Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects DNS resolutions to popular threat intelligence, reputation, and sandboxing APIs (e.g., VirusTotal, URLScan, AbuseIPDB) originating from non-browser processes on non-analyst workstations. This behavior may indicate an attacker programmatically querying these services to verify if their infrastructure, payloads, or IP addresses are flagged as malicious, or to conduct reconnaissance.
avatar
Shadows VMB@Vemorian_Mort
avatar
Detections.ai Community
16 hours ago
102