Browse Rules

Search and filter across all detection sources

108 rules

hayabusa high sigma

TanStack Supply-Chain Attack Execution Indicators - Windows

Detects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath reported on early May 2026.

sigma high sigma

TanStack Supply-Chain Attack Execution Indicators - Windows

Detects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath reported on early May 2026.

hayabusa high sigma

TanStack Supply-Chain Attack Execution Indicators - Windows

Detects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath reported on early May 2026.

signature-base unknown yara

MAL_LiteLLM_SupplyChain_Mar26 [yara]

Detects malicious indicators used in LiteLLM supply chain attack

signature-base unknown yara

MAL_Telnyx_SupplyChain_Mar26 [yara]

Detects malicious indicators used in Telnyx supply chain attack

sigma medium sigma

TanStack Supply-Chain Attack File Creation Indicators - Linux

Detects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026.

sigma medium sigma

TanStack Supply-Chain Attack File Creation Indicators - Windows

Detects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath, etc reported on early May 2026.

sigma high sigma

TeamPCP LiteLLM Supply Chain Attack Persistence Indicators

Detects the creation of specific persistence files as observed in the LiteLLM PyPI supply chain attack. In March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP. The malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.

hayabusa medium sigma

TanStack Supply-Chain Attack File Creation Indicators - Windows

Detects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath, etc reported on early May 2026.

panther medium python

Action Performed by Netskope Personnel

An action was performed by Netskope personnel.

panther medium python

Notion SCIM Token Generated

A Notion User generated a SCIM token.

signature-base unknown yara

APT_MAL_REvil_Kaseya_Jul21_1 [yara]

Detects malware used in the Kaseya supply chain attack

signature-base unknown yara

APT_MAL_REvil_Kaseya_Jul21_2 [yara]

Detects malware used in the Kaseya supply chain attack

signature-base unknown yara

SUSP_JS_Dropper_Mar26 [yara]

Detects suspicious JavaScript dropper used in plain-crypto-js supply chain attacks

panther medium python

GitHub Repository Collaborator Change

Detects when a repository collaborator is added or removed.

signature-base unknown yara

MAL_JS_NPM_SupplyChain_Compromise_Sep25 [yara]

Detects a supply chain compromise in NPM packages (TinyColor, CrowdStrike etc.)

splunk unknown spl

3CX Supply Chain Attack Network Indicators

The following analytic identifies DNS queries to domains associated with the 3CX supply chain attack. It leverages the Network_Resolution datamodel to detect these suspicious domain indicators. This activity is significant because it can indicate a potential compromise stemming from the 3CX supply chain attack, which is known for distributing malicious software through trusted updates. If confirmed malicious, this activity could allow attackers to establish a foothold in the network, exfiltrate

sekoia unknown yara

implant_mac_smoothoperator_update_agent [yara_rules]

UpdateAgent payload delivered by SmoothOperator during the 3CX supply chain attack

sigma high sigma

TanStack Supply-Chain Attack Execution Indicators - Linux

Detects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026. The preinstall hook runs setup.mjs, which downloads a platform-specific Bun runtime.

panther medium python

GitHub Supply Chain - Software Installation Tool User Agents

Detects software installation tool user agents in GitHub audit logs that should never directly access GitHub. Package managers like npm, pip, yarn, and system installers operate at the registry level, not GitHub audit level. Their presence indicates: 1. Supply chain attacks using spoofed user agents to blend in 2. Compromised systems running installation tools with stolen GitHub tokens 3. Malicious automation disguised as legitimate package managers Based on analysis of GitHub audit logs sho

signature-base unknown yara

MAL_JS_NPM_SupplyChain_Attack_Sep25 [yara]

Detects obfuscated JavaScript in NPM packages used in supply chain crypto stealer attacks in September 2025

panther informational python

GitHub User Added or Removed from Org

Detects when a user is added or removed from a GitHub Org.

panther medium python

GitHub User Added to Org Moderators

Detects when a user is added to a GitHub org's list of moderators.

hayabusa high sigma

Potential Suspicious Child Process Of 3CXDesktopApp

Detects potential suspicious child processes of "3CXDesktopApp.exe". Which could be related to the 3CXDesktopApp supply chain compromise

panther high python

GitHub Branch Protection Disabled

Disabling branch protection controls could indicate malicious use of admin credentials in an attempt to hide activity.