Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects unauthorized or anomalous write operations (upsert/insert) to a vector database, which could indicate a Retrieval-Augmented Generation (RAG) injection attack. The rule monitors for writes from non-sanctioned identities, operations outside of established maintenance or ingestion windows, or entries that lack necessary provenance metadata such as source document IDs or content hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001