Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

4 detections

Detects email from a new hire (within 30 days of hire date) combining personal-crisis pretext language with an explicit request to use a personal or unmanaged device, corroborated by a non-compliant or untrusted device sign-in, consistent with PurpleDelta's device-substitution social-engineering pattern.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects email communications from a recently-created account (within 60 days of account creation) requesting redirection of payroll or business payments to a personal bank account under a fabricated 'bank account under review' pretext, consistent with PurpleDelta payment-fraud tradecraft.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
205
Detects spearphishing email impersonating the CSIS 'Indo-Pacific Forecast 2026' invitation-only event lure, gated on CSIS branding/display name combined with a sender domain that does not match csis.org.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
308
Detects phishing emails impersonating AI/LLM service providers that reference API keys or developer consoles and contain embedded URLs to login/signin/auth/console pages, consistent with token-jacking campaigns harvesting developer credentials.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
15023