Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects the loading or installation of a driver file identified as DCRCVDrv.sys followed within 5 minutes by EDR sensor heartbeat loss or process activity, which is characteristic of attempts to tamper with security software or hide malicious activity via a kernel-mode driver.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
Detects process execution patterns and DNS requests associated with the GHAPPIER malware staging infrastructure. The rule monitors for specific command-line arguments involving known malicious scripts, temporary files, and deployment infrastructure (e.g., Vercel) often used for delivering or executing malicious payloads via node.js environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
303
Detects a process that deletes its own executable file immediately after launching. This anti-forensic behavior is commonly utilized by remote access trojans (RATs) and other malware to minimize their footprint and evade file-based forensic analysis.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects network activity associated with NetSupport Manager remote access software, specifically targeting DNS lookups, TLS SNI connections, and direct TCP beaconing to a known-malicious infrastructure IP. This rule is designed to identify unauthorized use of legitimate remote support tools for command and control purposes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects malicious JavaScript/npm payloads that attempt to evade static analysis and string-based detection signatures by dynamically reconstructing sensitive strings at runtime using V8 string-object construction or obfuscated string tables.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects execution of code using indirect syscalls or ntdll unhooking techniques, often associated with the PIVOTPIPE loader/RAT. The rule monitors for EDR indicators of evasion such as syscall stub execution, direct/indirect Nt* system call invocation, or call stacks originating outside of ntdll.dll, intended to bypass userland security hooks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Correlates an MFA method change with the next sign-in occurring from an ASN/country never seen for that user in 30 days, operationalizing TrustSphere's 2026 finding that reset-then-new-location access is the clearest signal separating a hijack from a genuine recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
This rule detects modifications to GitHub Actions workflow configuration files (.yml or .yaml) located in the .github/workflows/ directory. Such modifications may indicate unauthorized tampering with CI/CD pipelines to facilitate persistent execution, credential theft, or supply chain attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
Aggregates MFA/passkey enrollments tenant-wide, alerting when an unusual number of distinct users register new authenticators within a short rolling window — a mass-takeover indicator rather than isolated recovery activity, especially when linked by a common actor or source ASN.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Flags changes to a user's registered SMS/voice MFA phone number followed by a successful high-risk sign-in — the SIM-swap/SMS-interception bypass step documented across the 2024-2026 vishing threat-report taxonomy (CrowdStrike, Mandiant, Pindrop).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects attempts to bypass macOS Gatekeeper security controls by manually removing the 'com.apple.quarantine' extended attribute using 'xattr' or by modifying executable permissions with 'chmod' on specific system or sensitive file paths, such as 'iSync'. These actions are commonly performed to evade execution restrictions on downloaded or untrusted files.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects Node.js processes executing suspicious command lines that involve fetching and executing remote JavaScript code. This behavior is indicative of a loader or downloader script commonly used to pull and evaluate malicious payloads at runtime, specifically referencing indicators associated with 'GHAPPIER'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the reuse of a session or refresh token from a geographic location that contradicts recent user activity (impossible travel) without a new interactive MFA challenge. This activity is indicative of Adversary-in-the-Middle (AiTM) phishing attacks, such as those leveraging Evilginx, where session cookies are captured and replayed from attacker infrastructure to bypass multi-factor authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects when a user adds a new Multi-Factor Authentication (MFA) method such as a phone number, authenticator app, or FIDO2 key in Entra ID (Azure AD). Attackers often register their own MFA devices to maintain persistent access to a compromised account, particularly following a successful password reset or social engineering event.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the Cursor IDE application launching specific macOS system binaries ('SystemUpdate', 'iSync', 'loginwindow') that are potentially being used to execute hidden backdoors, often associated with the 'FLATROOF' or 'ROOFDECK' threats. The rule looks for process spawning behavior where Cursor initiates these binaries with specific suspicious command-line flags ('nohup', '--type=renderer') or in directories associated with known malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects instances where npm processes (install, preinstall, or postinstall) spawn suspicious child processes such as shell interpreters (cmd, powershell, bash, sh), network utilities (curl, wget), or scripting interpreters (python). This behavior is often associated with malicious npm package installation or software supply chain compromise where post-install scripts are used to gain persistence or download secondary payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of PowerShell with hidden window arguments from explorer.exe, typically indicative of ClickFix social engineering where a user is tricked into pasting malicious commands into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
303
Detects the creation of mailbox inbox rules (New-InboxRule) or modification of mailbox forwarding configurations (Set-Mailbox) that auto-forward, auto-delete, or move messages to hidden or secondary folders (e.g., RSS, Deleted Items). This behavior is characteristic of Business Email Compromise (BEC) follow-on activity intended to maintain covert access to victim communications, particularly following account takeover events like password resets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects a suspicious pattern where an inbound Microsoft Teams call or chat from an untrusted external guest tenant is followed within 30 minutes by a credential, MFA, or account-recovery action on the target user's account in Entra ID. This behavior is indicative of a vishing-over-Teams attack where an adversary impersonates IT support to facilitate unauthorized account recovery or MFA bypass.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects instances where processes (excluding known legitimate .NET processes) load common .NET runtime modules (e.g., clr.dll, mscoree.dll) followed by remote process injection or handle-based process access, which is often indicative of reflective assembly loading used by loaders like PIVOTPIPE to execute malicious code within a target process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects a suspicious sequence of events where a user modifies their MFA phone number, followed within 30 minutes by a sign-in event flagged with 'impossibleTravel' or 'unfamiliarFeatures' risk. This pattern is indicative of potential SIM-swap fraud, where an attacker has hijacked the user's phone number to receive MFA prompts and then attempts to access the account from an anomalous location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001