Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects the use of package installation commands (pip, npm, npx) where the package name resembles popular AI/ML libraries (tensorflow, torch, openai, langchain) but is not an exact match for known legitimate versions. This is a common indicator of a typosquatting supply chain attack, where attackers attempt to trick users into installing malicious packages with similar names to trusted software.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
13 days ago
001
Detects the installation of known AI-powered coding assistant extensions (e.g., Copilot, Tabnine, Cursor) on a device, followed by significant source-code repository cloning or archival activity by Git within two hours. This pattern is potentially indicative of intellectual property theft or sensitive source code exfiltration facilitated by a newly introduced AI tool.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
13 days ago
001
Detects command-line execution of scripting tools (e.g., PowerShell, Python, WScript) that simultaneously reference AI service domains (OpenAI, Anthropic), perform network request functions, reference API keys, and utilize encoding or decoding operations. This pattern is indicative of unauthorized use of local scripts to interact with AI APIs, potentially for data exfiltration or automated processing of sensitive information.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
Correlates a sequence of suspicious activities on a single host within 90 minutes: LSASS memory access consistent with credential dumping, followed by remote service or WMI-based lateral movement, and finishing with mass file renames or modifications characteristic of ransomware encryption.
avatar
Myat Min Khant@blitzkri3g
avatar
Detections.ai Community
17 days ago
004
Detects anomalous, mass-access behavior targeting plaintext credential files, certificate stores, private keys, or password-manager databases located on general-purpose network shares. Such activity is often indicative of an adversary conducting discovery or collection of credentials for lateral movement and privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
103
This rule correlates email attachment delivery events with subsequent process creation events on the recipient's endpoint. It identifies scenarios where a known document reader or mail client (Outlook, Word, Excel, PowerPoint, Adobe Acrobat/Reader) spawns a suspicious child process (PowerShell, CMD, WScript, CScript, MSHTA, Rundll32, or Regsvr32) shortly after a file is delivered via email to the same user. This detects the immediate execution phase of a phishing attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
103
Detects PowerShell processes using .NET screen capture libraries (System.Windows.Forms/Drawing) to generate image files in common staging directories like Temp or Public folders, which is a common pattern for malicious screen capture exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects the installation of known AI-powered coding assistant extensions (e.g., Copilot, Tabnine, Cursor) on a device, followed by significant source-code repository cloning or archival activity by Git within two hours. This pattern is potentially indicative of intellectual property theft or sensitive source code exfiltration facilitated by a newly introduced AI tool.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
Detects a multi-stage malware execution pattern consistent with VelvetCake activity. This includes staging text-based files in C:\Users\Public, downloading PowerShell scripts to temporary directories, executing the script via PowerShell, and subsequently deleting both the staged text files (except for specific allowed filenames) and the payload script.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects network connections from server or workload identities (excluding SYSTEM) to known public Generative-AI inference API domains. This may indicate the use of AI services for data exfiltration, automated content generation, or C2 communication via legitimate web services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
302
Detects the execution of Windows Script Host (wscript.exe/cscript.exe) loading WMI-related modules (wbemprox.dll, wbemcomn.dll, etc.). This pattern is often indicative of scripts attempting to query WMI for system information, environment configuration, or locale data, which is a common reconnaissance technique used by malware to identify the victim environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects the use of command-line tools such as rclone, aws CLI, gsutil, and curl to upload files associated with machine learning models (e.g., weights, checkpoints, training datasets) to public cloud storage or AI model hosting platforms. This pattern may indicate the exfiltration of sensitive proprietary AI research or training data.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
101
Detects the use of package installation commands (pip, npm, npx) where the package name resembles popular AI/ML libraries (tensorflow, torch, openai, langchain) but is not an exact match for known legitimate versions. This is a common indicator of a typosquatting supply chain attack, where attackers attempt to trick users into installing malicious packages with similar names to trusted software.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
001
This rule detects a malicious execution sequence often associated with VBScript droppers. It identifies the execution of a process (specifically notepad++.exe) from a dynamically named staging directory under C:\Users\Public\, followed within 10 minutes by the deletion of the associated staging archive (Evernote.zip).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects autonomous AI coding-agent processes (e.g., Claude Code, Cursor, Aider) spawning shell or git processes to perform potentially destructive actions such as recursive file deletion, forced git pushes, database manipulation, or unauthorized access to sensitive credential files, indicating agentic 'excessive agency' or compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
202
Detects video and audio conferencing clients (e.g., Zoom, Microsoft Teams, Webex) loading either unsigned DLLs or DLLs commonly associated with virtual camera and audio injection tools (e.g., OBS VirtualCam, Snap Camera). This behavior is characteristic of deepfake injection techniques used to manipulate video conference participants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
002
Detects web reconnaissance activity characterized by the use of User-Agent strings associated with automated AI agent frameworks and headless browser libraries (e.g., LangChain, AutoGPT, Playwright, Selenium, python-requests). These tools are frequently utilized in autonomous exploitation scenarios to scan multiple URI paths on a web server in a short timeframe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
002
This rule detects interactive or user-triggered execution of PowerShell carrying indicators of payload downloading, inline evaluation, or Base64 encoding. Because explorer.exe is the parent process, it typically signifies a payload delivered via email/web that a user opened directly such as an .lnk shortcut.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detection & Hunting Community
16 days ago
303
This rule detects interactive or user-triggered execution of PowerShell carrying indicators of payload downloading, inline evaluation, or Base64 encoding. Because explorer.exe is the parent process, it typically signifies a payload delivered via email/web that a user opened directly such as an .lnk shortcut.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Detections.ai Community
16 days ago
203
This rule detects network traffic patterns associated with the ARToken PhaaS backend infrastructure. It identifies specific fixed URI paths and cross-affiliate API route contracts used by the backend service, as well as known indicators of compromise for affiliate infrastructure, to monitor for potential credential harvesting or adversary-controlled service interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects instances where a process not associated with standard web browsers accesses, copies, or modifies sensitive browser files such as cookies, local storage, or session tokens. This behavior is highly indicative of information-stealer malware (e.g., Vidar, Lumma, RedLine) attempting to exfiltrate session data for account hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Page 122 of 1870