Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous, high-volume enumeration activity (List/Get/Read operations) performed by a single identity across multiple Azure resource providers within a short time window, indicative of automated reconnaissance by a compromised service principal or managed identity.
Detects suspicious process activity or file access patterns originating from within a container that indicate an attempt to escape to the host. This includes monitoring for the use of tools like nsenter, unshare, and mount, attempts to interact with the docker.sock, or attempts to access critical host paths like /proc/1/root or /host/etc, excluding events originating from authorized container management processes.
This rule detects automated browser-based processes (such as chromedriver, msedgedriver, geckodriver, playwright, or node/python scripts leveraging browser automation frameworks) initiating network connections to domains or URLs identified in active threat intelligence as malicious. This behavior is indicative of an AI agent or automated script being steered toward attacker-controlled infrastructure, potentially for drive-by compromise or exploitation.
This rule detects potential prompt injection attacks against AI agents by monitoring tool-invocation parameters. It identifies indicators such as common instruction-overriding phrases, large base64-encoded blobs, or embedded shell metacharacters within parameters when the agent's context is derived from external content (web, email, URLs, etc.).
This rule detects potential prompt injection attacks against AI agents by monitoring tool-invocation parameters. It identifies indicators such as common instruction-overriding phrases, large base64-encoded blobs, or embedded shell metacharacters within parameters when the agent's context is derived from external content (web, email, URLs, etc.).
Detects cloud service principals identified as AI agents or assistants performing sensitive API operations such as IAM policy modifications or storage configuration changes. This pattern may indicate that an AI service account has been compromised or misused to perform reconnaissance, privilege escalation, or persistence, exceeding its intended scope of operation.
Detects successful authentication events by a service principal (e.g., an AI agent or automated application) that have been flagged by Azure AD Identity Protection as having anomalous risk characteristics, such as unfamiliar locations, unexpected travel patterns, or unfamiliar sign-in features.
Detects abnormal bulk API operations (upsert, batch updates, or deletions) targeting vector database or Retrieval-Augmented Generation (RAG) knowledge stores. This activity is flagged when performed by non-authorized service identities or when ingestion volume exceeds a specific threshold within a short timeframe, potentially indicating an attempt to poison the agent's memory store or retrieval corpus to facilitate indirect prompt injection.
Detects DNS query activity from processes commonly used as AI agent runtimes (e.g., python.exe, node.exe) toward domains characterized by DGA-like patterns, such as long alphanumeric strings or high-consonant density, which may indicate command-and-control communication.
Detects an abnormally high frequency of tool/function invocations by an AI agent within a one-minute timeframe. This pattern is indicative of a potential hijack where an attacker forces the agent into a runaway loop to perform resource exhaustion (DoS), repetitive brute-force operations, or automated exfiltration of sensitive data via manipulated tool execution.
Detects anomalous DNS query patterns originating from AI agent hosts that are characteristic of DNS tunneling, such as the use of TXT or NULL records and excessively long subdomain labels. These techniques are often used by attackers to establish covert Command and Control (C2) channels and exfiltrate data by bypassing traditional HTTP/HTTPS egress filtering.
Detects outbound HTTP POST requests from an AI agent runtime environment to known external paste-sites, webhook providers, or staging services. This behavior is indicative of a compromise where the AI agent is being manipulated to exfiltrate sensitive API keys, tokens, or configuration secrets to an attacker-controlled endpoint.
Detects interpreter processes (e.g., python, node, bash) typically used for AI agents accessing sensitive system files or directories outside of defined sandbox or workspace paths. This behavior suggests potential sandbox escape or unauthorized path traversal by an AI agent.
Detects unauthorized attempts to disable, reconfigure, or bypass AI safety guardrails and moderation services, particularly when followed by high-risk tool invocations such as file deletion, network egress, or credential access. This activity indicates an attacker attempting to impair an AI agent's defensive mechanisms to facilitate malicious actions.
Detects successful remote authentication events (Network or Interactive) performed by AI agent orchestration service accounts. This rule monitors for atypical lateral movement patterns where an automated service account pivots to remote hosts using protocols such as RDP or WinRM, diverging from its standard operational context.
Detects a burst of file delete or overwrite operations initiated by a configured AI agent service identity. This behavior, if deviating from established baselines, may indicate a compromised agent performing malicious destructive activities such as mass data deletion or ransomware-style file destruction.
Detects attempts to inject code into an AI agent orchestrator process by monitoring for suspicious CreateRemoteThread events. This rule is designed to identify potential process hijacking attacks by malicious actors seeking to bypass application-layer controls, while excluding common legitimate security monitoring tools that may exhibit similar behavior.
Detects periodic, repetitive outbound HTTPS network connections from AI agent-runtime environments to domains that are not in the predefined allow-list. This behavior is consistent with C2 beaconing disguised as application API traffic, potentially indicating an AI agent has been compromised or misused for unauthorized external command communication.
Detects anomalous AI agent behavior where the agent ingests untrusted external content (e.g., tool outputs, RAG retrievals, or web fetches) and subsequently invokes high-risk or sensitive capabilities (such as shell execution, secret reading, or unauthorized network calls) within the same session. This pattern is indicative of an indirect prompt injection attack attempting to leverage the agent's internal tool-calling mechanisms for unauthorized actions.
Detects anomalous AI agent behavior where the agent ingests untrusted external content (e.g., tool outputs, RAG retrievals, or web fetches) and subsequently invokes high-risk or sensitive capabilities (such as shell execution, secret reading, or unauthorized network calls) within the same session. This pattern is indicative of an indirect prompt injection attack attempting to leverage the agent's internal tool-calling mechanisms for unauthorized actions.
Detects an AI agent or automated process that accesses sensitive data sources (such as vaults, databases, or documentation platforms) followed by an outbound HTTP POST request to known high-risk SaaS or web services (e.g., paste sites, file sharing, or webhook services) with a suspicious or large payload.
