Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule performs indicator-based detection for the SectopRAT malware. It monitors network activity for connections to known command-and-control (C2) IP addresses and backup domains, as well as file and process creation events matching known malicious SHA256 hashes associated with the malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects DB/DLL files masquerading as legitimate components that embed an XOR-encrypted PE (SectopRAT payload) or the sdkcra.dll loader export used in the FrameworkBase.dll tampered-IAT chain
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
001
Detects the creation of scheduled tasks (Windows), cron jobs (Linux), or systemd timers where the initiating process is a common scripting or runtime interpreter (e.g., Python, Node.js, PowerShell, Java). This activity is often indicative of persistence mechanisms being established by a compromised agent or script-based process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
This rule detects anomalous spikes in network connections from a device to major LLM provider API endpoints (OpenAI, Azure OpenAI, Anthropic) by establishing a baseline for each device and identifying deviations exceeding a statistical threshold. Such behavior may indicate unauthorized data exfiltration or mass data processing using LLM services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects network connection attempts by known AI agent or development-related runtime processes (python, node, etc.) to external endpoints that are not contained within a defined allowlist of LLM and infrastructure providers. This is intended to identify potential data exfiltration or unauthorized command and control communication originating from LLM-powered applications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects instances where AI agent runtime environments, such as Python or Node.js processes, spawn command interpreters to execute commands that suggest reconnaissance or unauthorized system manipulation. This behavior is indicative of a hijacked AI agent abusing its tool-use capabilities to execute commands outside of an approved workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
Detects instances where AI agent runtime processes (e.g., Python, Node.js) initiate child processes using common Windows Living-off-the-Land Binaries (LOLBAS). This behavior may indicate an AI agent has been compromised or misused to execute unauthorized system commands for defense evasion or post-exploitation activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
This rule detects unauthorized or anomalous outbound network connections from known AI agent runtime processes to LLM or API endpoints. It helps identify potential data exfiltration by monitoring for connections to destinations outside of an organization's approved allow-list for model providers, effectively catching scenarios where a compromised AI agent is prompted to relay sensitive data to an attacker-controlled endpoint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
001
Detects package manager utilities (pip, npm, yarn, conda) being executed as child processes by Python or Node.js agent runtime processes. This behavior may indicate an unauthorized installation of plugins or tools within an AI agent framework, potentially bypassing secure deployment pipelines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
101
IOC hunt across DNS, network, and file-hash telemetry for the Ledger Google Ads phishing campaign. Vercel redirect domains are matched by exact hostname (DNS query name / parsed URL host) rather than substring, eliminating false positives from unrelated strings that merely contain a look-alike domain fragment. GCS bucket and Google Sites path IOCs remain substring-matched since the bucket IDs and page slugs are already highly specific.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
003
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
518
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
003
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
203
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
003
This rule detects potential exploitation of the Oracle PeopleSoft PSEMHUB component vulnerability (CVE-2026-35273). It identifies suspicious POST requests to the PSEMHUB HttpListeningConnector servlet, including obfuscated URL paths, followed by the creation of suspiciously named .jsp or .jspx files in the PSEMHUB.war application directory, which is indicative of a web shell deployment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
003
Detects Neo-reGeorg tunnel.jsp/tunnel.jspx servlets used by UNC6240 to establish SOCKS5-over-HTTP(S) tunneling from compromised PeopleSoft PSEMHUB.war hosts
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
003
This rule monitors the software inventory for vulnerable versions of OpenSSL and WolfSSL libraries. Specifically, it flags instances of WolfSSL prior to version 5.9.4, which are susceptible to peer-authentication bypass vulnerabilities. The rule is intended for patch management and asset exposure tracking rather than detecting active exploitation.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
8 days ago
001
Detects a suspected ClickFix phishing sequence where a user navigates to a brand-impersonating GitHub organization or repository, followed by a redirection within a short timeframe to a GitHub Pages portal hosting malicious content. The rule also monitors for direct navigation to a known common lure-hosting domain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
3011
This rule detects known malicious activity including network connections to a specific C2 IP address (69.48.229.140), downloading files from specific C2 URLs, the presence of known malicious file hashes (SHA256), and communications involving specific actor-associated email addresses.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
001
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
501
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
001
Page 48 of 1870