Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects an internal/compromised mailbox sending phishing-style email to multiple employees, the technique CISA's red team used to gain initial workstation access via a trusted internal sender.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
26028
This rule detects potential data exfiltration by monitoring write activity to external USB storage devices. It identifies scenarios where a high number of files (more than 25) or a significant total volume of data (more than 100MB) is written to a connected USB device within a short timeframe.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
307
Detects the execution or initiation of a process named 'PrettyPrague.exe' while running with SYSTEM level privileges (AccountSid: S-1-5-18) from directories associated with Avast antivirus software. This activity is indicative of potential privilege escalation or malicious activity masquerading within legitimate security software paths.
avatar
Amit Ambekar@Amit007
avatar
Detections.ai Community
1 month ago
406
This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
102
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
002
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
002
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
202
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
102
Detects instances where the OneDrive sync client process creates files on drives other than the system drive (e.g., D: drive and beyond). This pattern is often used to identify potentially suspicious file synchronization activities or the use of secondary storage locations that may deviate from baseline OneDrive configurations.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
1 month ago
604
Detects repeated, non-interactive requests to the Google Sheets Visualization API (gviz/tq) originating from common web browsers. This pattern is indicative of a malicious browser extension attempting to reconstruct or reinject payloads when a user visits specific targeted websites.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
Detects a multi-stage browser-based web skimming attack. The rule identifies a specific sequence of network activity: a device fetching an obfuscated loader script from 'paste.sh', followed by retrieving payload fragments from the 'Google Sheets Visualization API', and concluding with network interactions with crypto-transaction services 'SwapZone.io' or 'SimpleSwap.io', characteristic of a browser-based wallet-drainer campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
000
Detects a multi-stage browser-based web skimming attack. The rule identifies a specific sequence of network activity: a device fetching an obfuscated loader script from 'paste.sh', followed by retrieving payload fragments from the 'Google Sheets Visualization API', and concluding with network interactions with crypto-transaction services 'SwapZone.io' or 'SimpleSwap.io', characteristic of a browser-based wallet-drainer campaign.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
This rule detects potential web skimmer activity where a user's browser performs a network connection to known payload delivery hosts (e.g., paste.sh or Google Sheets API) followed by a clipboard modification event on the same device within a one-hour window. This behavior is consistent with malicious scripts attempting to replace copied cryptocurrency wallet addresses with an attacker-controlled address.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
Page 418 of 1870