Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects potential process injection attempts involving 'charmap.exe', a Windows system utility. The rule monitors for a sequence of memory management and thread creation API calls (OpenProcess, VirtualAlloc, WriteProcessMemory, and CreateRemoteThread) originating from or targeting this binary, which is often abused as a host for malicious code to bypass security controls.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
002
This rule detects a correlation between the creation or modification of a specific file name ('nloemfbihmhm') and the subsequent execution of processes from the 'Temp' directory involving related filenames ('kojuyn.ini', 'ogftogcyiblzjccmcbnw.exe', or 'nloemfbihmhm') within a 5-minute window. This behavior is indicative of a multi-stage execution chain, often used by malware to drop and execute secondary payloads.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
102
This rule detects PowerShell commands that utilize specific character array joining techniques (e.g., [char]nnnn -join '') often used to obfuscate malicious strings or bypass keyword-based security filters. This is a common tactic for evading detection when downloading or executing payloads.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
002
Detects PowerShell command execution that uses bitwise XOR operations combined with the .NET [IO.File]::WriteAllBytes method. This pattern is commonly used by malware, such as AsyncRAT, to deobfuscate and drop secondary payloads or modules onto the file system during execution.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
002
Detects browser extension manifest.json files requesting declarativeNetRequest and content_scripts/host_permissions covering AI assistant vendor domains (BragJack attack class)
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
101
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
001
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
001
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
001
Detects rapid AI agent state transitions (from 'think' to 'act') within Microsoft Edge processes, specifically identifying potential exploitation of the CVE-2026-55945 race condition vulnerability, which could be used to force the unauthorized execution of an injected prompt.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
Detects high-frequency, automated interactions with popular AI assistant web interfaces (e.g., Gemini, Perplexity, Claude, Copilot) from common browser processes. This pattern often indicates unauthorized automated data submission or scraping, which may follow or facilitate automated exfiltration of browser-resident data.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
101
This rule detects the creation of a scheduled task intended to run an executable named 'wsc_updata.exe' from a temporary directory, or identifies svchost.exe initiating a process from that location. Such behavior is indicative of potential persistence mechanisms where malicious actors attempt to run code from unauthorized or writable directories under the context of system processes or scheduled tasks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
108
This rule detects scenarios where 'MpClient.dll' is loaded by a process that is not a recognized Microsoft Defender security process, and this load event occurs in close temporal proximity to the creation or modification of 'ShieldCrash_' artifacts. This pattern is indicative of potential DLL side-loading or defense evasion activities, where an adversary attempts to masquerade malicious activity using components associated with security product internals or crash reporting mechanisms.
avatar
Sergiu B@Sergiu
avatar
Detections.ai Community
1 month ago
1010
Detects potential exploitation of a CrowdStrike Falcon remediation process vulnerability ('FalconFlank'). The rule identifies either direct execution of the PoC binary or the suspicious combination of a CrowdStrike remediation process loading an unsigned or untrusted DLL from a user-writable path followed by the same process spawning a command shell in the SYSTEM context within 15 minutes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
7017
Detects the use of 'curl.exe' to download a file named 'msgbox.exe' to the local temporary directory, specifically when triggered by 'cmd.exe' originating from 'chrome.exe'. This pattern is indicative of a browser-based delivery mechanism initiating a secondary malicious download.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
208
This rule detects PowerShell commands that exhibit signs of obfuscation by searching for specific string manipulation methods commonly used to hide malicious code. Specifically, it identifies the use of base64 decoding (FromBase64String) or string concatenation combined with character replacement techniques (Replace) on the command line, which are often used by threat actors to execute encoded payloads while bypassing simple string-based signatures.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
24 days ago
202
This rule monitors network traffic and internal logs for connections to known malicious IP addresses or domain names associated with 'ClickFix' social engineering campaigns (often impersonating services like HBO Max). The logic explicitly filters out known threat intelligence scanners and security researcher probes. It performs correlation by requiring domain/message matches for generic IP-based alerts to reduce noise, and aggregates events per host over 15-minute windows to produce consolidated alerts.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
002
This rule monitors network traffic and internal logs for connections to known malicious IP addresses or domain names associated with 'ClickFix' social engineering campaigns (often impersonating services like HBO Max). The logic explicitly filters out known threat intelligence scanners and security researcher probes. It performs correlation by requiring domain/message matches for generic IP-based alerts to reduce noise, and aggregates events per host over 15-minute windows to produce consolidated alerts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
002
Detects network communication with domains and IP addresses known to be associated with 'ClickFix' social engineering campaigns (specifically those masquerading as legitimate HBO Max or macOS related updates). The rule applies a strict correlation between observed malicious IP traffic and specific DNS requests to reduce noise from IP address reuse or threat intelligence feed probes, while also excluding known security-related processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
202
Detects network communication with domains and IP addresses known to be associated with 'ClickFix' social engineering campaigns (specifically those masquerading as legitimate HBO Max or macOS related updates). The rule applies a strict correlation between observed malicious IP traffic and specific DNS requests to reduce noise from IP address reuse or threat intelligence feed probes, while also excluding known security-related processes.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
1102
Detects network activity (DNS queries or direct IP communication) associated with 'ClickFix' social engineering attacks targeting users under the guise of an HBO Max update or repair utility. The rule includes indicators for known malicious domains and IP addresses while incorporating filters to minimize false positives from security scanners, threat intel feeds, and automated crawlers by analyzing User-Agent strings and network source addresses.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
102
Page 320 of 1871