Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects network connection events initiated by known beaconing-related process names. These processes are associated with command and control infrastructure or pivot nodes often used by adversaries for post-compromise activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects Node.js processes executing suspicious command lines that involve fetching and executing remote JavaScript code. This behavior is indicative of a loader or downloader script commonly used to pull and evaluate malicious payloads at runtime, specifically referencing indicators associated with 'GHAPPIER'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects network beaconing activity from suspicious processes that masquerade as macOS system services, specifically filtered to only trigger when an active Cursor IDE session is detected on the host. This behavior correlates network-based C2 activity with an active development environment, potentially indicating an adversary using legitimate IDE sessions to blend in or exfiltrate development-related data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
KQL Query from file: Rapid bash + Terminal.app burst indicating bulk macOS TCC consent sequence
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
201
Detects the reuse of session tokens from distinct network locations, devices, or user agents shortly after a successful MFA-protected login. This behavioral pattern is a primary indicator of Adversary-in-the-Middle (AiTM) phishing, where attackers capture session tokens via reverse proxy to bypass authentication controls.
avatar
Myat Min Khant@blitzkri3g
avatar
Detections.ai Community
14 days ago
113
Detects when a namespace-scoped identity creates, updates, or patches AWS or Azure IAM-related custom resources in Kubernetes. This pattern monitors for a 'confused deputy' scenario where a user might attempt to leverage high-privilege cloud operators (like ACK or ASO v2) that operate with a shared high-privilege identity to modify cloud IAM configurations.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects unauthorized or suspicious use of Google Cloud Config Connector (KCC) service accounts to apply high-privilege IAM roles ('roles/owner' or 'roles/resourcemanager.organizationAdmin') at the Organization or Folder scope. This rule monitors for 'SetIamPolicy' API calls where the principal is identified as a KCC-related service account, flagging potential exploitation of KCC's authority to grant excessive permissions.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
101
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
Detects the use of the ntdsutil.exe utility to create an Install From Media (IFM) backup. This technique is often used by adversaries to create a copy of the Active Directory database (NTDS.dit) for offline credential extraction.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the installation and execution of Cloudflare Tunnel (cloudflared.exe) as a Windows service. Adversaries may abuse this utility to create unauthorized persistent network tunnels, enabling covert remote access to the internal network. This rule correlates process creation events involving 'service install' or 'tunnel run' commands with Windows service installation events referencing the cloudflared binary.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001