Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
101
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
101
Detects suspicious use of Windows API functions (SetWindowsHookEx) often associated with keylogging, correlated with the presence of temporary staging files in common directories (e.g., Temp, AppData). The rule excludes known legitimate applications that frequently utilize system hooks.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
101
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
101
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
101
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
001
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects OtterCookie JavaScript-based RAT/infostealer malware artifacts associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects OtterCookie JavaScript-based RAT/infostealer malware artifacts associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects OtterCookie JavaScript-based RAT/infostealer malware artifacts associated with WaterPlum/Contagious Interview campaign
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
001
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
001
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
001
This rule monitors for the presence or execution of files matching a known set of SHA256 hashes associated with the 'DXSCAN' malware, utilizing both device file and process events.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
23 days ago
002
This rule monitors for the presence or execution of files matching a known set of SHA256 hashes associated with the 'DXSCAN' malware, utilizing both device file and process events.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
102
Detects file and process activity associated with the Hermes ransomware, specifically targeting the presence of 'SOUL.md' files, '.hermes' file paths, and the 'HERMES_DISABLE_SAFETY=1' command-line argument.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
202
This rule monitors various logs (device network events, Entra ID sign-ins, cloud application events, and email events) for any interaction with a predefined list of indicator IP addresses identified as being associated with malicious actor egress traffic.
avatar
F S@Fsdr
avatar
Detections.ai Community
26 days ago
305
Detects persistence attempts related to the NetSupport Manager remote access tool by monitoring modifications to Windows Registry keys associated with run keys, Winlogon notification packages, and services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
102
This rule detects potentially malicious file access patterns by the executable 'comet.exe'. It alerts when this process accesses sensitive files or directories associated with credentials, configuration files, or sensitive browser data, while explicitly excluding benign locations such as Chrome data folders and temporary directories.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
102
Detects the execution of a hidden PowerShell process that subsequently spawns a child process using the 'Start-Process' cmdlet with the '-Verb RunAs' argument within a short time window. This pattern is commonly associated with attempts to bypass User Account Control (UAC) or execute processes with elevated privileges silently.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
102
Page 287 of 1871