Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
001
Detects cortex-xdr-payload.exe connecting to a server outside Palo Alto Networks LRC infrastructure. Attackers can abuse the Live Terminal feature as a pre-installed, EDR-trusted C2 channel by redirecting the payload to their own server using a URL validation bypass in the server hostname check
avatar
chiki briki@ekkor13
avatar
Detections.ai Community
1 month ago
45016
Detects network activity from infrastructure provisioner tools (Terraform, Coder) or shell processes attempting to connect to suspicious domains (e.g., coder-infra.com) that resemble legitimate infrastructure domains. This activity is indicative of credential theft, specifically targeting OIDC tokens, SSH keys, or authentication tokens during automated provisioning processes.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects the execution of Terraform commands (init, apply, plan) that interact with the 'registry.coder.com' domain, or direct network connections to the associated infrastructure. This may indicate the use of unauthorized or compromised Infrastructure-as-Code (IaC) modules or malicious supply chain activity involving Terraform configurations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
This rule identifies endpoints running specific Windows OS versions susceptible to CVE-2026-69414 (ShieldBreak) that currently have Microsoft Defender for Endpoint configured as the active and compliant antivirus solution. This is used for tracking compensating controls across the fleet.
avatar
Adarsh Pandey@Pandeyadarsh
avatar
Detections.ai Community
1 month ago
33053
Detects scripts or files referencing the JSCeal loading chain that invokes node.exe with -r preflight.js to decompress and execute a compiled V8 bytecode app.jsc payload
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects a suspicious sequence of activities where PowerShell downloads or extracts specific zip files (node.zip, build.zip) to staging directories, followed by the execution of associated binaries like node.exe, winpty-agent.exe, or winpty.dll from those same locations. This behavior is indicative of an adversary staging and executing tooling within temporary user directories.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects a hardcoded PEM RSA public key embedded alongside JSCeal-specific compiled V8 bytecode obfuscation artifacts, used to encrypt exfiltrated data or C2 communications
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects Node.js or related helper processes executing shell commands (cmd.exe, powershell.exe) or other processes where the execution involves the 'withCreateProcessUser' argument. This often indicates attempts to bypass execution restrictions or run malicious payloads by utilizing Node.js as an execution proxy within unconventional or temporary directories.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects Node.js or related helper processes executing shell commands (cmd.exe, powershell.exe) or other processes where the execution involves the 'withCreateProcessUser' argument. This often indicates attempts to bypass execution restrictions or run malicious payloads by utilizing Node.js as an execution proxy within unconventional or temporary directories.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
Detects Node.js or related helper processes executing shell commands (cmd.exe, powershell.exe) or other processes where the execution involves the 'withCreateProcessUser' argument. This often indicates attempts to bypass execution restrictions or run malicious payloads by utilizing Node.js as an execution proxy within unconventional or temporary directories.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
This rule detects suspicious activity associated with JSCeal proxy handlers. It identifies Node.js or Electron processes running from non-standard, user-writable directories (such as AppData, ProgramData, or Temp folders) that actively delete or modify browser cookie files within standard web browser profile paths, often indicative of session hijacking or data tampering.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
001
This rule detects suspicious activity associated with JSCeal proxy handlers. It identifies Node.js or Electron processes running from non-standard, user-writable directories (such as AppData, ProgramData, or Temp folders) that actively delete or modify browser cookie files within standard web browser profile paths, often indicative of session hijacking or data tampering.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
This rule detects suspicious activity associated with JSCeal proxy handlers. It identifies Node.js or Electron processes running from non-standard, user-writable directories (such as AppData, ProgramData, or Temp folders) that actively delete or modify browser cookie files within standard web browser profile paths, often indicative of session hijacking or data tampering.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects periodic screen capture activity performed by Node.js or Electron-based processes, correlated with subsequent outbound network connections to public IP addresses within a short timeframe. This behavior is indicative of the JSCeal malware's surveillance and exfiltration module, where local reconnaissance via screenshotting is followed by data transmission.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
001
Detects when a Node.js process initiates a low-level keyboard hook (WH_KEYBOARD_LL or WH_KEYBOARD) while running from common user-writable directories, which may indicate malicious keylogging activity by a suspicious process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects anomalous child process creation (e.g., cmd.exe, powershell.exe, rundll32.exe) spawned by the VMware host process 'vmware-vmx.exe'. This behavioral pattern is a high-confidence indicator of potential guest-to-host virtual machine escape, specifically monitoring for activity associated with vulnerabilities like CVE-2026-59346.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
1 month ago
001
Detects an internal/compromised mailbox sending phishing-style email to multiple employees, the technique CISA's red team used to gain initial workstation access via a trusted internal sender.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
26028
Page 417 of 1870