Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects a suspicious process chain where wscript.exe or cscript.exe (executing a VBScript file) initiates a PowerShell process with arguments typically used for downloading external content (e.g., Invoke-WebRequest, Net.WebClient), followed by subsequent actions involving remote management tools or installation packages (e.g., MSI files, ConnectWise, ScreenConnect, GoToResolve). This behavior is characteristic of initial access or secondary payload delivery via malicious scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects the execution of known Remote Monitoring and Management (RMM) software installers or command-line arguments when invoked by PowerShell processes. This behavior is often indicative of malicious post-compromise activity where an adversary uses legitimate remote access tools to establish persistent command-and-control access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects known file hashes associated with SideCopy/ReverseRAT.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
005
Detects known file hashes associated with SideCopy/ReverseRAT.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
905
This rule detects network activity and cloud API events indicative of an adversary utilizing the VAPI.ai platform to orchestrate automated voice-phishing (vishing) campaigns. It correlates outbound network connections to VAPI.ai endpoints with specific webhook callback patterns used to track call status for victim records.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
304
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
305
Detects HTML files that employ FlipBook branding as a lure for password-gated smuggling. The detection identifies client-side JavaScript logic that uses PBKDF2 and AES-GCM to decrypt a hidden redirect URL after user interaction with a password prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects network communication with known malicious infrastructure (C2 IPs and URLs), presence of malicious files identified by SHA256 hashes on disk, and execution of known malicious files. It also correlates these activities with specific operator email addresses involved in the malicious campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects a specific adversarial pattern used to bypass authentication protections, where a browser process first navigates to an attacker-controlled identity verification or CAPTCHA challenge page, followed by an immediate navigation to legitimate Microsoft device code authentication endpoints within the same process session.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
204
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a specific multi-stage exfiltration pattern characterized by initial reconnaissance/fingerprinting probes against sensitive service endpoints (/health, /docs, /openapi.json) followed by unauthorized access to artifact storage endpoints (/files or /file?name=) from the same device against the same host within a short timeframe.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
008
Page 97 of 1870