Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

This rule monitors for potential persistence and malicious activity by aggregating three distinct detection signals: COM hijacking attempts via the InprocServer32 registry key, the creation of scheduled tasks using specific suspicious naming conventions, and the identification of named mutexes indicative of specific malware presence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
102
Detects the legitimate wmpnetwk.exe process, commonly used as a target for ShadowPad process injection, initiating outbound network connections while simultaneously accessing Firefox browser profile data. This behavior is indicative of credential theft and command-and-control communication typical of post-compromise activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
102
Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
Detects text/report artifacts (markdown, JSON, plain text) produced by an autonomous AI-driven vulnerability research pipeline that decompiles binaries, traces cross-references, hypothesizes memory-safety flaws, and generates/debugs proof-of-concept exploits
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
001
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
001
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
001
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
001
This rule detects unauthorized or suspicious automated scraping behavior by identifying periodic, non-interactive tasks that perform high-volume outbound network requests to multiple external hosts. It specifically filters for processes launched via scheduling mechanisms (Task Scheduler, cron) that exhibit indicators of anti-bot or proxy-rotation bypass techniques (such as usage of headless browser tools or proxy-related keywords in command lines). The rule is tuned to ignore legitimate system maintenance, update, and monitoring processes.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
001
This rule detects potentially unauthorized process executions (such as shells, network utilities, or enumeration tools) originating from TeamCity server processes (java.exe, javaw.exe). It filters out known TeamCity build agent or maintenance activities to highlight deviations from standard server behavior.
avatar
Thiru N@Iamthiru
avatar
Detections.ai Community
1 month ago
107
Identifies devices running versions of Chromium-based browsers (such as Chrome) vulnerable to CVE-2026-85046, a V8 type confusion vulnerability that allows remote code execution within the browser sandbox.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
1 month ago
103
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
1 month ago
003
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
avatar
Arnold Chan@slaz
Defender - KQL
24 days ago
000
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
000
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
avatar
Arnold Chan@slaz
avatar
Hunters
24 days ago
000
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
000
Page 378 of 1870