Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects anomalous DNS queries with high-entropy or encoded labels that exceed 40 characters in size, potentially indicating DNS tunneling used for Command and Control (C2) communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects anomalous network behavior consistent with the PolinRider malware, which uses public Ethereum JSON-RPC endpoints and blockchain explorers (e.g., Etherscan.io) as a dead-drop resolver for command-and-control (C2) communication. The rules monitor for specific RPC methods (eth_getTransactionByHash, eth_call, eth_getBalance) over HTTP/TLS and DNS resolution queries to known blockchain explorer infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects network activity associated with NetSupport Manager remote access software, specifically monitoring for connections to known malicious domains and infrastructure, as well as recurring beaconing patterns indicative of command-and-control behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects network communication to a known malicious IP address (45.32.253.166) associated with the PIVOTPIPE RAT using Cobalt Strike C2 beaconing patterns. The rule identifies TCP connections, HTTP GET requests for beacon check-ins, and HTTP POST requests for task responses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects malicious tampering with GitHub Actions workflows by monitoring for two specific patterns within an hour: the addition of automatic push triggers for the main branch alongside the removal of manual approval gates, or rapid sequential commits that rewrite workflows to facilitate an unattended publish of a package. This rule also integrates with npm registry publish events to identify potential malicious distribution of compromised packages like @dforge-core/dforge-mcp.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects the creation of files named 'parser.js' or 'loader.js' within hidden or suspicious VSCode directories (e.g., .npm/.vscode/ or AppData/VSCode/). The detection also flags potential signs of malicious intent, such as the existence of a 'package.json' file nearby or the presence of 'tokenapp' in the file path, which are often indicative of the GHAPPIER implant behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects the execution of rundll32.exe with a command line containing 'DavWWWRoot', indicating the loading of a DLL from a remote WebDAV share. This is a common technique used by attackers to execute remote malicious code while bypassing local execution policies or attempting to evade local file-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects anomalous, high-frequency access to clipboard APIs (GetClipboardData/SetClipboardData) by non-standard, unrecognized processes. The rule specifically monitors for patterns consistent with clipper malware, which polls the clipboard for cryptocurrency address formats and replaces them with attacker-controlled addresses.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
This rule identifies processes that delete themselves shortly after execution. It joins process creation events with file deletion events on the same device, filtering for cases where the initiating process file name, ID, and hash match the deleted file, and where the deletion occurs within 120 seconds of the process creation. This behavior is commonly associated with malware or adversary tools attempting to remove traces of their activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects instances where a repository's GitHub CI/CD workflow, git configuration, or repository settings are modified, followed shortly thereafter by an npm package publish event. This behavior is indicative of a supply chain compromise where an adversary modifies workflow files to auto-publish malicious versions of a package.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
Detects the execution of PowerShell via explorer.exe (typically initiated through the Windows Run dialog) where the command line references a WebDAV UNC path (containing DavWWWRoot). This behavior is characteristic of 'ClickFix' social engineering attacks, where users are coerced into copying and pasting commands into the Run dialog that trigger remote script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects malicious shell commands attempting to perform supply-chain persistence via environment variable manipulation in CI/CD environments. The rule identifies processes injecting BASH_ENV into GITHUB_ENV, a known technique used by the SCKIT supply-chain worm to perform credential harvesting during CI pipeline execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002