Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential browser-based wallet address substitution attacks by monitoring for a specific sequence of network connections within a single browser process. It looks for connections to cryptocurrency swap platforms (SimpleSwap/SwapZone) closely followed by the retrieval of an external loader script (paste.sh) and a Google Sheets Visualization API payload, which is a known technique for injecting malicious scripts that intercept and modify XHR/fetch responses in the user's browser.
This rule detects potential browser-based wallet address substitution attacks by monitoring for a specific sequence of network connections within a single browser process. It looks for connections to cryptocurrency swap platforms (SimpleSwap/SwapZone) closely followed by the retrieval of an external loader script (paste.sh) and a Google Sheets Visualization API payload, which is a known technique for injecting malicious scripts that intercept and modify XHR/fetch responses in the user's browser.
This rule detects potential browser-based manipulation or phishing campaigns where a user visits a known loader script host (paste.sh) and subsequently visits cryptocurrency trading sites (SimpleSwap, SwapZone) within a short time window. This behavior is indicative of an injected script modifying the browser's view of trading sites to display deceptive 'Loyalty Bonus' or discount banners to lure users into transactions.
This rule detects potential browser-based manipulation or phishing campaigns where a user visits a known loader script host (paste.sh) and subsequently visits cryptocurrency trading sites (SimpleSwap, SwapZone) within a short time window. This behavior is indicative of an injected script modifying the browser's view of trading sites to display deceptive 'Loyalty Bonus' or discount banners to lure users into transactions.
Detects a multi-stage browser-based web skimming attack. The rule identifies a specific sequence of network activity: a device fetching an obfuscated loader script from 'paste.sh', followed by retrieving payload fragments from the 'Google Sheets Visualization API', and concluding with network interactions with crypto-transaction services 'SwapZone.io' or 'SimpleSwap.io', characteristic of a browser-based wallet-drainer campaign.
This rule detects activities related to Tampermonkey (a popular browser extension for userscripts) or interactions with paste.sh, often used for hosting scripts or payloads. The rule monitors both process-level executions and network requests for these indicators, which may be associated with malicious script execution or browser-based credential or session theft.
This rule monitors for a multi-stage attack pattern involving two potential indicators: first, it identifies phishing emails containing a 'Google Docs' link combined with an attachment named 'API Logic Flaw'. Second, it detects browser activity involving the paste of JavaScript code or suspicious browser clipboard activity, which may indicate an attacker attempting to execute malicious scripts directly in the user's browser context.
Detects execution of 'BrowserCore.exe' when the initiating (parent) process is not a recognized web browser (msedge.exe, chrome.exe, or firefox.exe). This rule flags potential process masquerading or misuse of the BrowserCore utility, particularly when spawned by command interpreters or the Task Scheduler.
Detects the loading or usage of the malicious driver 'DCRCVDrv.sys' associated with the ClearFake crypto stealer campaign, which uses a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to interact with the device path '\Device\DCRCVDRV_U' to terminate or impair EDR and security tools.
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
Page 419 of 1870
