Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule detects specific JavaScript helper functions and state machine constants commonly used in 'ClickFix' phishing campaigns (e.g., Exvicy and ErrTraffic). These scripts typically prompt users to copy and paste malicious code snippets, often disguised as error fixes or CAPTCHA resolution, to facilitate initial access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
These rules detect various exploitation attempts targeting SharePoint to bypass SafeControls, an security mechanism used to restrict the types of controls allowed in web parts. The patterns match suspicious Register directives and markup injection techniques often associated with remote code execution or privilege escalation, as identified in CVE-2026-65660.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the IIS worker process (w3wp.exe) used by SharePoint loading a specific combination of assemblies (PresentationFramework.dll, System.Xaml.dll, and System.Data.Services.dll). This behavior is indicative of an ExpandedWrapper/XamlServices.Parse() insecure deserialization gadget chain, typically associated with the exploitation of vulnerabilities like CVE-2026-65660, which enables fileless in-memory code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects outbound network traffic from internal hosts to known IP addresses associated with Exvicy Malware-as-a-Service (MaaS) Command and Control (C2) or hosting infrastructure. This rule acts as an indicator of compromise (IOC) match to identify potential infected hosts communicating with malicious external servers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects HTTP POST requests to SharePoint ToolPane or WebPartPage endpoints containing serialized gadget chains (e.g., ysoserial ExpandedWrapper/ObjectDataProvider or XamlServices) indicative of deserialization exploitation attempts, specifically targeting CVE-2026-65660.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects unauthenticated HTTP POST requests targeting SharePoint WebPartPage-derived endpoints using the 'webPartMarkup' parameter. This activity attempts to exploit a vulnerability (CVE-2026-65660) where anonymous access to specific pages bypasses authentication, allowing an attacker to invoke internal methods for malicious register-directive injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where the SharePoint IIS worker process (w3wp.exe) initiates command interpreters or known living-off-the-land binaries (LOLBins). This behavior is characteristic of post-exploitation activity, such as command execution following successful exploitation of SharePoint vulnerabilities involving insecure deserialization or malicious directive injection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects non-browser and non-messaging processes accessing both browser credential stores (like 'Login Data' or 'Cookies') and messaging application session storage (Slack/Discord LevelDB) in a single session. This pattern is characteristic of credential-stealing malware, such as RevStealer, which targets both saved web browser credentials and application session tokens for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
202
Detects outbound HTTP POST requests to the 'vpugy.vcqi' domain, which is associated with RevStealer malware exfiltration. The rule specifically looks for traffic using a spoofed Chrome/147 user-agent and specific cookie artifacts used for session tracking in the exfiltration communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of elevated cmd.exe processes (running with High or System integrity) spawned by parent processes originating from the AppData directory. This pattern is commonly associated with malicious installers, droppers, or payload execution where a staged binary in the user profile attempts to perform administrative actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects PowerShell execution that combines screen capturing capabilities (System.Drawing.Bitmap, Windows.Forms) with network communication (System.Net.WebClient) directed towards known C2 domains (medianewsonline.com) using specific exfiltration parameters (OKey, Who).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects unauthorized processes attempting to open handles to Google Chrome or Microsoft Edge with elevated permissions, specifically accessing thread context (often associated with hardware breakpoints used for process injection or credential extraction techniques).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects unauthorized access to critical Chromium-based browser credential databases (such as Login Data, Cookies, and History) by processes other than recognized browser executables. This behavior is indicative of credential-harvesting activity, specifically matching techniques employed by infostealers like RevStealer.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects suspicious process access attempts targeting common web browsers (chrome, msedge, firefox) using high-privilege access masks (such as 0x1F0FFF or 0x1FFFFF). The detection is specifically scoped to calls originating from unbacked memory (indicated by an UNKNOWN stack trace entry containing ntdll.dll), which is a common indicator of direct or indirect syscalls used by malware for stealthy memory access, such as credential theft or session cookie exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the execution of a RevStealer native PE payload by an Electron-based loader (XabivSystem.exe). The rule identifies when the loader spawns an unsigned, detached process from a hidden, randomly-named subdirectory within the user's AppData folder. This process creation is a precursor to the malware's environment checks, anti-VM/sandbox gating, and CAPTCHA verification routines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects non-browser processes accessing sensitive browser credential stores (e.g., Login Data, Cookies) and cryptocurrency wallet files within a short time window. This pattern is characteristic of infostealer malware like Vidar, which grabs browser and wallet data for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects web browser processes (Chrome, Edge, Firefox, Brave, Opera, IE) being spawned by a parent process that is not part of the standard, trusted application launch lineage. This pattern is commonly observed in credential-stealing malware like Vidar Stealer, which invokes browsers to access and exfiltrate stored browser data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the custom ARX-based stream cipher used by Vidar Stealer (v2.2+) to encrypt strings and configuration data. The rule identifies the presence of specific FNV-1a and golden-ratio constants used for state initialization, in combination with unique, per-build keystream constants observed in recent variants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the presence of known Vidar Stealer malware binaries (internal build versions 2.0 through 3.4) by matching their SHA256 file hashes. Vidar is an infostealer malware typically used to exfiltrate sensitive data from victim systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects potential execution of Vidar Stealer by identifying specific diagnostic loader strings (e.g., 'Loader: write failed') within file modification and process execution events. The presence of these strings in file metadata or command-line arguments indicates stage-specific activity related to the malware's loading process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a low-privileged account manually triggering the 'CreateObjectTask' scheduled task, which is a known technique to force the 'Shell Create Object Handler' (dllhost.exe) to start under the SYSTEM context. This behavior is often associated with pre-exploitation steps for privilege escalation vulnerabilities, specifically those involving OBJREF marshaling targeting specific COM objects.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
202