Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects network indicators associated with the Exvicy/ErrTraffic 'ClickFix' campaign. The rule identifies the retrieval of malicious HTML lure templates from compromised WordPress sites and subsequent telemetry/registration calls to an attacker-controlled 'api.php' script, which are precursors to the fake Cloudflare Turnstile 'Win+R' execution sequence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
105
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects instances of mshta.exe initiating network connections to cloud storage providers (CloudFront, Cloudflare R2/pages) to retrieve multiple remote files (specifically .js or .txt). This behavior is indicative of an exploit stage where mshta.exe is used as a LOLBAS to fetch orchestrator scripts and gadget payloads for memory-based deserialization attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
This rule detects potential HTML smuggling activity by identifying a browser process writing an executable file named 'config.exe' to the user's Downloads folder without a traditional network download event, followed immediately by Microsoft Defender SmartScreen or Antivirus reporting a warning or scan failure on the file. This behavior is indicative of a payload being reconstructed on the client-side via JavaScript blobs or data URLs, which is a common characteristic of HTML smuggling delivery chains.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
11 days ago
101
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects potential HTML smuggling activity by identifying a browser process writing an executable file named 'config.exe' to the user's Downloads folder without a traditional network download event, followed immediately by Microsoft Defender SmartScreen or Antivirus reporting a warning or scan failure on the file. This behavior is indicative of a payload being reconstructed on the client-side via JavaScript blobs or data URLs, which is a common characteristic of HTML smuggling delivery chains.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects UAT-11587 Stage 1 HTA and WSF stager template: hidden/zero-sized window, fixed Cloudflare Pages tracking beacon with ?track, and WinHttp/MSXML ActiveXObject loading Stage 2 from Cloudflare R2 or CloudFront.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a suspicious sequence of events where a common internet-facing server process (e.g., w3wp.exe, nginx.exe) spawns a potentially malicious child process (e.g., cmd.exe, powershell.exe), followed shortly thereafter by mass file modifications on the same host, which is characteristic of ransomware behavior following initial exploitation.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects SQL injection exploitation attempts against MOVEit Transfer targeting the CVE-2023-34362 vulnerability, followed by the deployment and subsequent interaction with the 'human2.aspx' webshell associated with Cl0p ransomware mass-exploitation campaigns.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Page 88 of 1870