Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
000
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
000
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects anomalous, bulk file access activity targeting browser credential databases, cryptocurrency wallet data, and application-specific configuration stores, characteristic of the SectopRAT 'DeployBrowserKey' command.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects the specific command-line sequence used by SectopRAT for self-deletion. The malware uses 'choice' to create a delay followed by a 'del' command to remove its own executable, a technique for deleting files after the process has terminated.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects the suspicious pattern of a process reading a 'pool.db' file followed immediately by the loading of .NET Common Language Runtime (CLR) modules (clr.dll or mscoreei.dll). This behavior is characteristic of fileless execution chains where a secondary payload is retrieved and executed directly in memory.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects the SectopRAT shellcode execution stage by identifying the concurrent access of a specific encrypted database file (Activation.Desktop.db) and the loading of a malicious DLL (stp_aim_x64_vc15.dll) on the same device within a 5-minute window. This behavior suggests the decryption and execution of shellcode via DLL callback abuse.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects the ReportDump.exe process initiating a network connection on port 15847 followed by the loading of GDI/User32 libraries shortly thereafter. This behavior is indicative of SectopRAT establishing a command-and-control channel and initializing screen capture capabilities.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
9 days ago
000
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
1010
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
18 days ago
307
Detects instances where common AI agent orchestration runtimes (e.g., LangChain, AutoGPT, CrewAI) spawn command-line or scripting interpreters as child processes. This behavior is highly suspicious and often indicative of malicious command execution triggered by prompt injection attacks, where an adversary manipulates the agent into executing arbitrary system commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects the installation of common AI agent and orchestration frameworks (e.g., LangChain, AutoGen, CrewAI) using command-line package managers (pip, npm, conda) that point to non-standard or unverified package indexes. This behavior is a common indicator of a potential software supply-chain compromise, where an adversary attempts to inject malicious code by forcing the installation of packages from an attacker-controlled source.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects command-line operations indicative of bulk data export, dumping, or unauthorized scanning against vector databases (e.g., Pinecone, Chroma, Milvus, Qdrant) and caching backends (e.g., Redis). Such activities may indicate an adversary attempting to exfiltrate training data, embeddings, or context stored within an AI agent's memory backend.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects scenarios where common download utilities are used to fetch a file from the internet, followed by the immediate execution or loading of that same file within a 10-minute window, indicative of an Ingress Tool Transfer followed by execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
This rule detects automated browser-based processes (such as chromedriver, msedgedriver, geckodriver, playwright, or node/python scripts leveraging browser automation frameworks) initiating network connections to domains or URLs identified in active threat intelligence as malicious. This behavior is indicative of an AI agent or automated script being steered toward attacker-controlled infrastructure, potentially for drive-by compromise or exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects DNS query activity from processes commonly used as AI agent runtimes (e.g., python.exe, node.exe) toward domains characterized by DGA-like patterns, such as long alphanumeric strings or high-consonant density, which may indicate command-and-control communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects successful remote authentication events (Network or Interactive) performed by AI agent orchestration service accounts. This rule monitors for atypical lateral movement patterns where an automated service account pivots to remote hosts using protocols such as RDP or WinRM, diverging from its standard operational context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects a burst of file delete or overwrite operations initiated by a configured AI agent service identity. This behavior, if deviating from established baselines, may indicate a compromised agent performing malicious destructive activities such as mass data deletion or ransomware-style file destruction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Detects attempts to inject code into an AI agent orchestrator process by monitoring for suspicious CreateRemoteThread events. This rule is designed to identify potential process hijacking attacks by malicious actors seeking to bypass application-layer controls, while excluding common legitimate security monitoring tools that may exhibit similar behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
9 days ago
000
Page 92 of 1870