Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
This rule identifies browser extensions installed on devices that are either explicitly known as malicious or exhibit suspicious naming patterns potentially associated with unauthorized or malicious extensions.
This rule identifies browser extensions installed on devices that are either explicitly known as malicious or exhibit suspicious naming patterns potentially associated with unauthorized or malicious extensions.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to JeetBot/Twitch Enhanced Viewer malicious browser extension infrastructure exfiltrating Twitch OAuth tokens. Apex domains (jeetbot.cc, api.jeetbot.cc) are gated on a token-forwarding indicator to avoid false positives.
Detects network connections to JeetBot/Twitch Enhanced Viewer malicious browser extension infrastructure exfiltrating Twitch OAuth tokens. Apex domains (jeetbot.cc, api.jeetbot.cc) are gated on a token-forwarding indicator to avoid false positives.
Detects network connections to JeetBot/Twitch Enhanced Viewer malicious browser extension infrastructure exfiltrating Twitch OAuth tokens. Apex domains (jeetbot.cc, api.jeetbot.cc) are gated on a token-forwarding indicator to avoid false positives.
This rule detects potential phishing activity by correlating email delivery of Excel attachments with subsequent network connections to known malicious domains initiated by common browser or office processes. It identifies cases where a user may have opened a suspicious Excel file and initiated an outbound network request to a flagged domain within 24 hours of receiving the email.
This rule monitors for indicators of compromise (IOCs) associated with a specific AutoIT-based malware delivery chain. It tracks the execution and presence of specific malicious file names and SHA256 hashes, as well as network connections to a identified command-and-control (C2) infrastructure IP address (158.51.122.136). The detection spans file creation, process execution, image loading, and network communication events to identify the multi-stage attack lifecycle.
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
Page 359 of 1870


