Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potential remote code execution (RCE) attempts targeting AI agent applications, specifically those utilizing the Semantic Kernel framework. It identifies suspicious command-line patterns indicative of a Python type hierarchy traversal attack (CVE-2026-26030), which is used to bypass security blocklists within an eval() sink to execute arbitrary commands like 'os.system()'. The rule monitors for the spawning of common shell or utility processes by Python or .NET processes associated with AI agent activity.
Detects anomalous file access patterns by Semantic Kernel agent processes attempting to read sensitive host files such as SSH keys, configuration files, and credential stores. This activity is indicative of malicious use of agent file-transfer capabilities, potentially exploiting path traversal vulnerabilities or prompt injection to exfiltrate sensitive data from the host environment into the agent sandbox.
Detects anomalous file access patterns by Semantic Kernel agent processes attempting to read sensitive host files such as SSH keys, configuration files, and credential stores. This activity is indicative of malicious use of agent file-transfer capabilities, potentially exploiting path traversal vulnerabilities or prompt injection to exfiltrate sensitive data from the host environment into the agent sandbox.
Detects an accelerated sequence of attack phases—specifically recon, privilege escalation, lateral movement, and persistence—occurring on a single device within a short timeframe (15 minutes). This behavioral pattern indicates potential automated or script-orchestrated intrusion activity.
Detects a potential post-exploitation attack chain where a user receives a phishing lure and subsequently executes a rapid burst of distinct process commands on the same host. This pattern is consistent with an adversary utilizing an LLM to iteratively troubleshoot and refine command syntax during a post-exploitation phase.
Detects anomalous file access patterns by Semantic Kernel agent processes attempting to read sensitive host files such as SSH keys, configuration files, and credential stores. This activity is indicative of malicious use of agent file-transfer capabilities, potentially exploiting path traversal vulnerabilities or prompt injection to exfiltrate sensitive data from the host environment into the agent sandbox.
Detects a potential post-exploitation attack chain where a user receives a phishing lure and subsequently executes a rapid burst of distinct process commands on the same host. This pattern is consistent with an adversary utilizing an LLM to iteratively troubleshoot and refine command syntax during a post-exploitation phase.
Detects a potential post-exploitation attack chain where a user receives a phishing lure and subsequently executes a rapid burst of distinct process commands on the same host. This pattern is consistent with an adversary utilizing an LLM to iteratively troubleshoot and refine command syntax during a post-exploitation phase.
This rule detects unauthorized processes attempting to read sensitive configuration files (secrets.json, config.yaml) associated with AI coding assistants like Cline and Continue. By filtering out known, legitimate IDE and development processes, the rule highlights potential file-grabber activity indicative of an infostealer attempting to exfiltrate plaintext LLM API keys.
Detects instances where a browser or agentic-browser process initiates a file download and subsequently executes that same file within a five-minute window, without the intervention of a user-driven process like explorer.exe. This pattern is indicative of automated 'agentic' browser activity, potentially signifying hijacked web instructions or malicious automated tool execution flows.
Detects potential Command and Control (C2) activity leveraging the OpenAI Assistants API. The rule identifies non-standard processes (e.g., PowerShell, Python, cmd) that establish network connections to OpenAI API endpoints, specifically those often used for interaction with AI models, suggesting potential abuse of AI services for command issuance or data exfiltration.
This rule detects potential backdoor deployment or persistence mechanisms in AI coding assistants like Claude Code and Cursor. It identifies when specific configuration or hook files (e.g., settings.json, hooks.js) are modified, followed within a two-hour window by the execution of suspicious child processes (e.g., powershell.exe, curl.exe, python) initiated by the coding assistant's CLI tool.
Detects potential misuse of AI agentic frameworks (e.g., Semantic Kernel) where the host process executes destructive commands (e.g., file deletion, wiping, shadow copy deletion) or performs large-scale file deletion, which may indicate unauthorized tool invocation or compromised AI agents.
Detects instances where package management tools (pip, npm, docker) spawn child processes that immediately attempt to read sensitive files (SSH keys, cloud/container credentials) or perform outbound network connections. This behavior is indicative of a trojanized supply-chain package executing malicious post-install logic to exfiltrate secrets or establish initial communication with a C2 server.
Detects common runtime processes (Node.js, npx, Python) often used for Model Context Protocol (MCP) servers accessing sensitive local credential files such as AWS credentials, SSH private keys, or environment files. This behavior is indicative of potential credential harvesting by unauthorized MCP servers in developer environments.
Detects non-browser and non-approved application processes establishing outbound network connections to known public LLM/AI API endpoints, such as OpenAI or Azure OpenAI services. This behavior is indicative of potential command-and-control (C2) activity where an attacker abuses legitimate AI APIs as a bidirectional communication channel to poll for instructions.
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
Detects the presence of known Vidar infostealer samples by matching file hashes against a list of identified malicious artifacts. The rule monitors for file creation events, process execution (both as the primary process and as an initiating process), and network activity originating from these known malicious files.
Detects the BotHelper RAT utilizing its msedge_proxy.exe process to execute 'ClipperStart' or 'ClipperStop' commands. These commands are indicative of the malware's clipboard-address substitution functionality, which is used to redirect cryptocurrency transactions by modifying clipboard content.
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
Page 117 of 1870


