Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
Detects phishing emails that mix writing systems or scripts in the Subject line, combined with phishing vocabulary.
Detects phishing emails that mix writing systems or scripts in the Subject line, combined with phishing vocabulary.
Detects phishing emails that mix writing systems or scripts in the Subject line, combined with phishing vocabulary.
Detects phishing emails that mix writing systems or scripts in the Subject line, combined with phishing vocabulary.
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; the suspicious-URL signal requires a high-confidence credential/urgency term (not generic business vocabulary); sender risk requires the domain to be new to both the recipient and the organization; and at least three independent signal categories (not two) must corroborate the language-confusion signal before the rule fires.
This rule detects potential adversarial reconnaissance activities targeting AI agents via multiple communication channels (e.g., email, collaboration tools). It identifies patterns where a sender transmits messages containing common 'jailbreak' or 'instruction-override' phrases (e.g., 'ignore previous instructions', 'bypass approval') across at least three distinct channels within a 24-hour window, indicating a concerted effort to manipulate or probe agent logic.
This rule detects potential adversarial reconnaissance activities targeting AI agents via multiple communication channels (e.g., email, collaboration tools). It identifies patterns where a sender transmits messages containing common 'jailbreak' or 'instruction-override' phrases (e.g., 'ignore previous instructions', 'bypass approval') across at least three distinct channels within a 24-hour window, indicating a concerted effort to manipulate or probe agent logic.
This rule detects potential adversarial reconnaissance activities targeting AI agents via multiple communication channels (e.g., email, collaboration tools). It identifies patterns where a sender transmits messages containing common 'jailbreak' or 'instruction-override' phrases (e.g., 'ignore previous instructions', 'bypass approval') across at least three distinct channels within a 24-hour window, indicating a concerted effort to manipulate or probe agent logic.
Detects a sequence of potentially malicious activity targeting LLM-related API endpoints. The rule identifies a client IP performing rapid, distinct endpoint discovery, followed by a POST request to sensitive paths, and concluding with a spike in 5xx server-side errors, indicating potential exploitation attempts or fuzzing against Large Language Model interfaces.
Detects a sequence of potentially malicious activity targeting LLM-related API endpoints. The rule identifies a client IP performing rapid, distinct endpoint discovery, followed by a POST request to sensitive paths, and concluding with a spike in 5xx server-side errors, indicating potential exploitation attempts or fuzzing against Large Language Model interfaces.
Detects a sequence of potentially malicious activity targeting LLM-related API endpoints. The rule identifies a client IP performing rapid, distinct endpoint discovery, followed by a POST request to sensitive paths, and concluding with a spike in 5xx server-side errors, indicating potential exploitation attempts or fuzzing against Large Language Model interfaces.
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
