Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects potential browser-based wallet address substitution attacks by monitoring for a specific sequence of network connections within a single browser process. It looks for connections to cryptocurrency swap platforms (SimpleSwap/SwapZone) closely followed by the retrieval of an external loader script (paste.sh) and a Google Sheets Visualization API payload, which is a known technique for injecting malicious scripts that intercept and modify XHR/fetch responses in the user's browser.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
000
This rule detects potential browser-based wallet address substitution attacks by monitoring for a specific sequence of network connections within a single browser process. It looks for connections to cryptocurrency swap platforms (SimpleSwap/SwapZone) closely followed by the retrieval of an external loader script (paste.sh) and a Google Sheets Visualization API payload, which is a known technique for injecting malicious scripts that intercept and modify XHR/fetch responses in the user's browser.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
This rule detects potential browser-based manipulation or phishing campaigns where a user visits a known loader script host (paste.sh) and subsequently visits cryptocurrency trading sites (SimpleSwap, SwapZone) within a short time window. This behavior is indicative of an injected script modifying the browser's view of trading sites to display deceptive 'Loyalty Bonus' or discount banners to lure users into transactions.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
This rule detects potential browser-based manipulation or phishing campaigns where a user visits a known loader script host (paste.sh) and subsequently visits cryptocurrency trading sites (SimpleSwap, SwapZone) within a short time window. This behavior is indicative of an injected script modifying the browser's view of trading sites to display deceptive 'Loyalty Bonus' or discount banners to lure users into transactions.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
000
Detects a multi-stage browser-based web skimming attack. The rule identifies a specific sequence of network activity: a device fetching an obfuscated loader script from 'paste.sh', followed by retrieving payload fragments from the 'Google Sheets Visualization API', and concluding with network interactions with crypto-transaction services 'SwapZone.io' or 'SimpleSwap.io', characteristic of a browser-based wallet-drainer campaign.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
000
This rule detects activities related to Tampermonkey (a popular browser extension for userscripts) or interactions with paste.sh, often used for hosting scripts or payloads. The rule monitors both process-level executions and network requests for these indicators, which may be associated with malicious script execution or browser-based credential or session theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
000
This rule monitors for a multi-stage attack pattern involving two potential indicators: first, it identifies phishing emails containing a 'Google Docs' link combined with an attachment named 'API Logic Flaw'. Second, it detects browser activity involving the paste of JavaScript code or suspicious browser clipboard activity, which may indicate an attacker attempting to execute malicious scripts directly in the user's browser context.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
000
Detects execution of 'BrowserCore.exe' when the initiating (parent) process is not a recognized web browser (msedge.exe, chrome.exe, or firefox.exe). This rule flags potential process masquerading or misuse of the BrowserCore utility, particularly when spawned by command interpreters or the Task Scheduler.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
1 month ago
13016
Detects the loading or usage of the malicious driver 'DCRCVDrv.sys' associated with the ClearFake crypto stealer campaign, which uses a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to interact with the device path '\Device\DCRCVDRV_U' to terminate or impair EDR and security tools.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
000
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
29 days ago
000
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
000
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
000
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
avatar
Ankit Mehta@Secvyn
Defender - KQL
29 days ago
000
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
29 days ago
000
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
29 days ago
000
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
29 days ago
000
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
avatar
Ankit Mehta@Secvyn
Defender - KQL
29 days ago
000
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
29 days ago
000
Page 419 of 1870