Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
18 days ago
1706
Page 101 of 1870