Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
001
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
Detects the inclusion of PowerShell download commands ('irm' or 'Invoke-RestMethod') within the Windows 'RunMRU' registry key. This key is used by Windows Explorer to track recently typed run commands, and adversaries often abuse it to maintain persistence or store malicious one-liner payloads that are intended to be executed at a later time.
avatar
Guillermo Lopez@guillermolg
avatar
Detections.ai Community
25 days ago
003
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
5013
Detects outbound network connections from endpoints to domains and IP addresses associated with the Kimsuky (APT43) threat actor group. This rule leverages endpoint network telemetry to identify potential command and control (C2) communication or data exfiltration activities.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
11013
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
003
Detects an exploitation attempt against the Vite Development Server (CVE-2026-39364) where an attacker uses specific query parameters to bypass file access restrictions and disclose sensitive files. The rule triggers on GET requests containing suspicious import-related query parameters and checks the resulting response to ensure a successful 200/206 status code and non-HTML content type.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
003
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
102
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
002
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
002
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
002
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
002
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
002
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
002
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
003
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
102
Page 309 of 1871