Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
Detects high-volume filesystem activity (exceeding 300 operations in 5 minutes) initiated by 'claude-code' or 'claude' processes. This behavior may indicate an autonomous, patched, or jailbroken AI coding assistant performing mass file operations or reconnaissance without user confirmation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
000
This rule detects potentially malicious usage of the Windows RegSvcs.exe binary, often used as a proxy for executing code. It monitors for two specific patterns: RegSvcs.exe being executed from user-writable directories (e.g., C:\Users\, C:\ProgramData\), or RegSvcs.exe spawning suspicious child processes (e.g., PowerShell, cmd, WScript, mshta), which is indicative of a living-off-the-land (LotL) attack technique to bypass application control or execute payloads.
avatar
F S@Fsdr
avatar
Detections.ai Community
28 days ago
103
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects an exploitation attempt against the Vite Development Server (CVE-2026-39364) where an attacker uses specific query parameters to bypass file access restrictions and disclose sensitive files. The rule triggers on GET requests containing suspicious import-related query parameters and checks the resulting response to ensure a successful 200/206 status code and non-HTML content type.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects an exploitation attempt against the Vite Development Server (CVE-2026-39364) where an attacker uses specific query parameters to bypass file access restrictions and disclose sensitive files. The rule triggers on GET requests containing suspicious import-related query parameters and checks the resulting response to ensure a successful 200/206 status code and non-HTML content type.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
001
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
001
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects the execution of known Windows accessibility binaries (e.g., sethc.exe, utilman.exe) where the internal metadata or original filename indicates that the process is actually cmd.exe. This is a common technique used by adversaries to gain unauthenticated command-line access with SYSTEM privileges via accessibility features, typically during the login screen process.
avatar
F S@Fsdr
avatar
Detections.ai Community
1 month ago
207
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
001
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
001
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects network connections to known command and control (C2) infrastructure, including hardcoded malicious domains, specific C2 IP addresses, and suspicious GitHub access patterns by processes other than standard web browsers, which may indicate malicious ingress tool transfer or C2 communication.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
30 days ago
705
Detects instances of the Windows utility RegSvcs.exe being executed from suspicious, user-writable directories (such as Temp or Public folders) or instances where RegSvcs.exe is used to spawn common command-line or scripting tools, which is a common indicator of living-off-the-land binary (LOLBin) abuse.
avatar
F S@Fsdr
avatar
Detections.ai Community
28 days ago
103
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
30 days ago
205
Detects instances where VLC media player is launched from common temporary or untrusted directories (e.g., Downloads, Temp) with media files and subsequently crashes within a short window (2 minutes), as indicated by a corresponding werfault.exe error report. This behavior may indicate an attempt to exploit vulnerabilities within the VLC application by using a maliciously crafted file.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
102
This rule detects potentially malicious behavior by correlating intensive usage of graphics-related API calls (like BitBlt, GetDC, etc.) which are indicative of screen capture, with the execution of specific command identifiers typically associated with C2 (Command and Control) traffic. The combination suggests an adversary is capturing screen data and potentially staging or exfiltrating it via a C2 channel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule monitors for network connections to known command-and-control (C2) IP addresses and the execution or presence of files matching known hashes associated with the 'PhantomC2' threat group or malware family. It correlates data from DeviceNetworkEvents, DeviceFileEvents, and DeviceProcessEvents to identify potential compromise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
001
Detects ClickFix-style social engineering attacks where users are prompted to copy and execute malicious commands in a shell environment. The rule triggers on process execution of terminal or shell binaries (zsh, sh, cmd.exe, powershell.exe) containing indicators of obfuscated execution or remote code downloading, such as piped shell commands (curl | sh/zsh) or PowerShell encoded command execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Detects high-frequency screen capture activity by monitoring process module loads related to BitBlt, GDI32.dll, and explicit screen capture descriptions. This rule identifies sustained screen scraping behavior (50+ events within a 5-minute window) indicative of the SparroWocky malware surveillance module's screen monitoring functionality.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
This rule monitors Portable Executable (PE) files to identify those signed with certificates associated with Discord Inc. or Lenovo. Adversaries frequently abuse stolen or fraudulently obtained code-signing certificates from legitimate, reputable companies to bypass security controls like Windows SmartScreen, gain persistence, or increase the likelihood of successful malware execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
000
Page 353 of 1870