Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects non-browser processes performing file operations (create, modify, rename) on known web browser credential storage, configuration files, and cryptocurrency wallet artifacts in a short duration. This behavior is indicative of credential harvesting or information stealing activity often associated with malware like Vidar, which stages these sensitive files for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
103
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
003
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
103
Detects the execution of PowerShell with suspicious command-line arguments (headless mode, hidden window, encoded commands) spawned by WScript.exe. This pattern is commonly associated with obfuscated script execution or fileless malware staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
205
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects network communication associated with the SectopRAT/ArechClient2 remote access trojan, specifically identifying its characteristic length-prefixed, AES-encrypted command-and-control handshake on non-standard ports. The rule matches traffic containing a specific length-prefixed packet structure starting with null bytes, typically seen during C2 check-in.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
301
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects network communication with 10729e014d0e.skyleen.fr, associated with the SCKIT malware downloading binaries during CI/CD emitter activities. This rule flags potential ingress tool transfers as part of a supply chain compromise campaign identified as 'memos-semi-nuclear'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects specific C2 communication patterns associated with SCKIT, including HTTPS beaconing to the skyleen.fr domain and structured URI patterns used for configuration and status requests.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of the 'sckit' Go-based implant when spawned by Node.js or Python processes using the command-line arguments 'stage0 --config64'. This pattern is associated with malicious npm and PyPI supply chain packages (memtensor) designed to harvest credentials and establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects malicious BASH_ENV injection within GitHub Actions CI pipelines originating from the compromised sckit_poetry_build.py build backend. The injection, which targets GITHUB_ENV to introduce a malicious _pypi_bridge.sh script, is used to intercept PyPI publishing tokens during build processes, characteristic of the MemTensor/sckit supply chain attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002