Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
10 detections
Filters
Last updated
All Time
Detection languages
6
3
1
Contributors
3
3
2
1
1
Categories
6
4
4
2
2
Platforms
7
2
2
1
Products / Services
6
4
3
2
1
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
IDS Classtypes
4
2
IDS Protocols
3
3
Detects potential embedding inversion or extraction attempts by identifying callers exhibiting abnormally high volumes of similarity or vector search queries against RAG-enabled vector stores or cognitive search APIs within a short timeframe.
Detects potential embedding inversion or extraction attempts by identifying callers exhibiting abnormally high volumes of similarity or vector search queries against RAG-enabled vector stores or cognitive search APIs within a short timeframe.
Detects high-volume DNS queries for subdomains of 'twilio.com' originating from a single source IP within a short 5-minute window, indicative of subdomain enumeration or reconnaissance.
Detects high-rate scanning and automated service probing patterns consistent with network reconnaissance. This includes tracking TCP SYN floods to external segments, excessive HTTP/login requests, and automated fingerprinting probes (e.g., favicon or admin panel enumeration). The rule accounts for common uptime monitoring services to minimize false positives.
Detects high-rate scanning and automated service probing patterns consistent with network reconnaissance. This includes tracking TCP SYN floods to external segments, excessive HTTP/login requests, and automated fingerprinting probes (e.g., favicon or admin panel enumeration). The rule accounts for common uptime monitoring services to minimize false positives.
Detects high-rate scanning and automated service probing patterns consistent with network reconnaissance. This includes tracking TCP SYN floods to external segments, excessive HTTP/login requests, and automated fingerprinting probes (e.g., favicon or admin panel enumeration). The rule accounts for common uptime monitoring services to minimize false positives.
Detects outbound FOFA asset-search traffic containing an exact title="Langflow" query directed at the FOFA API host (fofa.info), indicating reconnaissance for Langflow deployments.
This rule detects HTTP requests to 'crt.sh', a Certificate Transparency log search engine. Such requests can indicate an adversary performing reconnaissance to gather information about an organization's digital certificates and domains.
This rule detects HTTP requests made to the Shodan API (api.shodan.io). This activity is often associated with reconnaissance, where an attacker or security researcher uses Shodan to gather information about internet-connected devices and services. The rule specifically looks for the 'api.shodan.io' string within the HTTP host header, indicating an attempt to query the Shodan service.
Detects instances where 'nslookup.exe' is initiated by 'explorer.exe'. This activity can be indicative of an adversary performing DNS queries for reconnaissance or command and control (C2) staging, especially when not part of a legitimate administrative script or user action. The rule excludes a common false positive related to conhost.exe.




