Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects SectopRAT (Arechclient2) .NET RAT binaries deployed via tampered libcef.dll / JetBrains helper DLL sideloading that harvest browser credentials, cookies, credit card data, and files. Tightened to require combined sideload+family+target indicators plus .NET CLR import evidence, avoiding standalone generic strings.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
002
Detects SectopRAT (Arechclient2) .NET RAT binaries deployed via tampered libcef.dll / JetBrains helper DLL sideloading that harvest browser credentials, cookies, credit card data, and files. Tightened to require combined sideload+family+target indicators plus .NET CLR import evidence, avoiding standalone generic strings.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
004
Detects coordinated activity indicative of destructive malware propagation similar to NotPetya. The rule identifies a three-stage sequence on a single host: execution of a DLL via rundll32.exe, followed by file writes to administrative network shares (C$/ADMIN$), and remote process creation via WMI (WmiPrvSE.exe), correlated with a high volume of SMB connections.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
8 days ago
000
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
8 days ago
000
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
000
Detects the GitHub Actions runner executing the Bun runtime to run a hidden index.js payload, specifically associated with the compromised 'actions-cool/issues-helper' or 'actions-cool/maintain-one-comment' actions. The rule filters for process execution context tied to GitHub runner internals and validates that the Bun execution follows the pattern observed in these supply chain attacks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
103
This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools when initiated from suspicious parent processes (such as browsers, office applications, or command-line interpreters), originating from common writeable directories (e.g., Temp, Downloads), or executed with command-line arguments indicative of silent/unattended installation. This behavior is often associated with initial access, persistence establishment, or unauthorized remote control of a system.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects the execution of MSP360 or generic RMM-labeled binaries originating from common user download directories (Downloads or Temp folders) when the filename mimics common phishing lures such as invoice, e-card, RSVP, or document-related naming conventions. This activity indicates a potential social engineering attempt to execute remote monitoring and management tools.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
8 days ago
000
Detects instances where a legitimate Remote Monitoring and Management (RMM) agent (MSP360 or Faronics) is used to execute PowerShell commands that silently install ScreenConnect (ConnectWise Control) MSI packages within a 10-minute window. This behavior is indicative of an adversary abusing administrative tools for lateral movement or persistence.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
8 days ago
000
This rule detects the execution of potentially malicious binaries masquerading as legitimate Windows utilities (e.g., Windows Update, Defender, or Phone Link) from within a ScreenConnect temporary directory. This behavior is indicative of a phishing attack where an adversary uses remote access tools to stage and execute malicious payloads on a victim's system.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
000
This rule detects the execution of potentially malicious binaries masquerading as legitimate Windows utilities (e.g., Windows Update, Defender, or Phone Link) from within a ScreenConnect temporary directory. This behavior is indicative of a phishing attack where an adversary uses remote access tools to stage and execute malicious payloads on a victim's system.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
8 days ago
000
Detects potential persistence and network persistence mechanisms associated with the MSP360 RMM agent. The rule correlates the creation of a Windows service for RMM.Agent.exe or RMM.Agent.Launcher.exe with the addition of a firewall rule allowing UDP traffic on port 48678 by netsh or PowerShell, occurring within a one-hour window.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
000
This rule monitors for DNS queries and network connections to a known list of malicious domains associated with phishing campaigns that deploy remote access tools (such as ScreenConnect or MSP360). These campaigns typically involve users interacting with malicious links to trigger downloads or remote management sessions.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
000
Page 85 of 1870