Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects HTTP requests targeting the /terminal/ws endpoint of a Marimo notebook application, which indicates an attempt to exploit CVE-2026-39987, a pre-authentication Remote Code Execution vulnerability involving WebSocket connections.
Detects a specific credential-harvesting sequence associated with the RatHat malware. This behavior involves an initial malicious overlay drawn over a targeted application to harvest credentials, followed by a secondary fake 'install failed' overlay masquerading as Google Play within a short timeframe (1 hour), occurring when a user attempts to uninstall the malicious application.
This rule detects unauthorized screen surveillance on Android devices by correlating the execution of the minicap binary with subsequent network activity indicative of screen data exfiltration to a command-and-control (C2) server. It specifically looks for connections to known exfiltration paths associated with screen monitoring or video uploads within 30 minutes of minicap process activity, effectively identifying surveillance that bypasses Android's MediaProjection consent mechanism.
Detects instances where an Android application, installed from a non-standard source (sideloaded via ADB or unknown sources), requests the BIND_ACCESSIBILITY_SERVICE permission for a service named 'SystemHelper'. This behavior is characteristic of mobile malware like Rathat that leverages accessibility services to gain unauthorized control over user credentials and bank accounts.
Detects the use of the 'getevent' command by a shell process to read raw touch input data from '/dev/input/event*'. This behavior is associated with Android malware attempting to capture user interaction or credentials by monitoring touch events.
Detects network traffic associated with the RatHat malware family, which leverages the Gemini API to perform automated UI navigation on Android devices. The rule identifies both the outgoing prompt containing UI analysis instructions and the corresponding incoming API response containing coordinate-based navigation instructions.
Detects network communication to specific API endpoints associated with the RatHat Android malware, which leverages accessibility services for overlay-based credential harvesting and data exfiltration.
Detects anomalous attempts to silently reinstall an APK or modify accessibility settings via a local ADB shell daemon (identified by specific local-service file paths). This behavior is characteristic of Android malware, such as RatHat, attempting to maintain persistence and gain unauthorized permissions.
Detects network requests related to the RatHat Android malware, specifically focusing on the retrieval of the 'minicap' tool used for screen capture and the subsequent exfiltration of captured screen data or video chunks.
Detects instances where an Android accessibility service named 'SystemHelper' programmatically modifies system settings to enable developer options, ADB debugging, or wireless debugging. This behavior is indicative of malicious applications attempting to gain unauthorized control over device configuration, often seen in Android banking trojans to facilitate command and control or data extraction.
Detects instances where an Android application attempts to initiate an ADB wireless pairing process by connecting to the local loopback address (127.0.0.1). This behavior is characteristic of malicious applications, such as the RatHat malware, attempting to gain unauthorized ADB access to the device to bypass security sandboxes or manipulate device settings.
Detects the execution of known malicious binaries or disguised Go-based daemons (such as frpc, liblocal-service, or libmedia_codec) within the /data/local/tmp/ directory by the Android 'shell' user. This activity is indicative of Rathat malware or similar threats leveraging ADB for persistent C2 communication.
Detects anomalous ADB commands used by the RatHat Android malware to achieve persistence. This includes adding apps to the battery optimization whitelist, changing application standby buckets to 'active' to bypass background restrictions, disabling specific user-mode applications, or modifying accessibility service configurations.
Detects network activity associated with the 'RatHat' Android malware, specifically identifying attempts to retrieve tunnel configuration, deployment confirmation, and the initial reverse tunnel handshake using the fatedier/frp (Fast Reverse Proxy) tool.
Detects network beaconing and command-and-control (C2) communication patterns associated with the RatHat Android malware family. The rule identifies registration, shell command check-ins, heartbeat signals, and task fetching activity over HTTP. It uses stateful inspection (flowbits) to correlate device registration with subsequent heartbeat behavior to improve detection fidelity.
Detects a non-system application using the PackageInstaller Session API to perform sideloading followed immediately by a request or binding to an AccessibilityService. This behavior is indicative of malicious droppers or malware (such as the RatHat Android malware family) attempting to bypass install restrictions and gain elevated control over the device to manipulate settings like Developer Options or Wireless Debugging.
Detects infostealer malware (e.g., Vidar, Lumma, RedLine) that specifically searches for Claude/Anthropic session cookies, API tokens, and generic browser-based credential storage artifacts.
Detects phishing emails masquerading as legitimate DocuSign remittance advice notifications. The rule identifies emails containing specific keywords related to PDF sharing or remittance advice originating from 'docusign' and featuring suspicious, alternating-case hyperlinks often used in credential phishing campaigns.
Detects execution of remote payloads by piping the output of network utilities like curl or wget directly into a shell interpreter (bash, sh, zsh). This pattern is a common technique used by attackers to execute malicious scripts directly from a remote server without saving a file to disk.
Detects high-risk administrative actions in Microsoft 365, such as new MFA method registration, OAuth app consent grants, or email forwarding rule creation, occurring in sessions that lack fresh authentication (often indicative of a session-cookie replay attack).
Detects Microsoft 365 sign-in events where MFA was successfully satisfied, but the sign-in is simultaneously flagged by risk detection engines as exhibiting anomalous token or session characteristics, indicative of Adversary-in-the-Middle (AiTM) session hijacking.
