Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the GHAPPIER loader pattern: a top-level require('https').get() call to the primevector-app924560.vercel.app C2 that evals the response, disguised inside a large benign-looking JavaScript benchmark file
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
Detects the PolinRider/GHAPPIER campaign signature of a malicious loader payload silently appended to the end of a legitimate project configuration file
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
000
Detects the PolinRider/GHAPPIER campaign signature of a malicious loader payload silently appended to the end of a legitimate project configuration file
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
Detects the PolinRider/GHAPPIER campaign signature of a malicious loader payload silently appended to the end of a legitimate project configuration file
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
Detects the PolinRider/GHAPPIER campaign signature of a malicious loader payload silently appended to the end of a legitimate project configuration file
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
Detects the GHAPPIER loader payload concealed as a single line deep inside a large (~99KB) legitimate-looking JavaScript file, fetching and eval'ing remote code
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
000
Detects the GHAPPIER loader payload concealed as a single line deep inside a large (~99KB) legitimate-looking JavaScript file, fetching and eval'ing remote code
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
Detects the GHAPPIER loader payload concealed as a single line deep inside a large (~99KB) legitimate-looking JavaScript file, fetching and eval'ing remote code
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
Detects the GHAPPIER loader identified across 65 public npm/GitHub repositories and 22 developer accounts, based on its embedded remote-fetch/eval pattern and campaign markers
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
Detects the GHAPPIER loader identified across 65 public npm/GitHub repositories and 22 developer accounts, based on its embedded remote-fetch/eval pattern and campaign markers
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
Detects the GHAPPIER loader identified across 65 public npm/GitHub repositories and 22 developer accounts, based on its embedded remote-fetch/eval pattern and campaign markers
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
000
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
avatar
Arnold Chan@slaz
Defender - KQL
19 days ago
000
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
000
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
000
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
000
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
000
Page 304 of 1871