Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects HTML, XHTML, or SVG files used in Mirage2FA phishing campaigns. These files act as stagers by constructing hidden iframes to load remote JavaScript payloads from '/api/xls/' paths, utilizing specific placeholder tokens and obfuscation techniques such as XOR deobfuscation (0xAD) and custom function wrappers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects potential account compromise by identifying a specific sequence of behavior: reconnaissance of sensitive users (HR/Payroll) via Microsoft Graph API calls, followed by the creation of inbox rules (e.g., forwarding) by the same user account within a 12-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a multi-stage local execution chain associated with the Mirage2FA malware. The activity begins with WinRAR extracting an HTML stager from an Outlook quarantine directory, followed by rundll32.exe invoking shell32.dll to open the stager, and concluding with a spawned Microsoft Edge process executing the local HTML file.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects the initialization stage of a Mirage2FA phishing attack, characterized by the execution of a locally saved HTML file in a web browser, closely followed by an outbound network connection to the ipify.org API for victim IP geolocation and fingerprinting before the malicious sign-in page is rendered.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects the specific fingerprinting sequence associated with Mirage2FA AiTM phishing campaigns. The detection triggers when a process downloads a specific JavaScript loader from an '/xls/' path, followed closely within two minutes by an IP/geolocation lookup request to common services (api.ipify.org, api.country.is, api.ipgeolocation.io), which is a characteristic precursor to credential interception.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects instances where rundll32.exe is used to invoke shell32.dll with the SHCreateLocal function, or where a web browser process (msedge.exe, chrome.exe, or firefox.exe) is spawned by rundll32.exe to open an HTML file. This pattern is often indicative of malicious activity such as HTML smuggling or local file execution attacks where rundll32 is used as a proxy to open files via the browser.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects Microsoft Graph API requests targeting user information endpoints (/v1.0/users or /v1.0/me) using specific search filters associated with payroll or human resources and identified by the Axios HTTP client User-Agent string. This pattern is consistent with reconnaissance activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
Detects specific, targeted search operations within M365 environments for keywords related to payroll, HR, and banking information. This behavior is indicative of post-compromise reconnaissance activity, often following AiTM (Adversary-in-the-Middle) session hijacking where an attacker attempts to locate financial documents and payroll correspondence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the use of a malicious 'borlndmm.dll' file intended for DLL side-loading to deploy the OnyxC2 stealer payload. The rule identifies files masquerading as NVIDIA graphics libraries or Borland memory managers that contain embedded encrypted payloads, matching known indicators for OnyxC2 activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects OnyxC2 RunPE injection behavior where a process drops or loads a suspicious sideloaded DLL (specifically borlndmm.dll) and immediately initiates a secondary process instance, indicative of process hollowing or memory unpacking of a malicious payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects instances where a non-browser process accesses multiple distinct browser credential or session artifacts (such as Login Data, Cookies, or Local State) across different browser profiles in a short period. This behavior is indicative of credential harvesting activities, often associated with C2 frameworks or post-exploitation tools attempting to steal session cookies, 2FA backup codes, or saved passwords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
202
Detects the specific behavior associated with the OnyxC2 C2 framework where a process re-spawns a child instance of itself, followed by a rapid registry modification by that child process. This pattern serves as a marker for the ONYXC2 loader configuration stage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects anomalous Microsoft Graph API activity characterized by user enumeration or querying for sensitive organizational groups (e.g., payroll, finance, HR) often associated with post-AiTM account-takeover reconnaissance. This detection specifically identifies multiple requests for sensitive URIs or high-count enumeration requests originating from suspicious User-Agent strings like 'axios/1.18.1', commonly observed in threat actor activity such as Storm-2755.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
402
Detects Microsoft 365 sign-in activity consistent with adversary-in-the-middle (AiTM) token theft. The rule identifies successful sign-ins with multi-factor authentication, immediately followed by a new session attempt for the same user within 30 minutes from a different device, IP address, or location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
202
Detects the initiation of a SOCKS5 proxy handshake from an internal host to an external destination. The rule monitors for the characteristic SOCKS5 greeting (0x05) while specifically excluding HTTP traffic to identify potential unauthorized proxy tunneling used for command and control or data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a suspicious staging behavior associated with OnyxC2 premium-tier malware. The detection identifies a process respawning itself—a common precursor to hidden VNC or credential access activity—followed by the execution of Microsoft Edge with specific utility flags typically used to masquerade as an indexing component. This pattern is characteristic of techniques used to hijack authenticated browser sessions for C2 purposes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects unauthorized processes attempting to access the memory of the Local Security Authority Subsystem Service (LSASS) with high-privilege access masks, a technique commonly used for credential dumping to harvest passwords and authentication tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the use of WinRAR to open or extract password-protected ZIP archives containing 'Setup_File' in the filename, immediately followed by the execution of a file extracted into a WinRAR temporary directory. This behavior is associated with the OnyxC2 delivery chain, where attackers use password-protected archives to bypass security scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of ServiceModelReg.exe from the standard .NET Framework directories. While this utility is a legitimate tool used for registering and configuring WCF components, its abuse has been observed in the wild by threat actors, including the OnyxC2 malware, to leverage built-in Windows utilities for suspicious activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the presence of an OnyxC2 sideloaded DLL, identified by the filename 'borlndmm.dll', masquerading as an NVIDIA graphics library. The rule identifies suspicious files that are unusually large (50MB-200MB) with high entropy, suggesting an encrypted payload appended to the file. It also looks for associations with known loaders like 'ABRSubProcess.exe' or 'Setup_File_92.118.3096.exe' and the 'ACCA software S.p.A.' digital signature.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002