Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
101
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
101
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
001
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
001
Detects successful logons (Event ID 4624) that use NTLM authentication or a LogonType of 9 (NewCredentials), where the LogonProcessName involves 'seclogo'. This pattern is often associated with the use of the secondary logon service, which can be abused by tools to execute processes under different user contexts or to perform credential-based attacks.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
17 days ago
002
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
101
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
001
This rule detects when the Windows Security or System event logs have been cleared, which is a common technique used by adversaries to hide evidence of their activities and impede forensic investigations.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
17 days ago
002
Detects high-frequency assignment or invocation of special privileges on a Windows host within a one-hour window. This behavior often indicates an actor performing rapid enumeration or privilege escalation activities. The rule filters out service accounts (those ending with '$') to focus on user-based activity.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
17 days ago
202
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
101
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
001
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
001
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
15 days ago
101
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
101
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
001
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
avatar
Arnold Chan@slaz
Defender - KQL
15 days ago
101
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
101
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
001
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
101
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
002
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
002
Page 177 of 1871