Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects network activity associated with Rust-based stealer malware, specifically focusing on connections to a known C2 IP address (31.76.7.137) or HTTP requests directed at static-asset paths (e.g., analytics.gif, pixel.png, content.js) when the destination is an IPv4-literal address. This behavior is indicative of C2 beacons or data exfiltration disguised as legitimate web traffic.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
Detects network activity associated with Rust-based stealer malware, specifically focusing on connections to a known C2 IP address (31.76.7.137) or HTTP requests directed at static-asset paths (e.g., analytics.gif, pixel.png, content.js) when the destination is an IPv4-literal address. This behavior is indicative of C2 beacons or data exfiltration disguised as legitimate web traffic.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
This rule detects successful outbound network connections to the domain 'gapidriver.com' targeting the URI path '/api/get.php'. This pattern is associated with command and control (C2) activity. Due to the lack of specific HTTP header validation in this telemetry source, the signal may require additional validation, such as analyzing the initiating process lineage.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
000
This rule detects successful outbound network connections to the domain 'gapidriver.com' targeting the URI path '/api/get.php'. This pattern is associated with command and control (C2) activity. Due to the lack of specific HTTP header validation in this telemetry source, the signal may require additional validation, such as analyzing the initiating process lineage.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
This rule detects successful outbound network connections to the domain 'gapidriver.com' targeting the URI path '/api/get.php'. This pattern is associated with command and control (C2) activity. Due to the lack of specific HTTP header validation in this telemetry source, the signal may require additional validation, such as analyzing the initiating process lineage.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
000
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
000
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
000
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
000
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
000
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
000
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
Detects outbound network connections from a device to the 'gapidriver.com' domain, specifically targeting the '/api/rest.php' endpoint. This activity is often associated with malware command and control communication.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
This rule detects potential remote command execution using Windows Management Instrumentation (WMI) via wmic.exe or PowerShell, as well as suspicious child processes spawned by the WMI provider host (wmiprvse.exe). It monitors for command lines utilizing the /node switch to target remote systems or invoking WMI methods to trigger execution, which are common patterns for lateral movement.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
002
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
000
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
000
Detects suspicious process execution patterns originating from Langflow or Nacos AI orchestration services, including the spawning of sensitive binaries like cmd, powershell, or scripts (python/bash/sh) with suspicious command-line arguments. Additionally, it identifies potential exploitation attempts targeting known-vulnerable API endpoints (code validation and Nacos user authentication).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
30 days ago
003
Detects post-exploitation persistence artifacts on Windows endpoints consistent with abuse of CVE-2026-18577.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
30 days ago
003
Page 368 of 1870