Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects network connections to known ChatGPT Custom GPT ClickFix campaign infrastructure (IPs and URLs) as reported by Huntress. This rule covers the network_connection logsource only. Domain/DNS matching is covered by a separate dns_query rule, and file-hash matching is covered by a separate process_creation rule, as Sigma only supports one logsource per rule.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects DNS queries to chattypetty.com, associated with the ChatGPT Custom GPT ClickFix campaign (Huntress reporting).
This is one of three logsource-scoped rules split from a combined KQL IOC hunt because Sigma only supports one logsource per rule.
IP/URL matching is covered by a separate network_connection rule; file-hash matching is covered by a separate process_creation rule.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
002
Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
This rule monitors for the creation of known Neo-reGeorg web shell files ('tunnel.jsp', 'tunnel.jspx') within common web server directory paths, such as 'webapps', 'applications', 'wlserver', 'PSHTTP', 'PORTAL', or 'webserv'. Neo-reGeorg is a popular tunneling web shell used by adversaries to facilitate persistent access and proxy traffic into a compromised environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
Detects the execution of the SIDEEYE backdoor (Ple64.exe) when it is spawned by web-based processes such as Java (WebLogic) or shell interpreters (cmd.exe/powershell.exe) invoked by web-based parents. This behavior is indicative of a web shell exploitation attempt.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
avatar
Arnold Chan@slaz
avatar
Hunters
14 days ago
002
This rule detects a sequential multi-stage execution chain starting with msiexec.exe launching a hidden PowerShell script, followed by wscript.exe executing a VBScript agent, and finally node.exe executing a JavaScript file within a short time window. This pattern is indicative of a complex, multi-stage dropper or malware execution flow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
005
Detects the loading of a known malicious 136KB browser injection helper DLL (SHA256: 75018b06c7105a1dca391805d17b402aed35ebd515b92d461236eafbd606cb40) into Google Chrome or Microsoft Edge processes. The rule further correlates this activity with command line arguments indicative of abusing the browser's elevation service, which is a technique often used for process injection or local privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
005
Detects the deletion of Chrome registry keys related to extension integrity verification. This behavior is often associated with browser-based attacks, such as malware or malicious extensions attempting to tamper with browser security configurations to enable persistent browser hijacking or unauthorized extension modification.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
305
Detects the ChainScript RAT agent (executing as node.exe from specific masquerading directory paths) scanning for and enumerating cryptocurrency wallet files, browser-stored wallet extensions, and related sensitive configuration data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
205
Detects the installation or configuration of the NvFsFilter (Alinubx.sys) persistence driver, often associated with malicious behavior that continuously terminates security software processes to allow for persistent unauthorized activity after system reboots.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
005
This rule detects the loading of the known vulnerable NvFsFilter (Alinubx) driver, followed by the abrupt cessation of multiple active AV/EDR processes within a 30-minute window. This behavior is indicative of a Bring Your Own Vulnerable Driver (BYOVD) attack, where the driver is used to execute kernel-mode commands to terminate security software, bypassing standard protection mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
105
Detects the execution of MSI installers from user-writable directories (e.g., Downloads, Temp, Public) that masquerade as legitimate software applications like Spotify, Zoom, or Microsoft Teams. This behavior is indicative of 'ClickFix' style social engineering lures, where users are prompted to download and execute malicious installers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
105
Detects the installation of a Windows service that mimics the legitimate NVIDIA File System Filter Driver (NvFsFilter). Adversaries, such as those associated with the Rapuncel infostealer, use this technique to establish persistence and evade security controls by masquerading as a common driver component.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
205
Page 99 of 1870