Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects coordinated usage of 'xattr' to manipulate the com.apple.quarantine attribute and 'chmod' to grant executable permissions on sensitive macOS system or library paths. This behavior is indicative of an adversary attempting to bypass Gatekeeper or bypass execution restrictions on malicious payloads placed in system directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
203
The following analytic detects the usage of wevtutil.exe with parameters for clearing event logs such as Application, Security, Setup, Trace, or System.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments.
This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
If confirmed malicious, this behavior could allow an attacker to erase evidence of their activities, making it difficult to trace their actions and understand the full scope of the compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
003
Detects incoming HTTP requests where the 'pagename' parameter contains directory traversal sequences (e.g., '../', '..%2f'). These attempts are typically indicative of automated vulnerability scanning or exploitation attempts targeting WordPress page-template resolution logic, specifically related to CVE-2026-87902.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects Node.js or NPM process executions that reference Twilio-specific credential variables (ACCOUNT_SID, AUTH_TOKEN) within the command line, likely indicating an attempt to harvest these secrets from a developer environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the installation of a specific malicious Firefox browser extension identified by its unique internal ID 'pdf-para-texto@extensao.local' or by its name 'PDF Identity Verifier'. This behavior is characteristic of adversaries using browser extensions for persistence or credential theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects Node.js processes, such as npm package postinstall hooks, spawning shell commands used for host enumeration. This includes accessing system environment variables, network configurations, and filesystem metadata, a pattern frequently utilized by malicious packages for initial reconnaissance post-installation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects instances where the Firefox browser or its plugin container process initiates a DNS query for domains containing 'pdf.gusercontent.com', which is a known lookalike pattern used to masquerade as legitimate Google infrastructure for potential command and control or data exfiltration activities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the execution of piped curl-to-shell or curl-to-bash commands originating from a macOS Terminal process, a common pattern used in ClickFix-style social engineering attacks where users are tricked into copying and pasting malicious commands.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects instances where a suspicious login event (such as a risk challenge) is immediately followed by a credential or recovery information modification. This pattern may indicate an adversary is attempting to take over a compromised account by resetting the password or recovery details after triggering a security alert.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
203
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
003
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
103
Detects instances where AI-assisted development tools (such as Claude, Codex, Copilot, or Gemini) initiate command-line processes (e.g., shells, interpreters, or network utilities) with arguments indicative of credential access, reconnaissance, or sensitive file interactions.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
707
Detects ClickFix-style social engineering attacks where users are tricked into pasting malicious payloads into the Windows Run dialog. The rule monitors for common scripting interpreters (powershell.exe, cmd.exe, mshta.exe, rundll32.exe) spawned by explorer.exe or mstsc.exe with suspicious command-line patterns indicative of payload delivery, such as obfuscated strings, hidden windows, or short-URL downloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where end users grant high-risk delegated permissions (e.g., Mail.Read, Files.ReadWrite.All) to applications via OAuth consent flows outside of standard administrator approval processes. This behavior is indicative of device-code phishing or consent phishing campaigns designed to gain unauthorized access to user data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where a signed executable, typically a security or trusted system binary, loads an unsigned DLL from a user-writable, non-default directory (e.g., Temp, AppData, ProgramData). The rule specifically targets common system or vendor library names, indicating potential DLL search-order hijacking used to execute malicious code within a trusted process context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects instances where an existing, non-interactive SSO session token is reused from a suspicious network location, such as an anonymizing proxy, VPN, or VPS, or triggered by an impossible travel risk event. The rule specifically looks for token usage that lacks a fresh interactive Multi-Factor Authentication (MFA) challenge, a common indicator of session token hijacking or 'replay' attacks frequently used in cloud account takeover campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects HTTP requests directed at edge appliances (FortiOS/FortiProxy, SonicWall, Cisco ASA) that match known CVE-associated URI paths, alongside successful administrative authentication to management or VPN interfaces originating from external source IP addresses. This rule is designed to identify potential initial access via vulnerability exploitation or unauthorized administrative login to critical infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects malicious processes or scripts that perform multi-stage environment fingerprinting to identify virtualization or sandbox environments. The rule identifies chains of suspicious activities, including querying registry keys related to virtualization (e.g., VMware, VirtualBox, QEMU), WMI queries for BIOS/Computer system details, API calls common to sandbox evasion (GetCursorPos, GetTickCount), and artificial execution delays (sleep/timeout), typically used by malware like LummaC2 to perform conditional exits if an analysis environment is detected.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects the loading of a legitimately signed but vulnerable driver from suspicious directories (e.g., Temp, Downloads) followed closely by the termination of critical security/EDR service processes. This sequence is indicative of Bring Your Own Vulnerable Driver (BYOVD) exploitation used to disable security controls prior to ransomware deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects browser processes performing JSON-RPC network connections to known public blockchain node providers, a network behavior characteristic of the EtherHiding technique used by the ErrTraffic MaaS platform to resolve C2 infrastructure via smart contracts. This rule identifies the network-side beaconing and should be correlated with suspicious process execution chains (e.g., browser-spawned PowerShell/cmd).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000