Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects outbound TLS traffic to the domain 'trace-flow.ru', which is associated with Max Messenger covert telemetry beaconing behavior. The rule inspects the Server Name Indication (SNI) field in the TLS handshake for the specific domain string.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects high-frequency outbound TLS connections to 'api-gost.oneme.ru', which is indicative of potential bulk contact list uploading, possibly related to unauthorized data collection by the Max Messenger application.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects rapid termination of specific mobile messenger applications (Max) within seconds of starting, while indicators of the Frida dynamic instrumentation tool are concurrently detected on the device. This pattern suggests the application is identifying the presence of a hooking/instrumentation environment and self-terminating as a defense mechanism. The detection is further correlated with failed connection attempts to the application's backend.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
001
Detects rapid termination of specific mobile messenger applications (Max) within seconds of starting, while indicators of the Frida dynamic instrumentation tool are concurrently detected on the device. This pattern suggests the application is identifying the presence of a hooking/instrumentation environment and self-terminating as a defense mechanism. The detection is further correlated with failed connection attempts to the application's backend.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
101
Detects rapid termination of specific mobile messenger applications (Max) within seconds of starting, while indicators of the Frida dynamic instrumentation tool are concurrently detected on the device. This pattern suggests the application is identifying the presence of a hooking/instrumentation environment and self-terminating as a defense mechanism. The detection is further correlated with failed connection attempts to the application's backend.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
001
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
004
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
002
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
004
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
004
Detects potentially malicious script execution chains where a user launches a JavaScript file (.js/.jse) from commonly abused directories (Downloads, Documents, Desktop, AppData, WinRAR temporary folders) via wscript.exe, which subsequently spawns PowerShell and establishes an external network connection within a short time window. This behavior is commonly associated with malware loaders, phishing attachments, and initial access payloads.
avatar
Ajay Kumar@Karanajay
avatar
Detections.ai Community
13 days ago
202
Detects the presence of a specific Russian-language error string ("Не удалось сгенерировать HWID") within binary files, which is characteristic of the HWID generation mechanism used by Vidar Stealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the spawning of command-line interfaces such as cmd.exe, powershell.exe, or pwsh.exe as child processes of the SharePoint web application worker process (w3wp.exe). This behavior is highly irregular for a web server process and is indicative of potential exploitation, such as remote code execution (RCE) via web application vulnerabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects malicious deserialization attempts targeting Microsoft SharePoint, specifically leveraging System.Data.Services.Internal.ExpandedWrapper combined with LosFormatter and System.Xaml.XamlServices. This signature is indicative of exploitation attempts related to CVE-2026-65660, allowing an attacker to achieve remote code execution by bypassing SafeControls restrictions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects potential malicious PowerShell activity involving suspicious file paths in 'C:\Users\Public\' and the use of 'UPLOAD' command strings, which may indicate the staging and execution of payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects network connections from workstation subnets to domain controllers using administrative protocols such as SMB (445), RPC (135), RDP (3389), or WinRM (5985/5986). This activity is indicative of lateral movement attempts by an adversary attempting to reach critical infrastructure from a compromised workstation in a flat or poorly segmented environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects an exploitation attempt against the SharePoint WebPartPagesWebService using the GetWebPartPageConnectionInfo method. The rule monitors for suspicious input patterns such as 'Register' and 'ignoreParentFrozen' within the URI query, which are indicative of a directive injection vulnerability.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects large and sustained outbound TCP data transfers to external networks, which may indicate mass data exfiltration. The rule monitors established sessions and uses a threshold to identify unusual outbound traffic volume over an extended period.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects unauthorized modifications to the Entra ID authentication methods policy or suspicious application activity often associated with the staging of rogue External Authentication Methods (EAM). Adversaries may exploit these configuration changes to intercept or bypass multi-factor authentication (MFA) during user login processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
202
Detects network activity associated with a VBScript-based dropper attempting to retrieve payloads from known malicious infrastructure (cdn.imageurlgenerator.com) or abusing legitimate file hosting services (filemail.com) to bypass traditional security filters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the modification or creation of Azure AD applications that include specific malicious redirect URIs associated with 'TrustSink' style attacks, which abuse external authentication callback mechanisms to intercept tokens and bypass MFA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects an attempt to exploit a quote-injection vulnerability within the SharePoint ToolPane.aspx page, specifically targeting the Register directive to bypass SafeControls restrictions. This pattern is commonly used for remote code execution or unauthorized application behavior modifications by manipulating server-side parsing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002