Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
1
Platforms
1
1
1
Products / Services
1
1
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
This rule detects the unauthorized download of complete ML model checkpoint or weight files from a model registry or object storage. It monitors for common model file extensions in download events that are not associated with a legitimate deployment justification or a pre-approved change management window, helping to identify potential intellectual property theft or model exfiltration attempts.
