Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects the execution of the Bun JavaScript runtime invoking 'index.js' as part of an npm lifecycle event (such as preinstall). This pattern is commonly used in supply chain attacks to execute arbitrary code during the installation of malicious packages.
avatar
Hrushikesh Badgujar@H3AD
avatar
Detections.ai Community
27 days ago
404
Detects the execution of the Bun JavaScript runtime invoking 'index.js' as part of an npm lifecycle event (such as preinstall). This pattern is commonly used in supply chain attacks to execute arbitrary code during the installation of malicious packages.
avatar
Hrushikesh Badgujar@H3AD
XQL - Cortex Detections
27 days ago
104
Detects browser processes (Chrome or Firefox) originating from specific file paths or extension IDs attempting to perform OAuth validation against the Twitch API. This behavior is indicative of potentially malicious browser extensions or extensions masquerading as legitimate tools attempting to handle user authentication tokens.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
102
Detects the installation or update of a browser extension that requests specific host permissions related to Twitch (gql.twitch.tv, usher.ttvnw.net, id.twitch.tv) combined with suspicious domains (jeetbot.cc, drisnya.online, morphilina.me, deno.dev, deno.net). This pattern is indicative of malicious browser extensions designed to intercept credentials or manipulate Twitch-related traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
102
Detects anomalous execution or network activity involving a 'content.js' file in conjunction with specific proxy-related artifacts or authorization headers. This pattern is indicative of a malicious browser extension or script attempting to intercept or proxy web traffic and credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
002
This rule detects either the execution of specific files identified by SHA256 hashes or the installation/enabling of browser extensions matching known malicious extension IDs. This monitoring helps identify the introduction of potentially harmful browser-based persistent threats or the presence of known malicious binaries on endpoints.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
102
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
002
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
102
Detects network communication with identified C2 infrastructure associated with VectraRAT, Amadey, and ClickFix campaigns, as well as the presence of a specific 'callback.json' artifact in temporary directories, which is commonly used for C2 address overrides.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
102
Detects PowerShell or PowerShell ISE spawned directly from Windows Explorer (explorer.exe, covering both Start-menu launches and the Run dialog abused by ClickFix) whose command line carries a genuine obfuscation/evasion signal - true -EncodedCommand/-e usage, a hidden/minimized window flag, or a remote download cradle (IEX, Invoke-WebRequest, DownloadString, certutil, mshta, etc.) - while excluding invocations that point at an on-disk script file under a standard install path, since ClickFix payloads are inline one-liners rather than references to a local .ps1. Bare -NoProfile/-NoLogo flags no longer trigger alone, since they are common in legitimate automation.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
002
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
102
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
202
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
004
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
404
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
002
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
002
This rule performs a hunting activity across multiple telemetry sources (Network, Email, Endpoint) to detect known indicators of compromise (IOCs) associated with Anthropic threat intelligence reporting (September 2026). It looks for specific malware file names, command-line patterns, service installations, phishing email addresses, and C2 communication URLs.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
002
This rule detects the creation or modification of registry run keys associated with the JartePortable application. The detection logic looks for persistence mechanisms that point to executable paths in public directories or specific registry value data associated with known PlugX malware activity.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
20 days ago
000
Detects Adobe Acrobat (Acrobat.exe) launched by a suspicious parent process (GRrte.exe) while opening a specific PDF document from the user's temporary directory. This pattern is indicative of a potential malicious document lure often associated with malware delivery.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
20 days ago
000
Detects the execution of taskkill.exe to forcibly terminate the iediagcmd.exe diagnostic process, initiated by the process GRrte.exe. This behavior is indicative of an attempt to impair security or diagnostic tools on the endpoint.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
20 days ago
000
MicroStealer is a newly emerging infostealer that spreads quickly, evades traditional detection, and focuses on stealing corporate credentials, browser data, session tokens, and cryptocurrency wallets. Its layered delivery chain (NSIS → Electron → Java) and heavy obfuscation make it difficult to detect, while exfiltration occurs via Discord webhooks and attacker‑controlled servers.
avatar
Marco Moran@MarcoM
avatar
Detections.ai Community
1 month ago
37148
Page 329 of 1871