Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
1
Platforms
1
Products / Services
1
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
Detects suspicious modifications or registrations of AI agent tools within the registry. The rule identifies three core indicators of compromise: usage of an unverified or external registry source, unauthorized tool definition modifications (hash mismatch against baseline), and a suspicious 'update chain' where a non-standard maintainer pushes a tool update that simultaneously increases requested operational scopes.
