Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects malicious BASH_ENV injection within GitHub Actions CI pipelines originating from the compromised sckit_poetry_build.py build backend. The injection, which targets GITHUB_ENV to introduce a malicious _pypi_bridge.sh script, is used to intercept PyPI publishing tokens during build processes, characteristic of the MemTensor/sckit supply chain attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the SCKit Go-based credential-stealing implant found in compromised npm and PyPI packages. The detection logic focuses on unique build-info module paths, specific C2 encryption protocol headers, and embedded campaign identifiers related to 'memos-cloud-openclaw-plugin' and 'MemoryOS' supply chain compromises.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the creation of files or directories under specific paths (/.openclaw/ and /.sckit/) used by the sckit Go-based worm. This worm, distributed via compromised npm and PyPI packages, uses these directories to track state and coordinate execution on infected Linux systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects high-privilege IAM roles (roles/owner, roles/resourcemanager.organizationAdmin) being granted at the GCP organization level. This activity is indicative of the ConfigConfusion attack, where a low-privilege user exploits a Kubernetes ConfigConnector (KCC) controller's high-privilege service account to perform unauthorized IAM modifications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects suspicious activity associated with the DarkMe RAT, specifically targeting cryptocurrency wallet data files. The rule correlates file access to known wallet data paths by a hollowed process 'clspack.exe', followed by suspicious outbound network activity originating from that same process, and potentially preceded by WMI-based antivirus enumeration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects anomalous command execution patterns indicative of DarkMe/Graphalgo-style RATs. The detection triggers when a single parent process initiates multiple suspicious C2-driven actions within a 24-hour window. These actions include executing Go language commands, Node.js script execution, or delayed self-deletion sequences.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects network communication (DNS queries and TLS connections) to known actor-controlled Slack workspace subdomains, as well as the presence of a specific hardcoded public key in Slack API traffic, suggesting the use of Slack as a Command and Control (C2) channel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects potential exfiltration of sensitive DevOps credentials or configuration files (such as AWS credentials, SSH keys, Kubernetes configs, or cryptocurrency wallets) by monitoring for file access events followed by outbound network connections to known exfiltration channels like Slack or specific C2 infrastructure within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects post-exploitation shell activity spawned from the IIS worker process (w3wp.exe), narrowed to command lines carrying encoded/obfuscated PowerShell flags, remote-download cradles, or basic recon/persistence commands (whoami, certutil, bitsadmin, schtasks, reg add). This reduces noise from benign w3wp.exe-initiated automation while retaining the behavioral pattern seen in the Telerik UI for ASP.NET AJAX unauthenticated RCE chain (webshell/in-memory DLL execution dropping to a shell).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
11026
Detects execution of potentially malicious scripts (a2.cmd) or unusual DLL loading behavior via rundll32.exe. This activity is often associated with staging or executing malicious payloads using non-standard naming conventions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where a Terraform provider process spawns a child process (go.exe or cmd.exe) to execute 'go run .'. This behavior is atypical for standard Terraform provider execution and may indicate the use of malicious providers that compile and execute code on-the-fly, a technique used to evade signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where a Terraform provider process spawns a child process (go.exe or cmd.exe) to execute 'go run .'. This behavior is atypical for standard Terraform provider execution and may indicate the use of malicious providers that compile and execute code on-the-fly, a technique used to evade signature-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where a Terraform provider process initiates a child process that is either the Go runtime (executing 'go run') or a Windows command shell (cmd.exe, powershell.exe). This behavior is often indicative of malicious code execution during the provider's execution lifecycle, potentially exploiting vulnerabilities in the Terraform provider ecosystem.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a Go toolchain process (go.exe) spawning potentially suspicious child processes such as secondary 'go run' commands or Node.js execution. This behavior is indicative of a malicious Go module executing embedded or decrypted code during the build process, a tactic seen in supply chain attacks targeting development environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of package management commands (npm, pip, python) within directories or command-line arguments containing 'veltrix' or 'veltrix-capital', which may indicate the use of malicious dependencies or cloned repository lures.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where a process that is not a recognized web browser accesses or enumerates the file storage path of the MetaMask browser extension. This behavior is indicative of unauthorized reconnaissance or credential theft attempt targeting cryptocurrency wallet data stored locally, often performed by malware following successful system compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects suspicious execution patterns characteristic of post-exploitation activity, such as invoking 'go run' or 'node' from non-standard directories like AppData or Temp, as well as the use of command-line routines to delete files after execution (often associated with self-deleting secondary payloads or persistence cleanup).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects network connections to the Slack API (api.slack.com) initiated by processes executing from temporary directories commonly used by the Go build system ('go-build'). This pattern is indicative of a second-stage RAT or malicious payload compiled on-the-fly using 'go run' or similar mechanisms, utilizing Slack's infrastructure for C2 communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where Node.js, Python, or Go processes spawn command shell interpreters (cmd.exe, powershell.exe, etc.). This behavior is often indicative of C2 command execution by malware, such as the Graphalgo RAT, which may use these languages to execute shell-level commands after initial infection or payload execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where common scripting or development language runtimes (Go, Node.js, WScript, CScript) access sensitive configuration or credential files, such as AWS credentials, Kubernetes configs, SSH keys, or environment files. This activity is often indicative of credential harvesting or unauthorized access to sensitive secrets by potentially malicious scripts or processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001