Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects activity associated with MovieReaper campaign including process, file, and network indicators
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects activity associated with MovieReaper campaign including process, file, and network indicators
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects activity associated with MovieReaper campaign including process, file, and network indicators
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
002
This rule monitors DeviceNetworkEvents for outbound network connections to a list of known malicious IP addresses associated with various C2 frameworks and malware families, as identified by threat intelligence feeds (e.g., ThreatFox). Identifying these connections helps detect potential C2 communication and ingress tool transfer.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
24 days ago
204
This rule monitors for ADFS-related security events that may indicate credential theft or authentication bypass attempts. It flags anomalous federated sign-in events (e.g., MFA bypass, unfamiliar location), unauthorized access to the ADFS DKM container in Active Directory, and suspicious attempts to export ADFS token-signing certificates.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
304
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
30 days ago
4017
This rule detects the presence of files matching known SHA256 hashes associated with the GhostCode phishing kit. It monitors for these files both in email attachments and on local device filesystems to identify potential delivery and execution of malicious phishing payloads.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
003
This rule monitors for outbound network connections to a list of known malicious IP addresses identified as part of the GhostCode command-and-control (C2) infrastructure. It uses DeviceNetworkEvents data to flag activity originating from endpoints and highlights a specific IP address used during the Intune/MDM enrollment process for further investigation.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
23 days ago
103
This rule detects internal network activity (DNS queries, network connections, and security logs) communicating with domains associated with the GhostCode phishing kit. These domains are typically used to host credential harvesting pages or phishing infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
103
Detects network activity and HTTP request headers associated with the GhostCode phishing kit. The rule identifies specific URI patterns, custom site keys, malicious User-Agent strings, and session cookie artifacts indicative of interaction with a phishing server.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
23 days ago
003
Detects network activity and HTTP request headers associated with the GhostCode phishing kit. The rule identifies specific URI patterns, custom site keys, malicious User-Agent strings, and session cookie artifacts indicative of interaction with a phishing server.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
23 days ago
203
This rule detects the presence of files matching known SHA256 hashes associated with the GhostCode phishing kit. It monitors for these files both in email attachments and on local device filesystems to identify potential delivery and execution of malicious phishing payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
003
Detects mass file renaming activity associated with OpnKey ransomware, which appends specific ransom identifiers to files. This behavior is indicative of the encryption phase of a ransomware attack, where files are renamed to reflect the encryption status or to include a unique victim identifier.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
26 days ago
106
Detects anomalous network connection attempts using DCOM (port 135) or WinRM (ports 5985/5986) that originate from external networks or exceed established internal baseline frequencies. This pattern is often indicative of lateral movement or remote administration abuse via WMI or WinRM.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
0014
Detects instances of PowerShell being launched directly by Windows Explorer (explorer.exe), which is indicative of a user interacting with the 'Run' dialog (Win+R). The rule specifically flags common ClickFix social-engineering patterns, such as hidden windows and the use of download/execution cmdlets (e.g., Invoke-WebRequest, Invoke-RestMethod) used to fetch and run remote payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Detects PowerShell command execution patterns indicative of the VelvetCake malware module. The rule identifies scripts that enumerate files within the C:\Users\Public directory, calculate file metrics using [math]::Round, and stage discovered files for transmission over a raw TCP connection using System.Net.Sockets.TcpClient.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
18 days ago
000
Page 274 of 1871