Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
This rule detects inbound HTTP requests targeting a Vite development server that attempt to access the '.env' configuration file via the '//@fs/' path, which is a known technique for sensitive file exposure in misconfigured Vite environments.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Detects high-volume bursts of HTTP GET requests against specific paths associated with a Vite development server (/@vite/client, /@fs/, /src/) on port 5173. This pattern is indicative of automated reconnaissance or vulnerability scanning targeting an exposed development environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
21 days ago
000
Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
28 days ago
104
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
This rule monitors endpoint events (file, process, and image load) for a specific malicious MD5 hash or the presence of a specific file name pattern 'Request for Quotation' often used in malicious lures. It provides visibility into potential execution of known malicious payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
28 days ago
204
This rule detects modifications to the security descriptors (ACLs) of sensitive Active Directory objects, specifically targeting additions of powerful rights like GenericAll, GenericWrite, WriteDacl, or ForceChangePassword. Monitoring these changes on privileged objects such as Domain Admins, Enterprise Admins, and Domain Controllers is critical for detecting potential privilege escalation or persistence efforts.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
24 days ago
001
Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
3012
This rule monitors for network connections to known command-and-control (C2) IP addresses and the execution or presence of files matching known hashes associated with the 'PhantomC2' threat group or malware family. It correlates data from DeviceNetworkEvents, DeviceFileEvents, and DeviceProcessEvents to identify potential compromise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
100
This rule monitors for network connections to known command-and-control (C2) IP addresses and the execution or presence of files matching known hashes associated with the 'PhantomC2' threat group or malware family. It correlates data from DeviceNetworkEvents, DeviceFileEvents, and DeviceProcessEvents to identify potential compromise.
avatar
Arnold Chan@slaz
Defender - KQL
21 days ago
100
This rule monitors for network connections to known command-and-control (C2) IP addresses and the execution or presence of files matching known hashes associated with the 'PhantomC2' threat group or malware family. It correlates data from DeviceNetworkEvents, DeviceFileEvents, and DeviceProcessEvents to identify potential compromise.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Matches known Phantom Stealer MaaS infostealer sample hashes
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
21 days ago
000
Matches known VectraRAT sample SHA-256 hashes and the ClickFix distribution domain (verify-cloud.digital) recovered from pivoting across exposed VectraRAT distribution infrastructure
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000
Matches known SilverFox malware payload samples by SHA256 hash
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
000
Matches known SilverFox malware payload samples by SHA256 hash
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
21 days ago
000