrieve tunnel configuration, deployment confirmation, and the initial reverse tunnel handshake using the fatedier/frp (Fast Reverse Proxy) tool.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects network beaconing and command-and-control (C2) communication patterns associated with the RatHat Android malware family. The rule identifies registration, shell command check-ins, heartbeat signals, and task fetching activity over HTTP. It uses stateful inspection (flowbits) to correlate device registration with subsequent heartbeat behavior to improve detection fidelity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects a non-system application using the PackageInstaller Session API to perform sideloading followed immediately by a request or binding to an AccessibilityService. This behavior is indicative of malicious droppers or malware (such as the RatHat Android malware family) attempting to bypass install restrictions and gain elevated control over the device to manipulate settings like Developer Options or Wireless Debugging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects infostealer malware (e.g., Vidar, Lumma, RedLine) that specifically searches for Claude/Anthropic session cookies, API tokens, and generic browser-based credential storage artifacts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects phishing emails masquerading as legitimate DocuSign remittance advice notifications. The rule identifies emails containing specific keywords related to PDF sharing or remittance advice originating from 'docusign' and featuring suspicious, alternating-case hyperlinks often used in credential phishing campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects execution of remote payloads by piping the output of network utilities like curl or wget directly into a shell interpreter (bash, sh, zsh). This pattern is a common technique used by attackers to execute malicious scripts directly from a remote server without saving a file to disk.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects high-risk administrative actions in Microsoft 365, such as new MFA method registration, OAuth app consent grants, or email forwarding rule creation, occurring in sessions that lack fresh authentication (often indicative of a session-cookie replay attack).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects Microsoft 365 sign-in events where MFA was successfully satisfied, but the sign-in is simultaneously flagged by risk detection engines as exhibiting anomalous token or session characteristics, indicative of Adversary-in-the-Middle (AiTM) session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detects Azure AD/Entra ID sign-ins performed using the OAuth device-code flow, excluding common administrative tools like the Azure CLI or PowerShell. This flow is frequently abused in phishing campaigns (such as EvilTokens or ARToken) where attackers entice victims to enter a device code into a malicious application, allowing the attacker to gain authorized access to the victim's session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000
Detection of network traffic patterns associated with the NovaCookies Adversary-in-the-Middle (AiTM) phishing kit. The rules monitor for DNS queries for .vu domains, HTTP requests to lookalike Microsoft 365 login pages hosted on .vu domains, POST requests containing credential data, and the receipt of specific session cookies (ESTSAUTH) indicative of successful AiTM session interception.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
000