Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects anomalous patterns associated with potential WordPress comment moderation bypass. The rule identifies suspicious rapid sequences of comment submissions, use of unapproved comment preview endpoints with moderation hashes, or reuse of approved-commenter cookies. These behaviors can be indicative of an attacker attempting to preview or force-render stored XSS payloads to administrators or visitors before the comment has been officially approved.
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
Detects the creation of specific named mutexes used by the CHOSEN BRICK malware. The malware utilizes these mutexes as an execution guardrail to ensure only one instance of the infection persists on a host. Identification of these mutexes is a high-confidence indicator of CHOSEN BRICK infection activity, often accompanying persistence via Registry Run keys and subsequent communication with Telegram-based command and control servers.
Detects malicious software bundles consistent with the Contagious Interview (G1052) threat group's multi-stage infection chain. The rule identifies the presence of multiple malware family identifiers (such as BeaverTail, InvisibleFerret, and others) within the context of npm or VS Code task configuration files, which are commonly used in job-assessment themed social engineering campaigns.
Detects the modification of AI agent configuration files (e.g., mcp.json, config.json) followed shortly by the agent spawning a child process that matches typical Model Context Protocol (MCP) server execution patterns. This behavior may indicate an attacker has modified the configuration to inject malicious server commands or tools that the AI agent will execute upon next initialization, effectively achieving persistent code execution via the agent's legitimate functionality.
Detects the modification of AI agent configuration files (e.g., mcp.json, config.json) followed shortly by the agent spawning a child process that matches typical Model Context Protocol (MCP) server execution patterns. This behavior may indicate an attacker has modified the configuration to inject malicious server commands or tools that the AI agent will execute upon next initialization, effectively achieving persistent code execution via the agent's legitimate functionality.
Detects the modification of AI agent configuration files (e.g., mcp.json, config.json) followed shortly by the agent spawning a child process that matches typical Model Context Protocol (MCP) server execution patterns. This behavior may indicate an attacker has modified the configuration to inject malicious server commands or tools that the AI agent will execute upon next initialization, effectively achieving persistent code execution via the agent's legitimate functionality.
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
Detects potential exploitation of CVE-2025-3248 in Langflow by identifying suspicious inbound network traffic targeting the /api/v1/validate/code endpoint, correlated with subsequent python child processes containing base64 decoding and execution primitives such as eval, exec, or subprocess.
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
Detects the addition of exclusion paths to Microsoft Defender via PowerShell (Add-MpPreference or Set-MpPreference) initiated by non-Microsoft signed processes or specific messaging applications. This behavior is often indicative of malware attempting to exclude malicious payloads from security scanning.
This rule detects unauthorized processes attempting to access 'Login Data' files associated with Google Chrome or Microsoft Edge web browsers. Legitimate browser processes are excluded, so any external process attempting to read these files is potentially malicious, indicating an attempt to dump stored browser credentials.
Detects executable files launched from torrent-related directories or parent processes that perform reconnaissance commands or registry queries indicative of sandbox or virtualization detection, a technique observed in the MovieReaper malware loader.
This rule detects potential unauthorized access to Azure Key Vault secrets by correlating AI agent process execution on an endpoint with subsequent Key Vault API activity by the same user account. It tracks common AI coding/assistant tools running locally on a device and triggers an alert if the same identity accesses cloud-plane Key Vault operations within 5 minutes. Additionally, it identifies anomalous bulk secret enumeration patterns in Key Vault audit logs to detect potential automated exfiltration.
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects the execution of known malicious MSI files associated with the LegionLoader malware family by monitoring process creation events involving msiexec.exe. The rule matches on specific file hashes and filenames identified in technical analysis of LegionLoader variants.
Page 180 of 1871

