Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects evidence of account persistence and potential mailbox manipulation following an anomalous sign-in event in Google Workspace. The rule identifies suspicious post-compromise activity such as the addition of new MFA methods, new OAuth application grants, or mailbox forwarding/inbox rules, which are consistent with the reuse of captured authenticated sessions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004
Detects a potential brute force or password spraying attempt by identifying instances where a single IP address targets 8 or more distinct user accounts with failed authentication attempts (Event ID 4625) within a 30-minute window.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
14 days ago
005
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
103
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
003
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
003
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
004
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
004
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
104
This rule detects multiple suspicious file write operations on a Linux host, specifically targeting directories often used for persistence such as /etc/apt/apt.conf.d, /etc/profile.d, and /etc/cron.d. The rule flags hosts where at least two of these specific persistence techniques are utilized within a 24-hour window, which is indicative of an automated, redundant persistence strategy often employed by cryptocurrency miners like XMRig.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004
Detects suspicious command line activity or network interactions targeting MongoDB, characterized by the use of 'eval' combined with specific function calls (such as 'process', 'load', 'require', or constructor-chaining) indicative of attempts to escape the MongoDB JavaScript sandbox.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
102
This rule detects access to known malicious domains used in vishing-themed Adversary-in-the-Middle (AiTM) phishing campaigns. Attackers use these domains to deceive users into providing MFA credentials or session tokens, often following a voice phishing interaction where victims are directed to these sites to register or set passkeys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
007
This rule detects inbound Microsoft Teams calls originating from external or federated tenants where the caller's display name attempts to mimic internal IT support, help desk, or departmental roles. This behavior is a hallmark of vishing (voice phishing) attacks, often used as a secondary phase in social engineering campaigns following initial contact via email.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
007
This rule detects potentially malicious search activity in Microsoft SharePoint by monitoring for high-frequency queries that include specific site class patterns ('STS_Site' or 'STS_Web') and a document ID range search pattern ('indexdocid'). This behavior is characteristic of an adversary attempting to enumerate or scrape documents within a SharePoint environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
107
Detects exploitation attempts by the CARBONATO botnet targeting exposed Docker daemons. The rule monitors for container escape techniques using 'nsenter' to access host namespaces, the execution of specific malicious entrypoint scripts, the use of known malicious container image references, and the creation of privileged containers with host bind mounts, which are indicative of host filesystem and network compromise.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
11 days ago
102
This rule detects known malicious activity including network connections to a specific C2 IP address (69.48.229.140), downloading files from specific C2 URLs, the presence of known malicious file hashes (SHA256), and communications involving specific actor-associated email addresses.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects a node.exe process initiating a network connection to a specific remote IP (69.48.229.140) on port 8080, followed by the termination of that same process within 45 seconds of the connection. This behavior is indicative of a short-lived beaconing process or an ephemeral network task associated with command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects a suspicious sequence of events where a host performs multiple reconnaissance-style probes (health checks, documentation, or OpenAPI definitions) followed within 10 minutes by access to sensitive artifact-related URLs on the same remote host. This pattern is indicative of an attacker profiling a target server for metadata and then proceeding to exfiltrate files or sensitive artifacts.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a suspicious sequence of events where a host performs multiple reconnaissance-style probes (health checks, documentation, or OpenAPI definitions) followed within 10 minutes by access to sensitive artifact-related URLs on the same remote host. This pattern is indicative of an attacker profiling a target server for metadata and then proceeding to exfiltrate files or sensitive artifacts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects anomalous activity on Dahua camera management interfaces (port 37777) where multiple failed authentication attempts are followed by administrative configuration actions without a corresponding successful credentialed login, suggesting exploitation of authentication-bypass vulnerabilities such as CVE-2021-33044 and CVE-2021-33045.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
004