Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule monitors network, DNS, and HTTP activity to identify connections to known infrastructure associated with the ClickFix social engineering campaign and Vidar infostealer malware. The rule correlates device network events, HTTP request events, and DNS queries against a list of known malicious domains, IP addresses, and URL patterns used for C2, staging, and lures.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
11 days ago
001
This rule detects potential staging activity for ClickFix or Vidar malware campaigns. It identifies the creation of files or folders in directories mimicking Windows Diagnostics infrastructure (WDI) or known payload paths, correlated with the execution of suspicious PowerShell commands or archive-related utilities within a 30-minute window on the same device.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
This rule detects malicious activity related to the exploitation of MpDlpService.exe. It looks for the execution or presence of known malicious file hashes associated with this threat, including a P-stage script, payload files, and a malicious mpclient.dll. Additionally, it identifies instances where the legitimate MpDlpService.exe binary is executed from a non-standard, suspicious directory, which is a common indicator of side-loading or persistence techniques.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
101
This rule detects malicious activity related to the exploitation of MpDlpService.exe. It looks for the execution or presence of known malicious file hashes associated with this threat, including a P-stage script, payload files, and a malicious mpclient.dll. Additionally, it identifies instances where the legitimate MpDlpService.exe binary is executed from a non-standard, suspicious directory, which is a common indicator of side-loading or persistence techniques.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
001
This rule set detects network communication patterns associated with the AnonyMousKIT phishing kit, specifically targeting the exfiltration of captured user credentials to the Telegram Bot API and communication with known phishing panel infrastructure. It monitors for DNS lookups of 'anomkit.shop', established TCP connections to the associated backend relay, and HTTP requests containing specific credential-related keywords directed towards the Telegram API.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects phishing emails purportedly from Docusign that contain malicious links which redirect users through legitimate identity provider domains (e.g., login.microsoftonline.com, accounts.google.com) before landing on non-trusted infrastructure. This redirect-chain pattern is indicative of NovaCookies Adversary-in-the-Middle (AiTM) delivery, used to facilitate credential or session cookie theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects phishing attempts leveraging SendGrid infrastructure to send emails that impersonate well-known financial brands. The detection looks for emails with authentication checks passing (SPF/DKIM/DMARC) where the sender domain is suspicious (e.g., .asia or .com not matching the brand) and the volume of such messages suggests an automated campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
This rule monitors for two distinct suspicious patterns: first, the interaction between Claude Desktop and the CEF (Chromium Embedded Framework) library, which may indicate unauthorized plugin or extension loading; second, the execution of non-standard binaries initiated by various JetBrains IDE processes located outside of standard program directories, which could indicate process hollowing or unauthorized tool execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects web proxy requests that resemble phishing attempts targeting Apple Activation Lock. The rule identifies URLs containing specific Apple-related keywords in combination with common phishing URL paths, while filtering out legitimate Apple support documentation pages.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the presence of the i-Realm companion tool associated with the AnonyMousKIT PhaaS platform, which is designed to bypass iOS Activation Lock features.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects interaction between an internal host and the Vapi.ai API, typically used for automating AI-based voice phishing (vishing) calls. It identifies the initiation of a call via POST requests to the Vapi.ai API and subsequent callbacks from Vapi.ai to an attacker-controlled webhook endpoint used for tracking call status.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects artifacts associated with the JWR phishing framework client engine, specifically focusing on the presence of self-referential .toString().search() anti-debugging checks, decoy variable naming conventions, and WebSocket communication components (JWRCID/JWRCVV, ws-worker.js) used for session establishment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the presence of known AnonyMousKIT Phishing-as-a-Service (PhaaS) shared components (legacy.js, Core.js, ToolsController.php) by matching specific file hashes or detecting these filenames in small files. This rule is designed to identify backend infrastructure used by phishing resellers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects network indicators and session patterns associated with the JWR Phishing Framework, specifically targeting its WebSocket-based command and control (C2) communication, client engine (main.js/ws-worker.js) retrieval, and unique session token (JWRCVV) usage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the creation or writing of the specific log file '/logs/send_sms_apix.log' associated with the AnonyMousKIT Phishing-as-a-Service (PhaaS) platform. This file is typically used by the kit to record SMS billing or gateway activity during a phishing operation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects network connections (TLS SNI and HTTP requests) to domains associated with the AnonyMousKIT PhaaS (Phishing-as-a-Service) platform. It flags connections to known phishing backend domains and monitors for access to suspicious management dashboard paths commonly utilized by this threat actor for managing phishing orders and communications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects incoming emails that use 'Apple' or 'Find My' related strings in the sender display name while originating from common consumer email relay domains like Gmail or iCloud, which is indicative of a social engineering or phishing attempt attempting to impersonate Apple support.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects DNS queries for domains containing specific brand-related strings (such as government agencies or courier services) coupled with high-risk top-level domains (TLDs). This pattern is frequently used by adversaries to register infrastructure for phishing and social engineering campaigns by mimicking legitimate organizational presence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
102