Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects the execution of 'charmap.exe' from the Syswow64 directory where the process hierarchy indicates suspicious activity. The detection identifies a chain where PowerShell spawns 'conhost.exe', which in turn spawns a process from a temporary directory (interpreted as a renamed AutoIT executable) that then launches 'charmap.exe'. This pattern is indicative of a multi-stage obfuscated execution flow often used in malware dropper scenarios to bypass standard monitoring.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
25 days ago
000
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
25 days ago
000
Detects the execution of PowerShell commands that utilize a combination of 'Test-Path', 'Start-Sleep' (or 'sleep'), and arithmetic obfuscation (e.g., -lt (63+17)). This pattern is often used in malicious scripts to implement a delay while obfuscating the duration, a technique frequently seen in staging or persistence phases to evade sandbox analysis or signature-based detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
000
Detects the execution of PowerShell commands that use character-based obfuscation to call 'CreateDirectory' and interact with the user's temporary environment folder. This pattern is commonly observed when scripts attempt to hide file staging or payload delivery paths from static analysis.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
000
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
000
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
25 days ago
000
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
000
Detects network connections to known JeetBot infrastructure domains and IP addresses. The rule specifically identifies potential exfiltration of Twitch OAuth tokens via URL parameters or interaction with known token-collection proxy endpoints, which are associated with the JeetBot/Twitch Enhanced Viewer credential harvesting campaign.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
000
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
25 days ago
000
Detects network connections to JeetBot/Twitch Enhanced Viewer malicious browser extension infrastructure exfiltrating Twitch OAuth tokens. Apex domains (jeetbot.cc, api.jeetbot.cc) are gated on a token-forwarding indicator to avoid false positives.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
25 days ago
000
This rule monitors for a multi-stage attack pattern involving two potential indicators: first, it identifies phishing emails containing a 'Google Docs' link combined with an attachment named 'API Logic Flaw'. Second, it detects browser activity involving the paste of JavaScript code or suspicious browser clipboard activity, which may indicate an attacker attempting to execute malicious scripts directly in the user's browser context.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
002
This rule detects potential web skimmer activity where a user's browser performs a network connection to known payload delivery hosts (e.g., paste.sh or Google Sheets API) followed by a clipboard modification event on the same device within a one-hour window. This behavior is consistent with malicious scripts attempting to replace copied cryptocurrency wallet addresses with an attacker-controlled address.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
002
Detects browser-based network requests to the Google Sheets Visualization API (gviz/tq) that appear to be used for fetching malicious JavaScript payloads from public Google Sheets. The rule specifically identifies instances where a process initiates these requests without any corresponding active browser session associated with standard Google Docs or Sheets editing activity.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
002
This rule detects potential browser-based manipulation or phishing campaigns where a user visits a known loader script host (paste.sh) and subsequently visits cryptocurrency trading sites (SimpleSwap, SwapZone) within a short time window. This behavior is indicative of an injected script modifying the browser's view of trading sites to display deceptive 'Loyalty Bonus' or discount banners to lure users into transactions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
102
This rule detects potential browser-based wallet address substitution attacks by monitoring for a specific sequence of network connections within a single browser process. It looks for connections to cryptocurrency swap platforms (SimpleSwap/SwapZone) closely followed by the retrieval of an external loader script (paste.sh) and a Google Sheets Visualization API payload, which is a known technique for injecting malicious scripts that intercept and modify XHR/fetch responses in the user's browser.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
102
Detects browser-based network requests to the Google Sheets Visualization API (gviz/tq) that appear to be used for fetching malicious JavaScript payloads from public Google Sheets. The rule specifically identifies instances where a process initiates these requests without any corresponding active browser session associated with standard Google Docs or Sheets editing activity.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
102
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
105
Detects the loading or usage of the malicious driver 'DCRCVDrv.sys' associated with the ClearFake crypto stealer campaign, which uses a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to interact with the device path '\Device\DCRCVDRV_U' to terminate or impair EDR and security tools.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
29 days ago
002
This rule monitors for file, process, and image load events associated with a set of known malicious indicators (IOCs). It specifically flags potential DLL side-loading anomalies, such as 'Secur32.dll' being loaded by 'platform_experience_helper.exe' from non-system directories, or 'platform_experience_helper.exe' executing from locations outside the standard Google application directory.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
29 days ago
102
This rule monitors for file, process, and image load events associated with a set of known malicious indicators (IOCs). It specifically flags potential DLL side-loading anomalies, such as 'Secur32.dll' being loaded by 'platform_experience_helper.exe' from non-system directories, or 'platform_experience_helper.exe' executing from locations outside the standard Google application directory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
002
This rule monitors for indicators of compromise (IOCs) associated with a specific AutoIT-based malware delivery chain. It tracks the execution and presence of specific malicious file names and SHA256 hashes, as well as network connections to a identified command-and-control (C2) infrastructure IP address (158.51.122.136). The detection spans file creation, process execution, image loading, and network communication events to identify the multi-stage attack lifecycle.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
000
Page 382 of 1870