Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation of specific forensic log files (browser_decryption.log, sends.log) within the %TEMP% directory. These files are indicators of the data collection stage performed by the Rapuncel infostealer prior to archiving and exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects a suspicious sequence of events where a user's registered phone number or recovery contact method is updated, followed shortly by an MFA factor reset or new factor enrollment. This pattern is a common indicator of a SIM-swap attack, where an attacker intercepts SMS-based MFA codes after hijacking the victim's phone number.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects multiple MFA push notifications generated within a short timeframe for a single user during a Self-Service Password Reset (SSPR) flow. This behavior is indicative of an attacker attempting to perform MFA fatigue/push harassment to gain unauthorized access via SSPR or to bypass account security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous account recovery or MFA reset activity performed by a single help-desk user account. A high volume of reset actions across numerous distinct users within a short duration is a key behavioral indicator of potential help-desk account compromise or insider abuse involving unauthorized account takeovers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects multiple MFA push notifications generated within a short timeframe for a single user during a Self-Service Password Reset (SSPR) flow. This behavior is indicative of an attacker attempting to perform MFA fatigue/push harassment to gain unauthorized access via SSPR or to bypass account security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects ZIP archives exceeding 100MB that contain specific DLL filenames often used for junk-padding to evade sandbox analysis. This technique is observed in brand-impersonation campaigns targeting users with fake security or authentication software lures.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the staging of ChainScript files into specific, masquerading subdirectories within user AppData folders that mimic legitimate Windows system paths. This activity is indicative of the _scatter.ps1 script redistributing components such as the Node.js runtime, agent configuration, and helper utilities before execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects instances where common script interpreters (powershell.exe, cmd.exe, mshta.exe, etc.) are launched by developer-centric processes (node.exe, npm.exe, Code.exe) with suspicious command-line arguments often used for reconnaissance, payload downloading, or obfuscated command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the execution of known remote access or remote monitoring software (such as TeamViewer, AnyDesk, or ScreenConnect) on corporate-issued Windows endpoints. The rule triggers on process execution patterns associated with unauthorized remote control, specifically looking for indicators of unattended access or silent installation commonly used by overseas actors to remotely operate company-issued laptops assigned to fraudulently hired identities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects instances where Microsoft Visual Studio Code (Code.exe) spawns common interpreters or command-line tools (such as node, python, cmd, or powershell) that are not associated with known internal VS Code process behaviors like renderer tasks or tunnel operations. This activity may indicate malicious use of the integrated terminal or extension execution contexts to execute unauthorized code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the execution of known remote access or remote monitoring software (such as TeamViewer, AnyDesk, or ScreenConnect) on corporate-issued Windows endpoints. The rule triggers on process execution patterns associated with unauthorized remote control, specifically looking for indicators of unattended access or silent installation commonly used by overseas actors to remotely operate company-issued laptops assigned to fraudulently hired identities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects Node.js or Python processes exhibiting behavior characteristic of information-stealing malware (such as the WaterPlum suite: BeaverTail, InvisibleFerret, OtterCookie, StoatWaffle). The rule monitors for these processes accessing sensitive files related to browser credentials, cryptocurrency wallets, scanned identification documents, or performing collection activities like keylogging and screen capturing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the use of PowerShell cmdlets (Add-MpPreference or Set-MpPreference) to modify Microsoft Defender exclusions (paths, processes, or extensions). This behavior is often associated with adversaries attempting to evade security detection by excluding malicious files or processes from being scanned by Microsoft Defender.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
203
Detects suspicious command-line patterns typically used for downloading or executing malicious payloads, such as curl, base64 encoding, and PowerShell web requests, when spawned directly from Node.js or Visual Studio Code processes. This behavior is associated with supply chain compromises and loader activity (e.g., WaterPlum/Contagious Interview) targeting development environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects user authentication events to recruitment, career, or applicant-tracking applications where the connection originates from an anonymizing proxy, VPN, or datacenter IP address. This behavior has been observed as a precursor to North Korean IT worker recruitment fraud, where attackers mask their true geographic location to gain unauthorized employment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects Node.js or Python processes exhibiting suspicious behavior consistent with information-stealing malware (such as BeaverTail or InvisibleFerret). The rule monitors for these processes accessing sensitive files, including browser credentials, cookies, browser extension wallet settings, cryptocurrency wallet files, and various identification document image types, followed by the execution of archiving utilities (e.g., zip, rar, 7z) to stage the collected data for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
103
Detects the creation or modification of registry entries within the 'HKCU\...\Run' hive that point to executables located in suspicious or atypical directories such as 'ProgramData', 'Users\All Users', or specific non-standard application paths often used by malware for persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the use of PowerShell to modify Microsoft Defender preferences by adding exclusion paths, processes, or extensions shortly after the creation of Registry Run keys. This sequence is characteristic of post-exploitation activity where an adversary establishes persistence and subsequently attempts to neutralize security software monitoring of their malicious payloads to avoid detection during future execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
This rule detects the creation of a file within the SysWOW64 directory followed by an immediate modification or creation of a Windows Run registry key within a 10-minute window. This behavior is indicative of a persistence mechanism where a malicious file is dropped to a system directory and registered for execution at system startup or user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
103