Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
000
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
000
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
avatar
Arnold Chan@slaz
avatar
Hunters
20 days ago
000
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
20 days ago
000
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
20 days ago
000
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
avatar
Arnold Chan@slaz
Defender - KQL
20 days ago
000
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
000
Detects modifications to the 'HKCU\Software\Classes\ms-settings\shell\open\command' registry key, a technique used to hijack the fodhelper.exe binary to achieve silent UAC elevation. This allows attackers to execute commands with administrative privileges without triggering a UAC prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
002
Detects the execution of hidden, base64-encoded PowerShell commands spawned directly from explorer.exe, a pattern observed in the CRPx0 ClickFix campaign where attackers trick users into pasting malicious commands into the Windows Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
002
Detects execution of rundll32.exe using ordinal-based export calling syntax to load suspicious DLLs (e.g., sys_<hex>.dll) or reference non-executable files (e.g., WindowsUpdate.log). This behavior is consistent with the CRPx0 Stage 2 stager, which typically exports crypto globals and lacks standard named exports.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
002
Detects host and user discovery commands (whoami, hostname, systeminfo, wmic) executed within a 15-minute window following a suspected CRPx0 ransomware execution event, identified by either encoded PowerShell or curl-to-bash activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
002
Detects potential lateral movement activity associated with the CRPx0 propagation technique. The rule monitors for WmiPrvSE.exe spawning unusual child processes (indicative of remote Win32_Process.Create execution) which are concurrently correlated with outbound network activity from the same host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
25 days ago
002
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
6011
Detects Ruby processes executing with arguments explicitly disabling SSL/TLS verification (OpenSSL::SSL::VERIFY_NONE) while correlating with the presence of suspicious helper scripts ('loader.rb' or 'script.rb') within Ruby gem-related directories. This behavior is indicative of an adversary attempting to perform man-in-the-middle attacks or bypass security controls for outbound C2 communications.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
101
Detects usage of the 'gem' command (install, build, push, publish) that includes naming patterns or specific command strings associated with the GemStuffer supply chain compromise campaign. This targets attempts to introduce malicious dependencies into the environment using RubyGems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
23 days ago
001
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
108
This rule detects file creation or modification events within the WordPress plugin directory for 'admin-menu-editor-pro'. Given that WordPress plugins are frequent targets for web shell placement, this rule monitors for unauthorized changes to the plugin's file structure, which may indicate an attempt to gain persistence or remote code execution on the web server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
001
Detects file-related operations (creation, modification, renaming, or deletion) performed on files containing 'acronis' or 'backup' in their path, executed by a process associated with Acronis, running under highly privileged system contexts (root or SYSTEM). This activity is indicative of potential unauthorized manipulation or disabling of backup software, commonly seen in ransomware attacks to inhibit recovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
001
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects potential installation of compromised Admin Menu Editor Pro plugin updates by identifying sequential download events for specific plugin versions from the 'adminmenueditor.com' domain within a 24-hour window. This behavior is indicative of a supply chain attack where a legitimate update mechanism is leveraged to deliver malicious payloads without integrity verification.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
23 days ago
001
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
Page 330 of 1871