Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects potential Adversary-in-the-Middle (AiTM) activity by identifying a successful interactive MFA-protected sign-in followed within 15 minutes by a non-interactive (refresh token) sign-in for the same user from a different IP address, ASN, or User-Agent. This pattern is indicative of session hijacking where an attacker reuses a stolen session token.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
003
Detects MFA relay phishing kits (such as Bluekit) where the MFA challenge is satisfied by an attacker-controlled proxy rather than the legitimate user device. The rule identifies sign-in attempts where the primary authentication request originates from one network location, while the MFA completion step originates from a different network location, and the MFA claim indicates it was satisfied via a proxied token.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
003
Detects instances where a non-browser process initiates network connections to multiple AI service providers and Discord within a 15-minute correlation window, potentially indicating automated data exfiltration or unauthorized interaction with AI platforms using tools other than standard web browsers.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
11 days ago
003
Detects instances where a non-browser process initiates network connections to multiple AI service providers and Discord within a 15-minute correlation window, potentially indicating automated data exfiltration or unauthorized interaction with AI platforms using tools other than standard web browsers.
avatar
Goksel Atakan@gokselatakan
Defender - KQL
11 days ago
403
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
9023
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
14 days ago
506
Detects high-volume outbound data transfers (exceeding 100MB) directed towards common cloud storage providers, file sharing services, and AI model endpoints. This behavior is indicative of potential data exfiltration by an adversary using legitimate web services to bypass traditional network security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects DNS queries containing long, high-entropy subdomain labels, which are characteristic of DNS tunneling techniques. Adversaries use DNS tunneling to bypass network controls by embedding C2 communications within DNS protocol fields. This rule identifies suspicious query structures, specifically targeting extended length and high character diversity in subdomains while filtering out common CDN domains that exhibit similar structural behaviors.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
This rule detects potential DNS tunneling activities used for data exfiltration. It identifies suspicious patterns by monitoring for a sustained, high volume (over 200) of DNS queries containing long, high-entropy encoded strings within the subdomain segment from a single client IP address. Legitimate traffic such as reverse DNS lookups is excluded to minimize noise.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized processes attempting to access the cloud instance metadata service (169.254.169.254). Adversaries frequently target this endpoint to extract sensitive instance information, such as IAM credentials or configuration data, typically as part of post-exploitation discovery or SSRF-based attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects anomalous process execution originating from a Python-based sandbox (such as Semantic Kernel SessionsPythonPlugin in Azure Container Apps) that attempts to break out of the container isolation. The rule monitors for command-line arguments involving interaction with the Docker socket, sensitive host namespaces, or container privilege escalation techniques, indicative of exploitation attempts related to CVE-2026-25592.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
103
Detects instances where AI agent host processes (such as Python, .NET, or IIS worker processes) spawn suspicious child processes like command interpreters or common system utilities. This behavior is indicative of potential Remote Code Execution (RCE) via prompt injection, where an AI agent is manipulated into executing arbitrary system commands.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
003
Detects the suspicious retrieval and immediate execution of Agentic AI configuration files (e.g., AGENTS.md, KNOWLEDGE.md) from remote sources using common command-line utilities. This pattern is indicative of an adversary injecting malicious agent instructions or unauthorized configurations into an AI environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
603
Detects DNS queries to major public LLM API endpoints (OpenAI, Anthropic, Google Generative Language). This may indicate potential use of these services as a command and control (C2) channel or for data exfiltration by insiders or compromised systems, which may bypass traditional security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects a high volume of HTTP POST requests to common login endpoints (e.g., /login or /wp-login.php) from a single source IP address within a short time frame, which is indicative of a credential stuffing or automated brute-force attack.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
This rule identifies MikroTik devices running vulnerable versions of RouterOS (specifically those older than 7.24) that are susceptible to CVE-2026-84411. This vulnerability involves an integer underflow in the web management HTTP handling, which can lead to unauthenticated remote code execution or denial of service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
5 days ago
000
Detects incoming web requests containing a 'pagename' parameter with URL-encoded path traversal sequences, which could allow unauthorized file access or directory traversal attacks against WordPress page-template resolution as described in CVE-2026-87902.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
003
This rule detects unauthorized attempts to dump the memory of the Local Security Authority Subsystem Service (LSASS) process. It monitors for common post-exploitation tools (such as procdump, mimikatz, nanodump, and sqldumper) or built-in Windows techniques (using rundll32.exe with comsvcs.dll) that are typically used to extract sensitive credential material from process memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the WMI provider host (wmiprvse.exe) spawning common living-off-the-land binaries often associated with command execution or lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous patterns of Kerberos Ticket Granting Service (TGS) requests using RC4 encryption (0x17), which is a common indicator of Kerberoasting attacks. The rule identifies accounts requesting a high volume of service tickets for distinct Service Principal Names (SPNs), excluding the krbtgt account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of scheduled tasks using the 'schtasks.exe' utility where the command line contains suspicious patterns such as execution of common scripting engines (PowerShell, wscript, cscript), use of common staging directories (temp, appdata, programdata), or naming conventions that mimic legitimate Windows system tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000