Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Matches known VectraRAT sample SHA-256 hashes and the ClickFix distribution domain (verify-cloud.digital) recovered from pivoting across exposed VectraRAT distribution infrastructure
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
003
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
303
Matches known SilverFox malware payload samples by SHA256 hash
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
003
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
203
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
103
This rule detects the sequence of an external file download over HTTP, followed by the immediate creation and execution of an executable file (.exe, .dll, .scr) on the endpoint. It specifically filters out common system installers (e.g., msiexec.exe, trustedinstaller.exe) to reduce noise, focusing on potentially malicious payloads delivered via network channels.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
22 days ago
001
Detects process creation events containing command-line arguments indicative of an OAuth 2.0 device code flow, commonly used in consent phishing or device code phishing attacks to hijack account access via a malicious OAuth application registration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects executable files containing XOR-obfuscated strings associated with BabylonRAT capabilities, including browser credential theft, keylogging, HOSTS file manipulation, DDoS, and remote dynamic API resolution. This rule identifies patterns commonly used to evade static analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
003
This rule detects unauthorized persistence attempts by monitoring for the creation of a registry value named 'DailyFitnessTracker' under the HKEY_CURRENT_USER Run key. It triggers when 'reg.exe' is used to add the key, PowerShell is used to set the registry property, or when a general registry event indicates the creation of this specific key. This behavior is indicative of a persistence mechanism designed to launch a potentially malicious or unwanted program upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects execution of cmd.exe originating from potentially malicious or unexpected parent processes associated with RUSTYSHADE malware activity. This rule monitors for cmd.exe invoked by processes like 'DriverInstaller.exe' or 'Automata-20.exe', or processes other than standard Windows system processes (explorer.exe or services.exe), which is indicative of command-line shell abuse for malicious operations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects execution of a config.bat file combined with indicators of cleanup or reference to potentially malicious LNK files and payloads (e.g., windowsysupdates.txt). The rule monitors command-line activity via Sysmon to identify potential post-exploitation staging and cleanup behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
This rule detects potential data exfiltration by monitoring for screen capture activity, identified by API calls like BitBlt or CopyFromScreen or the loading of gdi32.dll, followed by the creation of a screenshot file and subsequent network connections to GitHub domains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the creation of suspicious scheduled tasks using either schtasks.exe or PowerShell's Register-ScheduledTask cmdlet. The rule specifically looks for masquerading attempts involving names like 'StandAloneOneDriveUpdater-2626', the usage of AtLogOn triggers, and the execution of the binary 'Automata-20.exe'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects rapid execution of multiple native Windows discovery commands (whoami, ipconfig, hostname, tasklist) within a short window, which is often indicative of an adversary performing environment reconnaissance post-compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the execution of a scheduled task named 'MicrosoftEdgeUpdateTaskUserS-1-5-24' which triggers conhost.exe with the --headless argument or PowerShell with an EncodedCommand. This behavior is indicative of a malicious persistence mechanism masquerading as a legitimate Edge update task, specifically associated with the retrieval of payloads from the malicious domain 'indiatodays.org'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
This rule detects the execution of the HTSPnew.Exe ransomware payload, associated with a trojanized HTS DLL, and subsequent ransomware-related file operations, such as the creation of .krsid encrypted files and the dropping of a Korean-language ransom note (README_KRSID.Txt).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the execution of 'HTSPnew.Exe', a utility associated with suspicious activity or ransomware simulation, combined with command-line arguments that suggest testing, batch execution, or help requests.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
This rule detects various common command-line techniques used for network reconnaissance and internal environment enumeration on Windows systems. It tracks the execution of native tools such as ARP for ARP cache dumping, Ping for subnet sweeps, and NetBIOS or SMB-related commands (nbtstat, net view, net share, net session) to identify remote systems, network shares, and active sessions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
000
Detects the execution of common command-line or scripting interpreters (cmd, powershell, cscript, etc.) spawned by the ScreenConnect remote administration client. This is a common pattern used by attackers leveraging legitimate remote access tools for post-exploitation activities and lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Detects potential SQL injection attempts by monitoring for 'INSERT INTO' SQL commands executed via command-line arguments. The rule specifically looks for operations targeting user or role tables and including administrative keywords, originating from database or application-related processes like mysql or java.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
001
Page 311 of 1871