Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
Page 101 of 1870

