Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
001
This rule identifies browser extensions installed on devices that are either explicitly known as malicious or exhibit suspicious naming patterns potentially associated with unauthorized or malicious extensions.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
001
This rule identifies browser extensions installed on devices that are either explicitly known as malicious or exhibit suspicious naming patterns potentially associated with unauthorized or malicious extensions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
001
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
001
Detects network connections to JeetBot/Twitch Enhanced Viewer malicious browser extension infrastructure exfiltrating Twitch OAuth tokens. Apex domains (jeetbot.cc, api.jeetbot.cc) are gated on a token-forwarding indicator to avoid false positives.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
001
Detects network connections to JeetBot/Twitch Enhanced Viewer malicious browser extension infrastructure exfiltrating Twitch OAuth tokens. Apex domains (jeetbot.cc, api.jeetbot.cc) are gated on a token-forwarding indicator to avoid false positives.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
001
Detects network connections to JeetBot/Twitch Enhanced Viewer malicious browser extension infrastructure exfiltrating Twitch OAuth tokens. Apex domains (jeetbot.cc, api.jeetbot.cc) are gated on a token-forwarding indicator to avoid false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
25 days ago
001
This rule detects potential phishing activity by correlating email delivery of Excel attachments with subsequent network connections to known malicious domains initiated by common browser or office processes. It identifies cases where a user may have opened a suspicious Excel file and initiated an outbound network request to a flagged domain within 24 hours of receiving the email.
avatar
Lewis Weedon@LewisWeedon
avatar
Detections.ai Community
1 month ago
762158
This rule monitors for indicators of compromise (IOCs) associated with a specific AutoIT-based malware delivery chain. It tracks the execution and presence of specific malicious file names and SHA256 hashes, as well as network connections to a identified command-and-control (C2) infrastructure IP address (158.51.122.136). The detection spans file creation, process execution, image loading, and network communication events to identify the multi-stage attack lifecycle.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
25 days ago
001
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
000
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
000
Page 359 of 1870