Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,272 detections

This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
23 days ago
2014
Detects the use of reg.exe to query the MachineGuid value from the Windows Registry (HKLM\SOFTWARE\Microsoft\Cryptography). This behavior is often associated with adversary reconnaissance, specifically host fingerprinting, to uniquely identify compromised machines.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects unauthorized or non-standard processes attempting to access sensitive browser cookie storage files, which is a common technique used by credential-stealing malware to exfiltrate session data and bypass multi-factor authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the use of 7-Zip (7z.exe) to extract a file named drata.dat using command line arguments that indicate silent extraction from an encrypted or password-protected archive. This behavior is associated with the LegionLoader malware, which uses this technique to stage its payload.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
This rule detects suspicious PowerShell activity associated with the Lightlife RAT, specifically targeting Google Chrome's login data files to steal credentials and performing checks for the presence of cryptocurrency wallets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
703
Detects potential path traversal or unauthorized access attempts by Semantic Kernel Agents (or related processes like Python/DotNet) to sensitive host files. The rule monitors for file read, creation, or modification activities targeting sensitive credentials, configuration files (e.g., .ssh, .aws, .kube), and system files, which could indicate a sandbox escape or malicious data collection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects exploit attempts targeting a Python prompt-injection vulnerability (CVE-2026-26030). The rule identifies command lines attempting to traverse Python's object hierarchy (e.g., using __class__, __base__, __subclasses__) to import the os module and execute system commands. It also flags subsequent child processes (e.g., calc.exe, cmd.exe) spawned by Python interpreters or Semantic Kernel host processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects the creation of potentially malicious script or executable files (.bat, .ps1, .exe, .vbs) within the Windows Startup folder. It triggers when these files are created by processes typically used for automation or development (dotnet, python) or processes utilizing specific semantic/download-related command lines. The rule further correlates this activity with the presence of PowerShell commands indicative of script downloading or code execution (e.g., IEX, DownloadString) by the same device within the same timeframe, suggesting persistent execution of potentially malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
402
This rule identifies non-browser processes (and those not originating from standard installation directories of common browsers) that exhibit persistent, repeated network connections to the OpenAI API. This pattern is indicative of potential C2 traffic, where adversaries abuse the OpenAI Assistants API as a covert communication channel (e.g., SesameOp).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects outbound HTTP GET requests containing a .ps1 file extension in the URI, originating from a host without a specified User-Agent, and targeting domains other than Microsoft or Windows Update. This pattern is characteristic of a persistence mechanism executing a PowerShell script to download a secondary payload (e.g., via Net.WebClient).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where browser automation tools (e.g., Selenium, Puppeteer, Playwright) or headless browser instances initiate command-line interpreters or scripting hosts. This behavior is indicative of potential automated exploitation, such as browser-based attacks where a malicious script attempts to execute commands directly on the host operating system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects scenarios where a browser or agent process downloads a file and subsequently initiates a local process that references the downloaded file within a very short timeframe (2 minutes). This pattern is indicative of automated or agentic behavior (such as AI-assisted malware execution) where a download is followed by immediate, non-human-mediated execution of the downloaded content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
This rule detects potential AI agent prompt injection by monitoring email subjects or attachment names for keywords often associated with system instruction overrides. It correlates these potentially malicious emails with subsequent execution of common administrative or script-interpreting binaries (e.g., PowerShell, cmd.exe) on the recipient's device within a one-hour window, suggesting a potential successful hijack of an automated process or AI agent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects unauthorized processes (non-browser) reading sensitive browser session and credential files (e.g., Cookies, Login Data) across multiple user profiles, followed by immediate outbound network connections. This behavior is highly characteristic of commodity information stealers (e.g., LummaC2, Stealc, Vidar) attempting to exfiltrate browser-stored credentials and session data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
This rule detects outbound HTTP GET requests initiated by a process using a 'WebClient' user-agent to retrieve a file named 'shell.ps1'. This behavior is characteristic of adversaries downloading second-stage PowerShell payloads to a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects instances where an AI agent (e.g., Semantic Kernel) launches command-line tools commonly used to perform bulk data destruction or system wiping, such as file deletion commands, volume shadow copy removal, or disk formatting. This rule flags suspicious orchestration by AI agents that may be acting outside of expected parameters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects the creation or modification of documents in common formats (e.g., .txt, .md, .docx, .pdf) that contain strings indicative of prompt-injection attempts. These strings are commonly used to manipulate the behavior of AI agents or Large Language Models (LLMs) that may process or index these files automatically.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
102
Detects the installation of a Windows service where the ImagePath points to a gitlab-runner executable but the ServiceName deviates from the default 'gitlab-runner' name. This technique is often used to mask persistence or evade simple naming-based detections by utilizing the --service flag to rename the runner service.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects execution of the BTR_CLI.exe utility with specific command-line arguments. The flags monitored include -a, -chain, -item, -trigger, and -cleanup, which suggest administrative, chaining, or automated triggering behaviors of a custom or proprietary command-line interface tool. This rule tracks the command-line usage to identify potential automated task execution or system configuration changes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the execution of BTR_CLI.exe with cleanup parameters that correlate with the deletion of specific registry keys (services) and related file artifacts (e.g., .dat or changelist files) within a short time window. This pattern is indicative of a post-compromise cleanup routine aimed at removing traces of malicious services or payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Detects the execution of BTR_CLI.exe with command line arguments indicative of installing or interacting with the Mimikatz driver (mimidrv.sys). This behavior is associated with loading the malicious driver to facilitate credential dumping from kernel memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
003
Page 149 of 1871