Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the loading of the malicious NvFsFilter driver (a BYOVD technique often used by the Rapuncel infostealer) followed immediately by a mass burst of process terminations, indicating an attempt to disable security software.
Detects a suspected social engineering attack chain where a user communicates with a recruiter via messaging apps or browsers, subsequently clones or installs a malicious repository using 'npm' or 'VS Code', and triggers suspicious child process activity from 'node.exe'. This pattern is associated with the WaterPlum campaign.
Detects Node.js or Python processes exhibiting behavior characteristic of information-stealing malware (such as the WaterPlum suite: BeaverTail, InvisibleFerret, OtterCookie, StoatWaffle). The rule monitors for these processes accessing sensitive files related to browser credentials, cryptocurrency wallets, scanned identification documents, or performing collection activities like keylogging and screen capturing.
Detects a specific behavioral chain associated with the CHOSEN BRICK implant. This rule identifies when a suspected malicious process writes image/screenshot files (.png, .jpg, .bmp) to disk, followed by a network connection to the Telegram Bot API within a 15-minute window, suggesting potential data exfiltration.
This rule detects artifacts and behaviors associated with the WaterPlum/Contagious Interview (also known as DeceptiveDevelopment) malware suite, including BeaverTail, InvisibleFerret, and related payloads. The rule specifically targets the presence of embedded family-name strings, as well as the execution of suspicious npm package installations triggered by VS Code task automation (tasks.json) or trust prompts, common in fake technical interview attack scenarios.
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
Detects anomalous, chained execution patterns initiated by AI agents integrated with Model Context Protocol (MCP) servers. The rule identifies a multi-stage sequence involving the invocation of browser automation tools followed by shell execution and subsequent outbound network activity, potentially indicating an AI-driven attack chaining filesystem, shell, or cloud-API access in an unauthorized manner.
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
Detects the use of the ntdsutil.exe utility to create an Install From Media (IFM) backup. This technique is often used by adversaries to create a copy of the Active Directory database (NTDS.dit) for offline credential extraction.
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
Page 100 of 1870


