Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule detects the execution of the MeshAgent remote administration tool from a temporary directory followed by a network connection to known malicious infrastructure within a 15-minute window. This behavior is indicative of unauthorized remote access setup or C2 activity using a legitimate remote management utility.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects the execution of the 'fanout.sh' utility from the /tmp directory, which subsequently spawns 'sshpass' child processes to perform rapid, non-interactive SSH authentication attempts ('StrictHostKeyChecking=no') against multiple internal hosts within a 10-minute window. This behavior is indicative of automated lateral movement, specifically observed by threat actor UNC6240.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
102
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects network traffic associated with the NPM Btree malware campaign, specifically identifying command-and-control (C2) polling activities directed toward blockchain RPC endpoints like Alchemy and Infura. The rules monitor for specific API keys, C2 smart contract addresses via 'eth_call' JSON-RPC requests, and overall traffic patterns to known malicious infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects Microsoft 365 Exchange MailItemsAccessed operations performed by a specific ClientAppId and AppId known to be associated with an exfiltration toolkit. This activity indicates unauthorized access to mail items, consistent with data harvesting efforts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects high-volume file access or download operations in SharePoint or OneDrive performed by common scripting libraries and client user agents, which may indicate automated data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects Node.js processes executing system-level reconnaissance (e.g., CPU, memory, hostname, uptime enumeration) followed by network connections to known exfiltration endpoints (Slack, Telegram API). This behavior aligns with identified npm malware campaigns using host fingerprinting for target selection and data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of the Windows Workspaces Broker process (wkspbroker.exe) when it loads a library (DLL) from a path within the RemoteApp Gateway directory under LOCALAPPDATA. This behavior is associated with DLL side-loading techniques used to execute malicious payloads such as the Xray-core implant.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003