Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
004
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
003
Detects high-frequency anonymous comment submissions to 'wp-comments-post.php' from a single IP address within a 10-minute window, characterized by minimal variations in User-Agent. This behavior is indicative of an automated script attempting to bypass comment moderation settings, potentially exploiting known vulnerabilities (e.g., CVE-2026-93485) to inject content without administrative approval.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
003
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
003
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
003
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
104
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects signs of the ClosedQuorum implant by correlating at least two redundant persistence mechanisms (Registry Run keys, Scheduled Tasks, WMI execution) on the same host within a 10-minute window. The rule focuses on artifacts originating from suspicious user-writable paths or unsigned binaries, while excluding known legitimate installation paths.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
102
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
102
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
This rule monitors for coordinated persistence efforts by detecting the occurrence of at least two out of three specific persistence techniques (registry run key modification, scheduled task creation, or WMI-based script execution) on the same device within a 30-minute window. It explicitly filters out activities from signed binaries or those occurring in standard system/application directories, focusing on potentially malicious artifacts originating from user-writable locations.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects anomalous, high-frequency requests from a single source IP targeting sensitive NetScaler/Citrix ADC Gateway paths. This behavior is indicative of automated reconnaissance or vulnerability scanning often preceding exploitation attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects potential process injection attempts (e.g., Early Bird APC injection or process hollowing) where a process is spawned in a suspended state, followed shortly by a remote-thread or QueueUserAPC injection primitive targeting that same process. The rule correlates process creation events with subsequent API calls while excluding known legitimate patterns like .NET runtime operations, system updaters, and EDR/AV security components.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects the ClosedQuorum 'unhook' evasion technique where a process patches ntdll's EtwEventWrite to suppress ETW telemetry, occurring within a 5-minute window of the same process initiating outbound network connections to known LLM C2 provider APIs or Discord webhooks used for AI-arbitrated decision cycles.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
This rule detects HTTP POST requests to .php files containing suspicious PHP execution functions in the request body, such as 'system', 'eval', or 'shell_exec'. These patterns are indicative of an attempt to execute commands via an in-memory or injected PHP web shell on an F5 BIG-IP APM device.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001