Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,719 detections

Detects unauthorized access by a non-browser process to Chromium-based 'Cookies' SQLite database files, which are used by browsers like Chrome, Edge, and Brave. This behavior is a strong indicator of credential theft or session hijacking, as attackers target these files to extract session cookies and bypass MFA for cloud services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized access attempts to Chromium-based browser credential storage files, specifically 'Login Data' (SQLite database) and 'Local State' (master key storage), by processes other than standard browsers or known security products. This activity is a common indicator of credential harvesting by information stealers such as LummaC2, Vidar, and RedLine.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects interactive (Logon Type 10) or network (Logon Type 3) authentication to Windows hosts originating from external, non-RFC1918 IP addresses using 'Negotiate' authentication. This pattern is indicative of potential lateral movement from a cloud-connected environment into on-premises infrastructure, specifically where an adversary might be leveraging stolen session artifacts or credentials to bypass standard Kerberos-based domain authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects typical behavior associated with infostealers targeting browser data, specifically the creation of compressed archives (.zip, .rar) in temporary directories (Temp or AppData) and the subsequent exfiltration of data via known webhook services (e.g., Discord, Telegram, Pastebin) or direct IP connections. It filters out common signed backup and synchronization software to minimize noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the ClickFix/fake-CAPTCHA initial access pattern where users are socially engineered into copying and pasting malicious commands into the Windows Run dialog or a browser-spawned shell. The rule matches on process creation events involving mshta.exe, powershell.exe, or wscript.exe initiated by explorer.exe or common shell-related processes, filtering out known administrative and deployment software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of administrative utilities (psexec.exe, wmic.exe, powershell.exe, cmd.exe) initiating network connections over common remote management ports (135, 139, 445, 3389, 5985, 5986) to internal destinations. This behavior is indicative of lateral movement activity, particularly when initiated from a host that has recently engaged in credential harvesting or infostealer-related activity. The rule excludes common, expected sources to minimize noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects activity indicative of the 'ClickFix' social engineering technique, where users are tricked into manually executing obfuscated commands (often from fake CAPTCHA or error prompts) via the Windows Run dialog or command-line interfaces. The rule correlates suspicious process execution (e.g., mshta, powershell, certutil, curl) originating from explorer.exe with the detection of common encoded/obfuscated command line patterns, or interactions with the Windows RunMRU registry key, which logs commands typed into the Run dialog.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a multi-stage activity chain indicative of infostealer malware, including reading the browser 'Local State' file (containing the master key), accessing a browser process (likely for memory dumping or token extraction), and initiating an immediate outbound network connection to an external destination.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized access to common browser credential storage files (Login Data, Cookies, Web Data, Local State) by processes other than standard web browsers. This rule identifies potentially malicious activity by filtering for rare or unsigned binaries executing from common staging directories (Temp, Downloads) or accessing browser files shortly after the process launch, which is a common behavior pattern for info-stealer malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects attempts to enumerate or access Windows Credential Manager and vault files, often used by adversaries to extract cached credentials. The rule monitors for execution of vaultcmd.exe, invocation of keymgr.dll via rundll32.exe, and unauthorized access to credential storage paths in AppData by non-system processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects processes that access multiple categories of sensitive data (browser autofill, cryptocurrency wallets, password manager exports, or system fingerprinting files) within a short time window. This behavior is highly indicative of modular infostealers or data-collection malware conducting 'stacking access' to stage sensitive information for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects network connections initiated by unsigned executables that were recently created (within one hour) in common staging directories such as AppData, Temp, or ProgramData. It specifically targets beacons to the Telegram Bot API or Discord webhooks, which are common patterns for command-and-control (C2) communication used by malware such as the Amadey bot.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential lateral movement by users who have recently been flagged for credential theft or infostealer activity. The rule correlates initial security alerts with subsequent Windows logon events (RDP, network/WinRM) or SMB share access, identifying users connecting to multiple distinct destinations within a 48-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a hybrid identity attack sequence where an anomalous or high-risk cloud sign-in (e.g., AD FS, Azure AD Connect) is followed within 24 hours by suspicious on-premise Active Directory activity, specifically DCSync replication requests or Kerberoasting (high volume of TGS requests). This pattern is indicative of an attacker leveraging stolen cloud session tokens to pivot into on-premise infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the mounting of VHDX files via disk imaging tools or PowerShell, followed shortly (within 15 minutes) by the execution of a shell process with hidden window flags. This behavioral pattern is associated with the delivery of malicious payloads, such as those observed in Star Blizzard's RedFlick delivery chain for CosmicPulse.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects the creation of specific decoy scheduled tasks ('Internet Quality Test Connection', 'Network Configuration Manager', 'System Health Monitor') identified as part of the Star Blizzard actor's CosmicPulse delivery mechanism. The rule monitors for the creation of these tasks via schtasks.exe or system events, specifically when the task configuration references execution via rundll32.exe, regsvr32.exe, control.exe, or remote/UNC-based payloads.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects the execution of a Control Panel (.cpl) item using control.exe or rundll32.exe. The rule specifically looks for CPL files that were recently written to suspicious directories (Temp, AppData, Downloads) and correlates this execution with subsequent suspicious behaviors, such as spawning Python processes, outbound network connections, or registry modifications consistent with key storage or payload persistence.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
10 days ago
202
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
Defender - KQL
10 days ago
002
Detects host and browser fingerprinting reconnaissance behavior associated with the Macfinger/ClickFix infection chain. The rule identifies multiple disparate indicators (ClickFix tracker domain, ipinfo.io geolocation lookups, and known AMOS C2 IP contact) occurring on the same device within a 15-minute window, effectively reducing noise from isolated or benign network lookups.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
10 days ago
002
Detects the execution of 'setup.js' by the node.js runtime when initiated by 'npm install' or 'postinstall' hooks. This behavior is a common indicator of a malicious supply chain attack where a compromised or malicious npm package executes unauthorized code during the package installation or setup phase.
avatar
mate rix@materix
avatar
Detections.ai Community
17 days ago
1013