Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects unauthorized screen surveillance on Android devices by correlating the execution of the minicap binary with subsequent network activity indicative of screen data exfiltration to a command-and-control (C2) server. It specifically looks for connections to known exfiltration paths associated with screen monitoring or video uploads within 30 minutes of minicap process activity, effectively identifying surveillance that bypasses Android's MediaProjection consent mechanism.
Detects instances where an Android application, installed from a non-standard source (sideloaded via ADB or unknown sources), requests the BIND_ACCESSIBILITY_SERVICE permission for a service named 'SystemHelper'. This behavior is characteristic of mobile malware like Rathat that leverages accessibility services to gain unauthorized control over user credentials and bank accounts.
Detects the use of the 'getevent' command by a shell process to read raw touch input data from '/dev/input/event*'. This behavior is associated with Android malware attempting to capture user interaction or credentials by monitoring touch events.
Detects network traffic associated with the RatHat malware family, which leverages the Gemini API to perform automated UI navigation on Android devices. The rule identifies both the outgoing prompt containing UI analysis instructions and the corresponding incoming API response containing coordinate-based navigation instructions.
Detects network communication to specific API endpoints associated with the RatHat Android malware, which leverages accessibility services for overlay-based credential harvesting and data exfiltration.
Detects anomalous attempts to silently reinstall an APK or modify accessibility settings via a local ADB shell daemon (identified by specific local-service file paths). This behavior is characteristic of Android malware, such as RatHat, attempting to maintain persistence and gain unauthorized permissions.
Detects network requests related to the RatHat Android malware, specifically focusing on the retrieval of the 'minicap' tool used for screen capture and the subsequent exfiltration of captured screen data or video chunks.
Detects instances where an Android accessibility service named 'SystemHelper' programmatically modifies system settings to enable developer options, ADB debugging, or wireless debugging. This behavior is indicative of malicious applications attempting to gain unauthorized control over device configuration, often seen in Android banking trojans to facilitate command and control or data extraction.
Detects instances where an Android application attempts to initiate an ADB wireless pairing process by connecting to the local loopback address (127.0.0.1). This behavior is characteristic of malicious applications, such as the RatHat malware, attempting to gain unauthorized ADB access to the device to bypass security sandboxes or manipulate device settings.
Detects the execution of known malicious binaries or disguised Go-based daemons (such as frpc, liblocal-service, or libmedia_codec) within the /data/local/tmp/ directory by the Android 'shell' user. This activity is indicative of Rathat malware or similar threats leveraging ADB for persistent C2 communication.
Detects anomalous ADB commands used by the RatHat Android malware to achieve persistence. This includes adding apps to the battery optimization whitelist, changing application standby buckets to 'active' to bypass background restrictions, disabling specific user-mode applications, or modifying accessibility service configurations.
Detects network activity associated with the 'RatHat' Android malware, specifically identifying attempts to retrieve tunnel configuration, deployment confirmation, and the initial reverse tunnel handshake using the fatedier/frp (Fast Reverse Proxy) tool.
Detects network beaconing and command-and-control (C2) communication patterns associated with the RatHat Android malware family. The rule identifies registration, shell command check-ins, heartbeat signals, and task fetching activity over HTTP. It uses stateful inspection (flowbits) to correlate device registration with subsequent heartbeat behavior to improve detection fidelity.
Detects a non-system application using the PackageInstaller Session API to perform sideloading followed immediately by a request or binding to an AccessibilityService. This behavior is indicative of malicious droppers or malware (such as the RatHat Android malware family) attempting to bypass install restrictions and gain elevated control over the device to manipulate settings like Developer Options or Wireless Debugging.
Detects infostealer malware (e.g., Vidar, Lumma, RedLine) that specifically searches for Claude/Anthropic session cookies, API tokens, and generic browser-based credential storage artifacts.
Detects phishing emails masquerading as legitimate DocuSign remittance advice notifications. The rule identifies emails containing specific keywords related to PDF sharing or remittance advice originating from 'docusign' and featuring suspicious, alternating-case hyperlinks often used in credential phishing campaigns.
Detects execution of remote payloads by piping the output of network utilities like curl or wget directly into a shell interpreter (bash, sh, zsh). This pattern is a common technique used by attackers to execute malicious scripts directly from a remote server without saving a file to disk.
Detects high-risk administrative actions in Microsoft 365, such as new MFA method registration, OAuth app consent grants, or email forwarding rule creation, occurring in sessions that lack fresh authentication (often indicative of a session-cookie replay attack).
Detects Microsoft 365 sign-in events where MFA was successfully satisfied, but the sign-in is simultaneously flagged by risk detection engines as exhibiting anomalous token or session characteristics, indicative of Adversary-in-the-Middle (AiTM) session hijacking.
Detects Azure AD/Entra ID sign-ins performed using the OAuth device-code flow, excluding common administrative tools like the Azure CLI or PowerShell. This flow is frequently abused in phishing campaigns (such as EvilTokens or ARToken) where attackers entice victims to enter a device code into a malicious application, allowing the attacker to gain authorized access to the victim's session.
Detection of network traffic patterns associated with the NovaCookies Adversary-in-the-Middle (AiTM) phishing kit. The rules monitor for DNS queries for .vu domains, HTTP requests to lookalike Microsoft 365 login pages hosted on .vu domains, POST requests containing credential data, and the receipt of specific session cookies (ESTSAUTH) indicative of successful AiTM session interception.
