Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

Detects network connections originating from browser processes to known JeetBot command and control (C2) infrastructure. The rule identifies suspicious C2 communication and, specifically, attempts at token exfiltration by monitoring for auth tokens in the URL of requests directed to known JeetBot hosts and Twitch-related infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
002
This rule identifies browser extensions installed on devices that are either explicitly known as malicious or exhibit suspicious naming patterns potentially associated with unauthorized or malicious extensions.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
002
This rule identifies browser extensions installed on devices that are either explicitly known as malicious or exhibit suspicious naming patterns potentially associated with unauthorized or malicious extensions.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
002
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with a specific AutoIT-based malware delivery chain. It tracks the execution and presence of specific malicious file names and SHA256 hashes, as well as network connections to a identified command-and-control (C2) infrastructure IP address (158.51.122.136). The detection spans file creation, process execution, image loading, and network communication events to identify the multi-stage attack lifecycle.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
25 days ago
002
This rule detects references to specific social media handles and identifiers associated with the MEK/NCRI (National Council of Resistance of Iran) influence campaign within email URLs, device process command lines, and miscellaneous device events. It is designed to identify potential engagement with or dissemination of influence-related content on endpoints and in email communication.
avatar
F S@Fsdr
avatar
Detections.ai Community
25 days ago
202
This rule detects potentially malicious activity where multiple critical processes (such as database engines or email clients) are terminated in a short time frame, correlated with a high volume of file creation or modification events on the same device. This behavior is indicative of destructive activity, such as ransomware encrypting data stores or disabling defensive software.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
2508
Detects Kerberos Ticket Granting Service (TGS) requests (Event ID 4769) that use RC4 encryption (0x17). In modern Active Directory environments, RC4 is considered weak and is often explicitly requested by attackers during Kerberoasting to facilitate offline brute-force cracking of service account passwords. The rule excludes common service accounts (e.g., krbtgt, machine accounts) to reduce noise.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
51051
Detects a process that has established a connection to the Telegram Bot API subsequently performing a large volume of file deletions across multiple folders within a 15-minute window. This behavior is indicative of a remote-controlled destructive attack, such as the deployment of a wiper malware (e.g., HEAVYGRAM or CHOSEN BRICK) triggered via Telegram C2 commands.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
23 days ago
001
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Detects the use of PowerShell, pwsh, or cmd to execute the 'Add-MpPreference' command with the '-ExclusionPath' parameter, specifically targeting common directories like Telegram Desktop or specific system directories. This activity suggests an attempt to bypass security scanning by excluding known malicious locations or folders from Microsoft Defender's real-time monitoring.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
avatar
Arnold Chan@slaz
Defender - KQL
23 days ago
001
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
23 days ago
001
Detects unauthorized processes (non-browser applications) creating, modifying, or renaming sensitive browser data files such as Login Data, Cookies, or local state files within standard browser profile directories. This activity is indicative of credential harvesting or session hijacking attempts by malicious software.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
Identifies instances of Google Chrome running on endpoints with version numbers below the threshold patched for CVE-2026-85046. This detection focuses on specific build numbers (e.g., 152.0.7977.82 for Windows/Linux) to identify potentially vulnerable browser installations in the environment.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
309
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
avatar
Arnold Chan@slaz
avatar
Hunters
23 days ago
001
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
001
Page 332 of 1871