Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
Detects DB/DLL files masquerading as legitimate components that embed an XOR-encrypted PE (SectopRAT payload) or the sdkcra.dll loader export used in the FrameworkBase.dll tampered-IAT chain
Detects the creation of scheduled tasks (Windows), cron jobs (Linux), or systemd timers where the initiating process is a common scripting or runtime interpreter (e.g., Python, Node.js, PowerShell, Java). This activity is often indicative of persistence mechanisms being established by a compromised agent or script-based process.
This rule detects anomalous spikes in network connections from a device to major LLM provider API endpoints (OpenAI, Azure OpenAI, Anthropic) by establishing a baseline for each device and identifying deviations exceeding a statistical threshold. Such behavior may indicate unauthorized data exfiltration or mass data processing using LLM services.
Detects network connection attempts by known AI agent or development-related runtime processes (python, node, etc.) to external endpoints that are not contained within a defined allowlist of LLM and infrastructure providers. This is intended to identify potential data exfiltration or unauthorized command and control communication originating from LLM-powered applications.
Detects instances where AI agent runtime environments, such as Python or Node.js processes, spawn command interpreters to execute commands that suggest reconnaissance or unauthorized system manipulation. This behavior is indicative of a hijacked AI agent abusing its tool-use capabilities to execute commands outside of an approved workflow.
Detects instances where AI agent runtime processes (e.g., Python, Node.js) initiate child processes using common Windows Living-off-the-Land Binaries (LOLBAS). This behavior may indicate an AI agent has been compromised or misused to execute unauthorized system commands for defense evasion or post-exploitation activities.
This rule detects unauthorized or anomalous outbound network connections from known AI agent runtime processes to LLM or API endpoints. It helps identify potential data exfiltration by monitoring for connections to destinations outside of an organization's approved allow-list for model providers, effectively catching scenarios where a compromised AI agent is prompted to relay sensitive data to an attacker-controlled endpoint.
Detects package manager utilities (pip, npm, yarn, conda) being executed as child processes by Python or Node.js agent runtime processes. This behavior may indicate an unauthorized installation of plugins or tools within an AI agent framework, potentially bypassing secure deployment pipelines.
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
Detects a suspected ClickFix phishing sequence where a user navigates to a brand-impersonating GitHub organization or repository, followed by a redirection within a short timeframe to a GitHub Pages portal hosting malicious content. The rule also monitors for direct navigation to a known common lure-hosting domain.
This rule detects known malicious activity including network connections to a specific C2 IP address (69.48.229.140), downloading files from specific C2 URLs, the presence of known malicious file hashes (SHA256), and communications involving specific actor-associated email addresses.
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
Page 48 of 1870


