Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects creation of the 'goopdate' Run-key value pointing to Sang.exe/defender.exe with the 'work' argument and a %programdata% path, used by CoolClient for persistence.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Correlates at least 3 of 4 distinct Abyssos background polling threads (clipboard, process list, network connections, screen capture) launched by the same unsigned/unknown-signature parent process within the same 5-minute window.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects the DOUBLECUP/ClickFix loader activity which involves a sequence of suspicious command-line execution patterns. The rule correlates three specific behaviors occurring within a 5-minute window: finding PowerShell paths using 'where', searching for the 'ZZ1984' marker using 'findstr', and executing a minimized background command process. This combination is highly indicative of the ClickFix delivery chain used to trick users into running malicious commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
8019
Detects the Abyssos UAC_BYPASS_FODHELPER technique: a ms-settings\Shell\Open\command registry value set immediately before fodhelper.exe launches an unsigned child payload, silently elevating to a high-integrity process without a UAC prompt.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a WinRAR-extracted OnyxC2 loader spawning an identical self-copy child process from a temp/download path, marking the transition from loader stage to active stealer logic.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
302
Detects creation of the ONYXC2 mutex used by the malware to enforce single-instance execution.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects extraction and execution of OnyxC2 lure archives (Setup_File*.zip, Fling-Standalone*.zip) via WinRAR/7-Zip from a Downloads/Temp directory, correlating the archive-open with the lure-named installer executing shortly after.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Matches endpoint file/process hashes and network IPs against a curated, freshness-checked OnyxC2 indicator feed.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
302
Detects creation of a non-default hidden desktop by a browser process, correlated with either an inherited long-lived authenticated browser network session or a non-standard parent process, consistent with OnyxC2's HVNC capability.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects a multi-hop HTTP redirect chain traversing two or more known OnyxC2 phishing lure domains from the same host within a two-minute window, consistent with the redirect obfuscation used before final payload delivery.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
This rule detects DNS configuration changes (via 'netsh' commands or registry modifications to the 'NameServer' value) initiated by specific system processes ('SwiService.exe' or 'svchost.exe') shortly after a Plug-and-Play (PnP) event, such as a USB drive connection. This pattern is indicative of potential malicious activity attempting to redirect DNS queries upon the insertion of unauthorized hardware.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
208
This rule detects potential privilege escalation through the abuse of a debug backdoor in the Wacom WTabletServiceISD service. It identifies when the 'PowerT' registry value is set for the service, followed shortly by the service spawning a command shell (cmd.exe or powershell.exe) under SYSTEM privileges. It specifically excludes scenarios where AutoAdminLogon is enabled, which might otherwise trigger false positives.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
008
This one's the interesting bit they're using Ethereum RPC calls as a C2channel and dumping stolen secrets to attacker-owned public repos tagged "Shai-Hulud: Here We Go Again". Also flags Claude/VS Code config file writes dropped by the worm for lateral persistence across dev machines.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
7018
This rule detects DNS configuration changes (via 'netsh' commands or registry modifications to the 'NameServer' value) initiated by specific system processes ('SwiService.exe' or 'svchost.exe') shortly after a Plug-and-Play (PnP) event, such as a USB drive connection. This pattern is indicative of potential malicious activity attempting to redirect DNS queries upon the insertion of unauthorized hardware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
2 months ago
818
Detects the use of native Windows utilities such as vssadmin, wbadmin, wmic, diskshadow, and bcdedit to delete volume shadow copies, backup catalogs, or modify boot configuration to prevent system recovery. The rule explicitly excludes designated backup servers to reduce noise from legitimate management activities.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
206
This rule detects the creation or modification of files within the Google Chrome browser extensions directory by processes other than legitimate Chrome-related binaries (chrome.exe, GoogleUpdate.exe). This activity is highly indicative of malicious browser extension sideloading or persistence, where an adversary attempts to install a rogue extension to achieve goals such as credential theft, session hijacking, or command-and-control communication.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
606
This rule detects potentially unauthorized access or memory dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. It monitors for events where processes interact with LSASS or execute commands containing 'lsass.exe', 'MiniDump', or 'comsvcs.dll', while excluding known administrative and benign processes like Task Manager, Procdump, and Windows Error Reporting.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
2 months ago
906
Detects python.exe executing from unusual locations (AppData, Temp, or ProgramData directories) that subsequently establish outbound network connections, consistent with DeviceManager RAT behavior delivered via the DOUBLECUP loader.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
3017
Detect DNS tunnelling via long subdomain labels. The query is useful for identifying DNS queries with unusually long request strings (typically 40+ characters per label) and high volumes of repetitive requests used by attackers to exfiltrate data or run command-and-control (C2) channels.
avatar
Montaser Ismail@M0nt3x
avatar
Detections.ai Community
2 months ago
15035
This rule detects instances where a process that is not a recognized web browser attempts to access sensitive files associated with browser credential stores, such as Login Data, Cookies, and web browser state files. Such activity is commonly associated with infostealer malware, which attempts to exfiltrate saved passwords, session cookies, and autofill information.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
2 months ago
16032
Detects execution of a 'setup.mjs' preinstall lifecycle hook, the stage-1 loader used in the
4 August 2026 compromise of the keyv and cacheable npm namespaces. The trojanised package.json
adds "preinstall": "node setup.mjs" while leaving dist/ byte-identical to the last clean
release, so the only execution-time signal is the hook itself. The loader downloads a
standalone Bun runtime and executes an obfuscated second stage (Math_Symbol.js).
avatar
Lourenço Santos@lourenco
avatar
Detections.ai Community
2 months ago
9032
Page 476 of 1866