Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects unauthorized processes accessing sensitive web browser files (login data, cookies, local state) from suspicious or non-standard paths. This is a common behavioral pattern for infostealers attempting to exfiltrate user credentials and browser session tokens.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
1010
Detects anomalous, high-volume authentication failures originating from a single source IP address targeting multiple distinct internal devices within a short timeframe. This behavior is indicative of a password spraying or brute-force attack.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
002
Detects anomalous, high-volume authentication failures originating from a single source IP address targeting multiple distinct internal devices within a short timeframe. This behavior is indicative of a password spraying or brute-force attack.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
002
This rule detects network connections and HTTP requests to known malicious URLs, including file downloads associated with C2 infrastructure and malware distribution campaigns. It monitors both direct device network events and HTTP requests logged through security product events to identify potential secondary-stage payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
30 days ago
409
Detects the ShieldCrash CVE-2026-69414 exploit PoC binary/PDB via multiple corroborating distinguishing strings and file size
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
3010
Detects the execution of the Cloudflare Tunnel client (cloudflared.exe) on Windows endpoints by monitoring process command line arguments, such as 'tunnel', 'run', or 'proxy-dns'. This tool can be used to establish unauthorized remote access tunnels, potentially bypassing firewall configurations.
avatar
D LaB@DLAB
avatar
Detections.ai Community
28 days ago
405
This rule detects when common Windows applications (explorer.exe, svchost.exe, winword.exe, excel.exe, rundll32.exe) load DLLs that are either unsigned or located in user-writable directories (e.g., \Users\, \AppData\, \Temp\, \ProgramData\). This is a common indicator of potential DLL hijacking or side-loading attacks.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
10019
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
000
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
000
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
000
Detects the deletion of the registry key responsible for Chrome extension integrity verification (PreferenceMACs). Deleting this key allows an adversary to tamper with installed Chrome extensions without triggering security warnings. This activity has been observed in the Rapuncel campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects the loading and service creation of the CcProtect/Alinubx kernel driver, a known technique for Bring Your Own Vulnerable Driver (BYOVD) attacks. The rule identifies suspicious characteristics such as file name mismatches, unauthorized product/company signatures, and the creation of services associated with this malicious driver family (e.g., NvFsFilter) to facilitate EDR/AV termination or privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects the deletion of the registry key responsible for Chrome extension integrity verification (PreferenceMACs). Deleting this key allows an adversary to tamper with installed Chrome extensions without triggering security warnings. This activity has been observed in the Rapuncel campaign.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects the loading and service creation of the CcProtect/Alinubx kernel driver, a known technique for Bring Your Own Vulnerable Driver (BYOVD) attacks. The rule identifies suspicious characteristics such as file name mismatches, unauthorized product/company signatures, and the creation of services associated with this malicious driver family (e.g., NvFsFilter) to facilitate EDR/AV termination or privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects the execution of ServiceModelReg.exe following parent process activity involving vsdbg.dll/vsdbg.exe, coupled with cross-process access indicators consistent with COM Elevation Moniker UAC bypass and potential process hollowing. This pattern is associated with the PUROSANGUE loader chain used to execute malicious code within a high-integrity process context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
This rule detects the potential bypassing of Protected Process Light (PPL) in Windows, characterized by kernel-mode driver activity (such as ObOpenObjectByPointer) correlated with the mass termination of security-related processes (e.g., Defender, CrowdStrike, SentinelOne). The correlation between driver-level object handle manipulation and the termination of protected security binaries is a strong indicator of an adversary attempting to disable EDR/AV protections via kernel exploitation or driver abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects the installation and loading of a suspicious driver named 'NvFsFilter' (nvfsflt64.sys), accompanied by registry persistence and suspicious process termination events. This pattern is characteristic of a 'kill-loop' persistence mechanism where malicious drivers or services repeatedly terminate security agents (AV/EDR) to maintain a persistent foothold on the endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects DLL injection into browser processes (chrome.exe or msedge.exe) followed by the invocation of the browser's Elevation Service 'DecryptData' function, a behavior characteristic of the Rapuncel credential stealer attempting to bypass app-bound encryption.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects the loading or file presence of known suspicious or potentially malicious kernel drivers, specifically 'alinubx.sys' and 'ccprotect.sys', which are associated with unauthorized system-level activity or potential rootkit behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects process injection behavior by monitoring for the usage of specific Windows API functions (NtAllocateVirtualMemory, NtCreateThreadEx, NtProtectVirtualMemory, NtWriteVirtualMemory, NtOpenProcess) frequently used by adversaries to execute malicious code within the context of a legitimate process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Detects unauthorized processes accessing cryptocurrency wallet data files, including 'wallet.dat' or specific browser-based extension storage databases (e.g., MetaMask, Coinbase Wallet), which is indicative of the Rapuncel stealer attempting to exfiltrate sensitive wallet data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
000
Page 321 of 1871