Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the drop and execution of the AvisLoader rootkit component, hmn_hook.dll. The rule identifies suspicious file drops in non-standard, user-writable directories (e.g., AppData, Temp) that are not associated with legitimate installers, as well as the loading of unsigned or non-Microsoft-signed versions of the DLL accompanied by hook-related process arguments such as HMN_HideStart or NtQuerySystemInformation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects potential manual paste-and-run execution patterns where a shell or interpreter is launched directly from Windows Explorer (e.g., via the Run dialog or manual clipboard paste), correlated with either command-line references to or outbound network connections towards Cloudflare Tunnel services (trycloudflare.com, workers.dev). The rule specifically identifies one-off execution events by excluding cases where explorer.exe spawns multiple child processes simultaneously, indicating non-routine shell behavior.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
101
Matches known SHA-256 hashes of AvisLoader toolkit components recovered from an exposed staging server: the Windows loader client, UAC-bypass helper, and process-hiding DLL
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects AvisLoader Windows loader requiring both decoy non-executable packer-named sections and an embedded c-toxcore developer build path to co-occur in a valid PE
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects AvisLoader Windows loader requiring both decoy non-executable packer-named sections and an embedded c-toxcore developer build path to co-occur in a valid PE
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
001
Detects the execution of 'Silent XMR Miner Builder.exe' followed by the spawning of common compilers (e.g., csc.exe, gcc.exe, donut.exe), which is indicative of a developer tool being used to compile and build a cryptocurrency mining payload.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects endpoint network connections to Heroku-hosted domains containing Google Ads tracking parameters (gclid, gad_source, gad_campaignid). This activity is associated with the initial staging phase of 'ShopEase' style malware delivery chains, where users are directed to decoy pages that prepare the environment for subsequent malicious browser-based actions.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
Detects instances where msiexec.exe is used in conjunction with specific application names (Spotify, Zoom, Teams) in the command line, and subsequently launches suspicious child processes such as wscript.exe, cscript.exe, or powershell.exe with specific script or executable arguments. This pattern is often associated with malicious installers or trojanized software attempting to execute embedded payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
103
Detects anomalous outbound network connections initiated by security and developer tooling (Trivy, Checkmarx, LiteLLM, Telnyx). This behavior is consistent with supply-chain attacks, such as those attributed to the UNC6780/TeamPCP threat group, where compromised tooling is leveraged to exfiltrate sensitive cloud credentials or API keys to external, non-vendor infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects high-volume, individually-tailored spear-phishing campaigns likely assisted by Generative AI. The rule monitors for a single sender targeting a high number of unique recipients with distinct, non-identical email subjects within a short timeframe. It specifically flags activity involving newly registered look-alike domains and interactions with credential-harvesting patterns in URLs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule identifies potential infections associated with the MacSync malware family by matching process, file, and network indicators (hashes, malicious domains, and specific payload URLs) against endpoint telemetry. It monitors for execution of known malicious binaries, file creation events, and communication with identified command-and-control infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
001
This rule detects potential prompt injection attacks against internal AI-powered assistants, agents, or LLM gateways. It monitors network HTTP requests for common patterns used to override system instructions, bypass safety filters, or force the model to adopt a privileged, unauthorized persona (e.g., administrator or debug mode). These techniques are often used in social engineering to manipulate the AI's output or security posture.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous, high-volume file access by a single process, followed by local file compression or archiving, and subsequent outbound data transfer to a non-internal IP address. This pattern is characteristic of automated agents (like those used in the GTG-1002/Anthropic AI-orchestrated campaigns) performing rapid data triage and staging for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects Node.js processes exhibiting network activity patterns consistent with 'EtherHiding' style C2 infrastructure, characterized by multiple distinct connections to external WebSocket hosts on non-standard TCP ports within a short timeframe, potentially following interaction with a blockchain/JSON-RPC endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects anomalous activity from IDEs or AI coding assistant extension host processes (e.g., VS Code, Cursor, JetBrains). The rule alerts when these processes spawn children that access sensitive local credential files, perform network connections to non-standard/unexpected domains, or modify critical CI/CD build script configuration files, which is indicative of a supply chain compromise within the developer environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the removal of persistence mechanisms related to the 'ComponentTask33Agent' task, specifically the deletion of a scheduled task or registry Run key, followed by the deletion of associated files within specific Microsoft-themed AppData subdirectories within a 30-minute window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects anomalous child process spawning from common web browsers or productivity applications (e.g., Office, Acrobat) on hosts that have recently communicated with known LLM or code-generation APIs. This behavioral correlation is intended to identify the potential execution of AI-generated exploit code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects HTTP requests to popular LLM API services (OpenAI, Anthropic, Google, Cohere) containing common jailbreak or role-play patterns. These patterns attempt to bypass safety guardrails by using techniques such as persona-switching (e.g., 'DAN'), hypothetical scenario framing, or unauthorized security testing pretexts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the persistence sequence associated with 'ChainScript', which involves creating a hidden scheduled task using PowerShell or specific scripts, and a fallback mechanism that creates a registry run key entry if the task creation fails. The rule monitors for PowerShell commands, bridge script execution, and registry modifications involving the 'ComponentTask33Agent' or wscript.exe executing an '_agent.vbs' file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003