Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects anomalous, high-volume, low-severity events flagged for human review originating from a single AI agent or source within a 10-minute window. This behavior is indicative of an adversary flooding the human-in-the-loop (HITL) review queue with chaff data (noise) to exhaust analyst capacity or conceal malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001
Detects Large Language Model (LLM) responses that contain instructions designed to propagate the current prompt to other users, systems, or agents. This pattern is indicative of a self-replicating prompt worm, which aims to spread malicious instructions across an AI ecosystem by leveraging the model's ability to generate text that instructs subsequent interactions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
10 days ago
001