Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
201
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects a sequence of suspicious activities indicative of malicious driver installation. It identifies the creation of an irregularly named .sys file in temp directories, the use of curl.exe to retrieve symbols for a potentially malicious driver, and the subsequent registration/start of that driver as a Windows system service.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects non-browser processes (e.g., non-chrome.exe/msedge.exe) modifying critical browser configuration files such as 'Secure Preferences' followed by near-simultaneous writes to extension-related directories like 'Extension State' or 'Extensions'. This pattern is indicative of a malicious attempt to bypass browser security integrity checks to silently install or load unauthorized extensions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
The rule detects correlation between the creation of persistence-related Registry keys (specifically Windows Run keys or Browser Native Messaging hosts) and the execution of the schtasks.exe utility to create or manage a task related to 'psychedelicloveUtils'. This pattern suggests an adversary attempting to maintain persistence by linking Registry-based autostart mechanisms with a scheduled task.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the persistence and execution mechanism of the Lunex Native Messaging Host backdoor. The rule identifies the registration of the 'com.lunex.explorer' native messaging host registry key and the subsequent invocation of PowerShell scripts from browser processes (chrome.exe or msedge.exe) containing specific backdoor command arguments like 'list_drives' or 'run'.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects a credential theft pattern where a browser process is forcefully terminated using taskkill, followed shortly by the creation of a 'wd_tmp.db' file in browser user data directories. This behavior is indicative of malware attempting to stage and exfiltrate browser credentials like cookies and login data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
101
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101