Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects anomalous, chained execution patterns initiated by AI agents integrated with Model Context Protocol (MCP) servers. The rule identifies a multi-stage sequence involving the invocation of browser automation tools followed by shell execution and subsequent outbound network activity, potentially indicating an AI-driven attack chaining filesystem, shell, or cloud-API access in an unauthorized manner.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
This rule identifies potential infections associated with the MacSync malware family by matching process, file, and network indicators (hashes, malicious domains, and specific payload URLs) against endpoint telemetry. It monitors for execution of known malicious binaries, file creation events, and communication with identified command-and-control infrastructure.
avatar
Arnold Chan@slaz
avatar
Hunters
11 days ago
002
This rule identifies potential infections associated with the MacSync malware family by matching process, file, and network indicators (hashes, malicious domains, and specific payload URLs) against endpoint telemetry. It monitors for execution of known malicious binaries, file creation events, and communication with identified command-and-control infrastructure.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
11 days ago
002
This rule detects activities associated with the MacSync backdoor, specifically focusing on persistence mechanisms such as LaunchAgent manipulation, .repair-run scripts, and suspicious GIT hook usage. It also correlates these events with the termination of macOS notification agents (BTMNotificationAgent, NotificationCenter, BackgroundTaskManagementAgent), which is a tactic used to suppress security alerts during malicious operations.
avatar
Arnold Chan@slaz
Defender - KQL
11 days ago
202
Detects post-exploitation activity against Citrix NetScaler appliances associated with CVE-2026-8452. The rule specifically monitors for HTTP GET requests targeting PHP files within the /var/vpn/theme/ directory, accompanied by efforts to execute shell commands (bin/sh) via the web server.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
002
Detects AI agent tooling (e.g., LangChain, Copilot, Claude Code) performing read operations on databases containing sensitive data patterns, or performing suspicious bulk data enumeration. The rule monitors Azure SQL Database security audit events for suspicious application name signatures and non-schema introspective queries.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
103
Detects phishing messages that deliberately mix writing systems/scripts or use homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. This is the only translation that implements true sender-novelty checking via baseline lookups (a sending domain must be new to both the specific recipient and the organization as a whole to add risk). A weighted score (script-mixing=2, homoglyph=3, phishing vocabulary=2, sender-novelty=1, threshold=6) requires multiple corroborating signals before firing. Note: unlike the SPL/S1QL/CQL/CortexQL translations, this version does not strip brand/product tokens before the script check.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts or use homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. This is the only translation that implements true sender-novelty checking via baseline lookups (a sending domain must be new to both the specific recipient and the organization as a whole to add risk). A weighted score (script-mixing=2, homoglyph=3, phishing vocabulary=2, sender-novelty=1, threshold=6) requires multiple corroborating signals before firing. Note: unlike the SPL/S1QL/CQL/CortexQL translations, this version does not strip brand/product tokens before the script check.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts or use homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. This is the only translation that implements true sender-novelty checking via baseline lookups (a sending domain must be new to both the specific recipient and the organization as a whole to add risk). A weighted score (script-mixing=2, homoglyph=3, phishing vocabulary=2, sender-novelty=1, threshold=6) requires multiple corroborating signals before firing. Note: unlike the SPL/S1QL/CQL/CortexQL translations, this version does not strip brand/product tokens before the script check.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
102
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects phishing messages that mix writing systems/scripts/homoglyphs in the Subject line as one corroborating signal within a broader, multi-signal phishing pattern.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects phishing messages that mix writing systems/scripts/homoglyphs in the Subject line as one corroborating signal within a broader, multi-signal phishing pattern.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000