Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a suspicious pattern where a single process loads high-risk cryptography and system-level modules (e.g., sqlite3, win32crypt, win32api) followed within 30 minutes by credential harvesting actions such as dumping Wi-Fi keys using 'netsh' or establishing persistence via 'schtasks'. This behavior is indicative of a 'lazy-import' stealer or malicious loader attempting to evade simple signature-based detection.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
TokenGrabber Builder: Nuitka/PyInstaller AV-Evasion Compilation - detects Python builder scripts compiling an embedded stealer.py payload into a native executable via Nuitka or PyInstaller with AV-evasion flags
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
001
Detects the creation of a Windows scheduled task via schtasks.exe where the initiating process is located in common user-writable temporary or non-standard directories (e.g., AppData, Temp, or Public folders). This behavior is often indicative of malicious persistence mechanisms being established by a dropper or stage-one malware payload.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
10 days ago
101
Detects the creation of multiple suspicious scheduled tasks using schtasks.exe initiated by scripting engines (wscript.exe, cscript.exe). The rule filters for specific task names associated with known malicious patterns and XML definition files located in a specific directory path, identifying potential automated persistence or malware installation behavior.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
308
Detects HTTP response bodies containing indicators of 'ClickFix' social engineering lures. The rule monitors for JavaScript code designed to manipulate the user's clipboard (execCommand('copy') or clipboard.writeText) in conjunction with instructions for the user to execute the Windows Run dialog (Win+R), a common technique to trick users into executing malicious commands under the guise of solving a fake CAPTCHA or error.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
202
This rule detects network traffic patterns indicative of the Lumma Stealer 'ClickFix' phishing campaign. It identifies outbound requests to suspicious domains ending in .cyou utilizing specific user agents (WinHttp or Microsoft BITS), which are characteristic of malicious PowerShell scripts attempting to retrieve secondary payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
202
Detects the execution of command interpreters or scripting engines spawned by the ManageEngine ADSelfService Plus GINA client process (typically present at the Windows logon screen). This activity is highly suspicious as it indicates potential command injection or abuse of a pre-authentication component running at SYSTEM privileges.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
15 days ago
105
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
17 days ago
208
Detects a high volume (more than 5 files within an hour) of potentially executable file types (.lnk, .exe, .vbs) created on non-system drives (D:, E:, F:). This pattern is often associated with the staging of malicious payloads, autorun-based infection attempts, or automated tool deployment from removable or secondary storage.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
12 days ago
002
This rule detects network connections initiated by common Windows administrative or scripting binaries (powershell.exe, cmd.exe, certutil.exe, bitsadmin.exe, mshta.exe) to remote URLs that end with extensions associated with executable content (.exe, .dll, .ps1, .bat). This behavior is often indicative of an adversary performing ingress tool transfer to download and execute malicious payloads.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
12 days ago
102
Detects the compiled x86/x64 fetch-decode-execute dispatch loop used by the Vidar Stealer custom VM bytecode interpreter (v2.0+). The rule identifies the structural jump-table bounds-check and computed-jump idiom that is consistent across different builds of the malware, despite randomization of opcode values and XOR keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
005
Detects trojanized versions of Zoom installers that bundle legitimate application installers alongside malicious components including a VBScript persistence mechanism (OneDriveUpdateScheduler) and the VelvetCake PowerShell downloader/C2 framework.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
005
Detects the Exvicy 'ClickFix' campaign execution chain where explorer.exe spawns a PowerShell process utilizing download commands (e.g., Invoke-WebRequest, Invoke-RestMethod) to interact with known malicious domains or IP addresses, followed by the execution of installers (msiexec.exe) or tools (putty.exe) within a short timeframe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
306
Detects the execution of script interpreters (powershell, cmd, mshta, etc.) spawned directly by explorer.exe via the Run dialog, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands to bypass security mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
306
Detects the use of package installation commands (pip, npm, npx) where the package name resembles popular AI/ML libraries (tensorflow, torch, openai, langchain) but is not an exact match for known legitimate versions. This is a common indicator of a typosquatting supply chain attack, where attackers attempt to trick users into installing malicious packages with similar names to trusted software.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
202
Detects the installation of known AI-powered coding assistant extensions (e.g., Copilot, Tabnine, Cursor) on a device, followed by significant source-code repository cloning or archival activity by Git within two hours. This pattern is potentially indicative of intellectual property theft or sensitive source code exfiltration facilitated by a newly introduced AI tool.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
002
This rule detects outbound network connections originating from managed devices where the remote URL or domain matches known underground LLM-based services, such as WormGPT, FraudGPT, or EvilGPT, which are often used by threat actors for malicious activities like generating phishing content or malware.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
102
This rule detects the use of headless or automated web browser tooling (such as Selenium, Puppeteer, Playwright, or browser-specific drivers like chromedriver) establishing network connections to popular generative AI websites. This behavior can indicate automated interaction with AI services, potential data exfiltration of internal information, or unauthorized automation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
412
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Detects various indicators of compromise (IOCs) including known malicious file hashes, suspicious file names commonly associated with staging or initialization in web directories, and network communication to known malicious domains or URLs. It also monitors process execution command lines for references to these IOCs, excluding common browser processes.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
100
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Page 68 of 1870