Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
Platforms
1
Products / Services
1
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
Detects unauthorized or anomalous write operations (upsert/insert) to a vector database, which could indicate a Retrieval-Augmented Generation (RAG) injection attack. The rule monitors for writes from non-sanctioned identities, operations outside of established maintenance or ingestion windows, or entries that lack necessary provenance metadata such as source document IDs or content hashes.
