Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects unauthorized modifications to AI agent configuration files, including system prompts, tool allow-lists, and MCP server registration files. Such changes are often performed by processes outside of approved configuration management or infrastructure-as-code pipelines, potentially allowing for persistent manipulation of AI model behavior and capabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects command-line execution patterns that exhibit hallmark traits of LLM-generated code, such as overly verbose and explanatory comments, appearing alongside common obfuscation or decoding primitives (e.g., base64, iex, eval). This combination suggests the use of AI to assist in creating decoy logic or burying malicious payloads within legitimate-appearing scripts to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects anomalous, chained execution patterns initiated by AI agents integrated with Model Context Protocol (MCP) servers. The rule identifies a multi-stage sequence involving the invocation of browser automation tools followed by shell execution and subsequent outbound network activity, potentially indicating an AI-driven attack chaining filesystem, shell, or cloud-API access in an unauthorized manner.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
000
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
000
Detects anomalous, chained execution patterns initiated by AI agents integrated with Model Context Protocol (MCP) servers. The rule identifies a multi-stage sequence involving the invocation of browser automation tools followed by shell execution and subsequent outbound network activity, potentially indicating an AI-driven attack chaining filesystem, shell, or cloud-API access in an unauthorized manner.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects anomalous, rapid execution of a high volume of diverse offensive security tools (scanners, exploitation frameworks, and C2 agents) from a single parent process within a short window, which is characteristic of automated LLM-driven orchestration or scripted attack tool chaining.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects outbound HTTPS connections to major generative AI inference endpoints originating from non-browser, non-development tool processes at regular intervals. This activity is indicative of beaconing behavior, where malware (specifically families like LAMEHUG) leverages LLM APIs for dynamic command generation, payload obfuscation, or C2 instruction retrieval, bypassing traditional security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects endpoint behavior consistent with AI-assisted exploit development, characterized by the execution of reverse engineering and vulnerability research tools (e.g., IDA Pro, Ghidra, AFL) interleaved with frequent outbound network connections to LLM APIs, followed by the local compilation of a new executable or DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects coordinated activity patterns across multiple distinct tenant environments within a one-hour window. The rule looks for shared infrastructure (C2 domains), malicious tool hashes, or specific agentic-CLI command line signatures (e.g., related to orchestration, reconnaissance, or exfiltration) that suggest an AI-orchestrated actor or automated attack campaign affecting multiple organizations simultaneously.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects anomalous, high-volume file access by a single process, followed by local file compression or archiving, and subsequent outbound data transfer to a non-internal IP address. This pattern is characteristic of automated agents (like those used in the GTG-1002/Anthropic AI-orchestrated campaigns) performing rapid data triage and staging for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects anomalous activity from IDEs or AI coding assistant extension host processes (e.g., VS Code, Cursor, JetBrains). The rule alerts when these processes spawn children that access sensitive local credential files, perform network connections to non-standard/unexpected domains, or modify critical CI/CD build script configuration files, which is indicative of a supply chain compromise within the developer environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects anomalous child process spawning from common web browsers or productivity applications (e.g., Office, Acrobat) on hosts that have recently communicated with known LLM or code-generation APIs. This behavioral correlation is intended to identify the potential execution of AI-generated exploit code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects potential runtime polymorphic malware that modifies its own executable or script content while simultaneously communicating with generative AI or LLM API endpoints. This behavior indicates an adversary using LLMs to regenerate obfuscated code or mutate malware signatures dynamically at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
101
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
000
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
000
Detects the execution of common remote monitoring and management (RMM) software on a host shortly after the associated user account underwent a password or MFA reset, a pattern indicative of help-desk impersonation (vishing) followed by unauthorized remote access setup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
001
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
000
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
000
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
206
Page 139 of 1870