Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects unauthorized processes attempting to read or create sensitive browser credential files ('Login Data', 'Web Data', 'Cookies', 'logins.json', 'key4.db'). This activity is commonly associated with information-stealing malware (such as Lumma, StealC, Vidar, RedLine, and Amadey) that targets browser databases to extract stored secrets, often bypassing standard browser process access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects a multi-stage attack chain where a device shows signs of credential theft (accessing browser credential stores or cookies) followed closely by a successful cloud authentication from that same user using a device identifier not previously observed in the last 30 days.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule correlates events across the end-to-end kill chain of an enterprise intrusion, specifically tracking the progression from initial endpoint-based infostealer activity (credential access), through anomalous or non-interactive sign-in activity, into privilege escalation or mailbox delegation within the cloud environment, and finally to mass data exfiltration or mail access. It detects accounts involved in at least three distinct stages of this progression within a 72-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects instances where a user account associated with a detected infostealer malware infection (e.g., Redline, Raccoon, Vidar) successfully authenticates to a cloud service from a suspicious network location, such as a VPN, residential proxy, or Tor exit node, within 24 hours of the infection alert.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule detects potential account compromise by identifying 'impossible travel' scenarios where successful logins for the same user occur from different geolocations within a short timeframe (less than 1 hour), specifically when at least one authentication event uses a refresh or session token rather than interactive MFA. It correlates these suspicious logins with previous endpoint infostealer detections on the same device within the last 72 hours, indicating that the token may have been stolen by malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule detects the installation or execution of common Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop, TeamViewer) on Windows endpoints within a 4-hour window of associated cloud identity risk activity (such as risky sign-ins, MFA changes, or privilege grants). It filters out legitimate activity initiated via standard software management pipelines (e.g., SCCM, Intune) to identify potential unauthorized use of remote access software by adversaries following account compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects the use of common archiving utilities (7zip, WinRAR, Tar, or PowerShell Compress-Archive) to bundle sensitive Google Chrome user data, such as cookies, login data, or the entire user data profile directory. This behavior is indicative of an adversary attempting to stage sensitive information for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects impossible-travel activity where a single user account authenticates successfully from multiple distinct countries or IP addresses within a short 15-minute window. This behavior is highly indicative of potential session hijacking or the concurrent use of a stolen session token by both an attacker and a legitimate user.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects the execution of common command-line cloud synchronization and file transfer utilities (such as rclone, rsync, and MEGAcmd) when invoked with flags or patterns indicative of data staging or exfiltration, such as copy, sync, or targeting remote cloud storage locations.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects periodic, beacon-like network activity targeting public platforms such as Steam community profiles or Telegram (api.telegram.org / t.me) originating from suspicious processes (script interpreters, unsigned binaries). This behavior is characteristic of LummaC2 and similar malware families using public web services as dead-drop resolvers for C2 fallback communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects instances of potential lateral movement using PsExec or WMI following an alert related to credential compromise, infostealers, or session hijacking, where the same user account is involved in both events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
501
Detects a single process reading browser cookie SQLite database files across multiple distinct browser profile directories or different web browsers within a short time window. This behavior is indicative of infostealer activity attempting to harvest session cookies for session hijacking and MFA bypass.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects a suspected infostealer activity chain involving the unauthorized access of credential and session cookie files, followed by the archival of these files into a temporary or staging directory, and concluding with an outbound network connection to an uncommon destination from the archiving process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects potential session hijacking by correlating endpoint-based detections of known infostealer malware (e.g., Vidar, Lumma, Redline) with a subsequent cloud Identity Provider (IdP) login for the same user. The correlation specifically focuses on instances where the IdP authentication originates from an IP address different from the infected host, suggesting the use of stolen session cookies by an external actor to access corporate resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects the loading of specific commonly side-loaded DLLs (libcef.dll, version.dll, msimg32.dll) from user-writable directories such as Downloads, Temp, or AppData. Attackers often use these locations to drop malicious DLLs alongside legitimate applications to achieve DLL side-loading for persistence or defense evasion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects unauthorized non-browser processes attempting to access Chrome browser master keys or bypass App-Bound Encryption by interacting with the Chrome IElevator service, DPAPI routines, or the 'Local State' configuration file. This behavior is indicative of infostealer activity aiming to decrypt browser-stored session cookies and credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects unauthorized processes attempting to read sensitive session files or databases associated with messaging applications like Telegram, Signal, and Discord. Accessing these files (such as 'tdata', 'db.sqlite', or 'leveldb') allows for full account takeover by extracting session tokens, enabling attackers to bypass authentication and 2FA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects non-CLI and non-DevOps utility processes accessing sensitive cloud credential and configuration files, including AWS SSO caches, AWS credentials, kubeconfig, and gcloud configuration files. This behavior is indicative of credential theft or discovery by infostealers attempting to gain unauthorized access to cloud environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Page 37 of 1870