Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
Platforms
1
Products / Services
1
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
Detects the installation of Model Context Protocol (MCP) servers or AI agent plugins that exhibit characteristics of supply chain risk, such as unverified or unknown publishers, requests for highly sensitive permissions (filesystem write, credential read, unrestricted network egress), or recent public listing, which aligns with AI model supply chain poisoning techniques (AML.T0104).
