Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

10 detections

Detects potential embedding inversion or extraction attempts by identifying callers exhibiting abnormally high volumes of similarity or vector search queries against RAG-enabled vector stores or cognitive search APIs within a short timeframe.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
8 days ago
000
Detects potential embedding inversion or extraction attempts by identifying callers exhibiting abnormally high volumes of similarity or vector search queries against RAG-enabled vector stores or cognitive search APIs within a short timeframe.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects high-volume DNS queries for subdomains of 'twilio.com' originating from a single source IP within a short 5-minute window, indicative of subdomain enumeration or reconnaissance.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
000
Detects high-rate scanning and automated service probing patterns consistent with network reconnaissance. This includes tracking TCP SYN floods to external segments, excessive HTTP/login requests, and automated fingerprinting probes (e.g., favicon or admin panel enumeration). The rule accounts for common uptime monitoring services to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
24 days ago
001
Detects high-rate scanning and automated service probing patterns consistent with network reconnaissance. This includes tracking TCP SYN floods to external segments, excessive HTTP/login requests, and automated fingerprinting probes (e.g., favicon or admin panel enumeration). The rule accounts for common uptime monitoring services to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
000
Detects high-rate scanning and automated service probing patterns consistent with network reconnaissance. This includes tracking TCP SYN floods to external segments, excessive HTTP/login requests, and automated fingerprinting probes (e.g., favicon or admin panel enumeration). The rule accounts for common uptime monitoring services to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
24 days ago
000
Detects outbound FOFA asset-search traffic containing an exact title="Langflow" query directed at the FOFA API host (fofa.info), indicating reconnaissance for Langflow deployments.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
This rule detects HTTP requests to 'crt.sh', a Certificate Transparency log search engine. Such requests can indicate an adversary performing reconnaissance to gather information about an organization's digital certificates and domains.
avatar
Darshan Thummar@Mighty
avatar
Detections.ai Community
4 months ago
003
This rule detects HTTP requests made to the Shodan API (api.shodan.io). This activity is often associated with reconnaissance, where an attacker or security researcher uses Shodan to gather information about internet-connected devices and services. The rule specifically looks for the 'api.shodan.io' string within the HTTP host header, indicating an attempt to query the Shodan service.
avatar
Darshan Thummar@Mighty
avatar
Detections.ai Community
4 months ago
003
Detects instances where 'nslookup.exe' is initiated by 'explorer.exe'. This activity can be indicative of an adversary performing DNS queries for reconnaissance or command and control (C2) staging, especially when not part of a legitimate administrative script or user action. The rule excludes a common false positive related to conhost.exe.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
90136