Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
002
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
17 days ago
002
Detects the creation of specific named mutexes used by the CHOSEN BRICK malware. The malware utilizes these mutexes as an execution guardrail to ensure only one instance of the infection persists on a host. Identification of these mutexes is a high-confidence indicator of CHOSEN BRICK infection activity, often accompanying persistence via Registry Run keys and subsequent communication with Telegram-based command and control servers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects malicious software bundles consistent with the Contagious Interview (G1052) threat group's multi-stage infection chain. The rule identifies the presence of multiple malware family identifiers (such as BeaverTail, InvisibleFerret, and others) within the context of npm or VS Code task configuration files, which are commonly used in job-assessment themed social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Detects the modification of AI agent configuration files (e.g., mcp.json, config.json) followed shortly by the agent spawning a child process that matches typical Model Context Protocol (MCP) server execution patterns. This behavior may indicate an attacker has modified the configuration to inject malicious server commands or tools that the AI agent will execute upon next initialization, effectively achieving persistent code execution via the agent's legitimate functionality.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
001
Detects the modification of AI agent configuration files (e.g., mcp.json, config.json) followed shortly by the agent spawning a child process that matches typical Model Context Protocol (MCP) server execution patterns. This behavior may indicate an attacker has modified the configuration to inject malicious server commands or tools that the AI agent will execute upon next initialization, effectively achieving persistent code execution via the agent's legitimate functionality.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
001
Detects the modification of AI agent configuration files (e.g., mcp.json, config.json) followed shortly by the agent spawning a child process that matches typical Model Context Protocol (MCP) server execution patterns. This behavior may indicate an attacker has modified the configuration to inject malicious server commands or tools that the AI agent will execute upon next initialization, effectively achieving persistent code execution via the agent's legitimate functionality.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
001
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
20 days ago
104
Detects potential exploitation of CVE-2025-3248 in Langflow by identifying suspicious inbound network traffic targeting the /api/v1/validate/code endpoint, correlated with subsequent python child processes containing base64 decoding and execution primitives such as eval, exec, or subprocess.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
24 days ago
1013
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
201
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
001
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
001
Detects the addition of exclusion paths to Microsoft Defender via PowerShell (Add-MpPreference or Set-MpPreference) initiated by non-Microsoft signed processes or specific messaging applications. This behavior is often indicative of malware attempting to exclude malicious payloads from security scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
106
This rule detects unauthorized processes attempting to access 'Login Data' files associated with Google Chrome or Microsoft Edge web browsers. Legitimate browser processes are excluded, so any external process attempting to read these files is potentially malicious, indicating an attempt to dump stored browser credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
006
Detects executable files launched from torrent-related directories or parent processes that perform reconnaissance commands or registry queries indicative of sandbox or virtualization detection, a technique observed in the MovieReaper malware loader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
006
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
101
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
101
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
101
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
101
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
301
Detects the execution of known malicious MSI files associated with the LegionLoader malware family by monitoring process creation events involving msiexec.exe. The rule matches on specific file hashes and filenames identified in technical analysis of LegionLoader variants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
17 days ago
002
Page 180 of 1871