Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
002
Detects an exploitation attempt against the Vite Development Server (CVE-2026-39364) where an attacker uses specific query parameters to bypass file access restrictions and disclose sensitive files. The rule triggers on GET requests containing suspicious import-related query parameters and checks the resulting response to ensure a successful 200/206 status code and non-HTML content type.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
002
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
002
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
002
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
102
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
102
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
002
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
002
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
002
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
002
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
002
Detects Mimikatz binary or in-memory module used for credential harvesting following PaperCut RCE exploitation
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
26 days ago
003
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
103
Detects the execution of the Rubeus.exe utility with command-line arguments indicative of Kerberos-related credential harvesting and abuse, such as Kerberoasting, AS-REP Roasting, and Pass-the-Ticket attacks.
avatar
Arnold Chan@slaz
Defender - KQL
26 days ago
303
Detects the execution of the Rubeus.exe utility with command-line arguments indicative of Kerberos-related credential harvesting and abuse, such as Kerberoasting, AS-REP Roasting, and Pass-the-Ticket attacks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
26 days ago
003
Page 327 of 1871