Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
101
Detects Git checkout operations involving specific SHA hash arguments that occur in conjunction with potential ambiguous refname errors, or are initiated by processes commonly used for AI-assisted coding (e.g., Copilot, Claude). This rule monitors for potentially malicious source code repository manipulation or automated branch hijacking attempts, often seen in supply chain or development environment attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
This rule detects potentially malicious activities aimed at credential harvesting and system recovery inhibition. It monitors for the execution of vssadmin.exe with arguments to list shadow copies (often a precursor to deletion) or references to DPAPI master keys in command lines. Additionally, it identifies unauthorized processes attempting to access sensitive browser-based credential files (e.g., Login Data, Cookies, key4.db) from standard browser installation paths, specifically excluding legitimate browser and update processes.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
001
This rule monitors network, DNS, and email activity to identify communication or references to a set of known malicious domains associated with threat activity. It consolidates logs from device network events, DNS queries, and email telemetry (URLs and sender domains) to detect potential compromise or phishing attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
24 days ago
001
Detects instances where AI-assisted development tools (Claude, Codex, Copilot, Gemini) are used to execute git checkout commands. The rule filters for non-interactive parent processes to identify potentially automated or background execution of git operations by these development assistants.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
001
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
This rule detects processes accessing sensitive credential, configuration, or environment files typically stored in locations like .aws, .ssh, .kube, or application user directories. It alerts when a non-standard or unexpected process touches multiple sensitive folders, or when specific suspicious process names or known malicious tools (such as 'NeedleStealer') are observed interacting with these files. This is indicative of potential credential harvesting or reconnaissance activities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects NeedleStealer Go-based stealer payload via embedded module path, internal API namespace, build tag, and C2 backend domain
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
Detects NeedleStealer Go-based stealer payload via embedded module path, internal API namespace, build tag, and C2 backend domain
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
This rule detects potential command-and-control beaconing activity associated with the Go RAT used in the GapiUpdate campaign. It monitors for outbound network connections over TCP port 5556 to a known malicious C2 IP address, or alternatively, detects persistent outbound activity to other external (non-RFC1918) IP addresses characterized by multiple successive connections within a 10-minute window, which mimics the behavior of persistent beaconing.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
001
This rule detects potential command-and-control beaconing activity associated with the Go RAT used in the GapiUpdate campaign. It monitors for outbound network connections over TCP port 5556 to a known malicious C2 IP address, or alternatively, detects persistent outbound activity to other external (non-RFC1918) IP addresses characterized by multiple successive connections within a 10-minute window, which mimics the behavior of persistent beaconing.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
This rule detects potential command-and-control beaconing activity associated with the Go RAT used in the GapiUpdate campaign. It monitors for outbound network connections over TCP port 5556 to a known malicious C2 IP address, or alternatively, detects persistent outbound activity to other external (non-RFC1918) IP addresses characterized by multiple successive connections within a 10-minute window, which mimics the behavior of persistent beaconing.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
This rule detects potential command-and-control beaconing activity associated with the Go RAT used in the GapiUpdate campaign. It monitors for outbound network connections over TCP port 5556 to a known malicious C2 IP address, or alternatively, detects persistent outbound activity to other external (non-RFC1918) IP addresses characterized by multiple successive connections within a 10-minute window, which mimics the behavior of persistent beaconing.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects a 'git checkout' command targeting a specific commit SHA that is not followed within five minutes by a 'git rev-parse HEAD' integrity check. This behavior, known as 'Plugin4Shell', involves an attacker replacing a pinned commit with a malicious branch of the same name, potentially leading to unauthorized code execution if verification steps are absent.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
21 days ago
000
Detects network activity associated with Rust-based stealer malware, specifically focusing on connections to a known C2 IP address (31.76.7.137) or HTTP requests directed at static-asset paths (e.g., analytics.gif, pixel.png, content.js) when the destination is an IPv4-literal address. This behavior is indicative of C2 beacons or data exfiltration disguised as legitimate web traffic.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
This rule detects successful outbound network connections to the domain 'gapidriver.com' targeting the URI path '/api/get.php'. This pattern is associated with command and control (C2) activity. Due to the lack of specific HTTP header validation in this telemetry source, the signal may require additional validation, such as analyzing the initiating process lineage.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
001
This rule detects successful outbound network connections to the domain 'gapidriver.com' targeting the URI path '/api/get.php'. This pattern is associated with command and control (C2) activity. Due to the lack of specific HTTP header validation in this telemetry source, the signal may require additional validation, such as analyzing the initiating process lineage.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
001
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
001
Page 341 of 1870