Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
000
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
000
This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the 'CSuite' phishing and RMM (Remote Monitoring and Management) campaign. It monitors network, DNS, proxy, email, URL click, and file creation telemetry over the past 24 hours to identify interactions with known-malicious IP addresses, domains, URLs, and file hashes related to the campaign.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
Detects a sequence of events on a single device involving a remote MSI installation followed by PowerShell-based process elevation and administrative checks using fltmc.exe. This pattern is indicative of an attacker attempting to deploy malicious packages remotely and escalate privileges within the environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
000
Detects the unauthorized creation of script or executable files in the Windows Startup directory by .NET or Python runtime processes, specifically targeting the exploitation pattern of CVE-2026-25592. This vulnerability allows an AI agent host to bypass sandbox isolation and write files to the host filesystem, potentially establishing persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
Detects the execution of the 'gitshot' binary, which is known to automatically create public repositories and release tags to host screenshots or screen recordings. This behavior can be abused by insiders or attackers to exfiltrate sensitive data outside of corporate control.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
000
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
11 days ago
001
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
002
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Page 84 of 1870