Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; a weighted score (script-mixing=2, homoglyph=3, high-confidence phishing vocabulary=2, threshold=6) means no two of the three signal categories can reach the threshold alone — all three must co-occur before the rule fires.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects phishing emails that mix writing systems or scripts in the Subject line, combined with phishing vocabulary.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects phishing emails that mix writing systems or scripts in the Subject line, combined with phishing vocabulary.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects phishing emails that mix writing systems or scripts in the Subject line, combined with phishing vocabulary.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects phishing emails that mix writing systems or scripts in the Subject line, combined with phishing vocabulary.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
103
Detects phishing messages that deliberately mix writing systems/scripts/homoglyphs in the Subject line as ONE corroborating signal within a broader, multi-signal phishing pattern. Hardened against false positives: brand/product tokens (e.g. Microsoft, PayPal) are stripped before the Latin-script check so a lone brand mention in non-Latin correspondence doesn't count as mixed-script; the suspicious-URL signal requires a high-confidence credential/urgency term (not generic business vocabulary); sender risk requires the domain to be new to both the recipient and the organization; and at least three independent signal categories (not two) must corroborate the language-confusion signal before the rule fires.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
This rule detects potential adversarial reconnaissance activities targeting AI agents via multiple communication channels (e.g., email, collaboration tools). It identifies patterns where a sender transmits messages containing common 'jailbreak' or 'instruction-override' phrases (e.g., 'ignore previous instructions', 'bypass approval') across at least three distinct channels within a 24-hour window, indicating a concerted effort to manipulate or probe agent logic.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects potential adversarial reconnaissance activities targeting AI agents via multiple communication channels (e.g., email, collaboration tools). It identifies patterns where a sender transmits messages containing common 'jailbreak' or 'instruction-override' phrases (e.g., 'ignore previous instructions', 'bypass approval') across at least three distinct channels within a 24-hour window, indicating a concerted effort to manipulate or probe agent logic.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects potential adversarial reconnaissance activities targeting AI agents via multiple communication channels (e.g., email, collaboration tools). It identifies patterns where a sender transmits messages containing common 'jailbreak' or 'instruction-override' phrases (e.g., 'ignore previous instructions', 'bypass approval') across at least three distinct channels within a 24-hour window, indicating a concerted effort to manipulate or probe agent logic.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects a sequence of potentially malicious activity targeting LLM-related API endpoints. The rule identifies a client IP performing rapid, distinct endpoint discovery, followed by a POST request to sensitive paths, and concluding with a spike in 5xx server-side errors, indicating potential exploitation attempts or fuzzing against Large Language Model interfaces.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a sequence of potentially malicious activity targeting LLM-related API endpoints. The rule identifies a client IP performing rapid, distinct endpoint discovery, followed by a POST request to sensitive paths, and concluding with a spike in 5xx server-side errors, indicating potential exploitation attempts or fuzzing against Large Language Model interfaces.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a sequence of potentially malicious activity targeting LLM-related API endpoints. The rule identifies a client IP performing rapid, distinct endpoint discovery, followed by a POST request to sensitive paths, and concluding with a spike in 5xx server-side errors, indicating potential exploitation attempts or fuzzing against Large Language Model interfaces.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000