Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects suspicious modifications or registrations of AI agent tools within the registry. The rule identifies three core indicators of compromise: usage of an unverified or external registry source, unauthorized tool definition modifications (hash mismatch against baseline), and a suspicious 'update chain' where a non-standard maintainer pushes a tool update that simultaneously increases requested operational scopes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000