Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects evidence of PowerShell AMSI (Antimalware Scan Interface) bypass attempts, including memory patching of amsiContext, usage of known malicious RC4 keys, or reflection-based tampering with AmsiUtils. These techniques are commonly used by attackers to disable AMSI scanning capabilities and execute malicious scripts undetected.
avatar
Ankit Mehta@Secvyn
Defender - KQL
1 month ago
002
Detects network connection attempts to specific external domains associated with suspicious JavaScript payloads. The rule filters for specific file paths (e.g., mpackage.js, bsc-loader.js) linked to known malicious or suspicious URL patterns on cdn.claritydelivr.com, rcrsinnovations.com, konverto.in, and cdn.api-middle-connect.com, which may indicate C2 beaconing or malware infection.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
102
Detects evidence of PowerShell AMSI (Antimalware Scan Interface) bypass attempts, including memory patching of amsiContext, usage of known malicious RC4 keys, or reflection-based tampering with AmsiUtils. These techniques are commonly used by attackers to disable AMSI scanning capabilities and execute malicious scripts undetected.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
502
This rule identifies potential command and control (C2) activity by correlating DNS over HTTPS (DoH) requests initiated by non-browser or unsigned processes with subsequent network connections to a known malicious C2 domain (gw.proxyvector.cc) within a 15-minute window.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
002
Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
202
Detects network connection attempts to specific external domains associated with suspicious JavaScript payloads. The rule filters for specific file paths (e.g., mpackage.js, bsc-loader.js) linked to known malicious or suspicious URL patterns on cdn.claritydelivr.com, rcrsinnovations.com, konverto.in, and cdn.api-middle-connect.com, which may indicate C2 beaconing or malware infection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
202
Detects the creation or modification of specific dropper/loader files and service worker registration within WordPress directory structures (wp-content/plugins, wp-content/themes, wp-content/uploads). These files are often associated with the injection of malicious scripts (e.g., on-chain resolvers) to facilitate drive-by compromises by site visitors.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
102
Detects evidence of PowerShell AMSI (Antimalware Scan Interface) bypass attempts, including memory patching of amsiContext, usage of known malicious RC4 keys, or reflection-based tampering with AmsiUtils. These techniques are commonly used by attackers to disable AMSI scanning capabilities and execute malicious scripts undetected.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
102
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
003
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
002
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
202
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
000
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
27 days ago
000
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
000
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Detects text/report artifacts (markdown, JSON, plain text) produced by an autonomous AI-driven vulnerability research pipeline that decompiles binaries, traces cross-references, hypothesizes memory-safety flaws, and generates/debugs proof-of-concept exploits
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
27 days ago
000
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
avatar
Arnold Chan@slaz
Defender - KQL
27 days ago
000
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
27 days ago
000
Page 402 of 1870