Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,178 detections

Detects periodic, beacon-like network activity targeting public platforms such as Steam community profiles or Telegram (api.telegram.org / t.me) originating from suspicious processes (script interpreters, unsigned binaries). This behavior is characteristic of LummaC2 and similar malware families using public web services as dead-drop resolvers for C2 fallback communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects instances of potential lateral movement using PsExec or WMI following an alert related to credential compromise, infostealers, or session hijacking, where the same user account is involved in both events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
501
Detects a single process reading browser cookie SQLite database files across multiple distinct browser profile directories or different web browsers within a short time window. This behavior is indicative of infostealer activity attempting to harvest session cookies for session hijacking and MFA bypass.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects a suspected infostealer activity chain involving the unauthorized access of credential and session cookie files, followed by the archival of these files into a temporary or staging directory, and concluding with an outbound network connection to an uncommon destination from the archiving process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects potential session hijacking by correlating endpoint-based detections of known infostealer malware (e.g., Vidar, Lumma, Redline) with a subsequent cloud Identity Provider (IdP) login for the same user. The correlation specifically focuses on instances where the IdP authentication originates from an IP address different from the infected host, suggesting the use of stolen session cookies by an external actor to access corporate resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the loading of specific commonly side-loaded DLLs (libcef.dll, version.dll, msimg32.dll) from user-writable directories such as Downloads, Temp, or AppData. Attackers often use these locations to drop malicious DLLs alongside legitimate applications to achieve DLL side-loading for persistence or defense evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects unauthorized non-browser processes attempting to access Chrome browser master keys or bypass App-Bound Encryption by interacting with the Chrome IElevator service, DPAPI routines, or the 'Local State' configuration file. This behavior is indicative of infostealer activity aiming to decrypt browser-stored session cookies and credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects unauthorized processes attempting to read sensitive session files or databases associated with messaging applications like Telegram, Signal, and Discord. Accessing these files (such as 'tdata', 'db.sqlite', or 'leveldb') allows for full account takeover by extracting session tokens, enabling attackers to bypass authentication and 2FA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects non-CLI and non-DevOps utility processes accessing sensitive cloud credential and configuration files, including AWS SSO caches, AWS credentials, kubeconfig, and gcloud configuration files. This behavior is indicative of credential theft or discovery by infostealers attempting to gain unauthorized access to cloud environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects unauthorized access to DPAPI master key files located in the Windows user profile (%APPDATA%\Microsoft\Protect\). This activity is commonly associated with infostealers attempting to decrypt browser-stored credentials (cookies, passwords) by manually accessing the master key files after exfiltrating encrypted data stores.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects DNS resolution attempts for newly registered or suspicious top-level domains (e.g., .xyz, .top, .live) that mimic corporate Identity Provider (IdP) or Single Sign-On (SSO) login portals. This behavior is characteristic of Adversary-in-the-Middle (AiTM) phishing kits like EvilProxy or Tycoon2FA, intended to capture user session tokens. Note: This rule monitors for initial domain contact and should be correlated with subsequent authentication logs to identify potential session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects unauthorized access to common browser credential storage files (Login Data, Cookies, Web Data, Local State) by processes other than standard web browsers. This rule identifies potentially malicious activity by filtering for rare or unsigned binaries executing from common staging directories (Temp, Downloads) or accessing browser files shortly after the process launch, which is a common behavior pattern for info-stealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule correlates endpoint security alerts for popular information-stealer malware (Lumma, StealC, Vidar, RedLine, Acreed, Atomic Stealer) with subsequent successful cloud identity authentication events from the same user account. The correlation window is set to 72 hours following an endpoint infostealer detection, which suggests potential account takeover or unauthorized access facilitated by credentials stolen from a compromised endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the startup or configuration of the WebClient service, commonly associated with WebDAV redirection, followed within 15 minutes by a process (e.g., control.exe, rundll32.exe, svchost.exe) interacting with a WebDAV-style UNC path. This behavioral pattern is indicative of attackers, such as the Star Blizzard group, abusing built-in Windows functionality to facilitate credential theft or remote file execution via malicious WebDAV shares.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
101
Detects a multi-stage exfiltration sequence consisting of: (1) bulk file archival/compression using common utilities, (2) suspicious OAuth grant or service principal authorization, and (3) abnormal network egress volume to common ports. This pattern suggests an adversary is preparing data, establishing or leveraging an identity/application for cloud access, and subsequently exfiltrating data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
203
Detects the LEMURLOOT ASP.NET web shell deployed by Cl0p following exploitation of CVE-2023-34362 in MOVEit Transfer
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
103
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
000
Detects the creation of a new Windows service where the service executable is located in potentially suspicious directories such as \Temp\, \Users\Public\, \AppData\, or \ProgramData\. Attackers often use these locations to drop and execute malicious payloads or persistence mechanisms while bypassing standard software installation security controls.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
8 days ago
101
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
avatar
Arnold Chan@slaz
avatar
SlimKQL
16 days ago
4012
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
2010
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
106
Page 34 of 1866