Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
Detects web servers serving significantly different content sizes to AI crawlers (e.g., ChatGPT-User, ClaudeBot) compared to human web browsers for the same URL, which is a technique used to serve benign content to automated scrapers while delivering malicious or deceptive content to human users.
Detects web servers serving significantly different content sizes to AI crawlers (e.g., ChatGPT-User, ClaudeBot) compared to human web browsers for the same URL, which is a technique used to serve benign content to automated scrapers while delivering malicious or deceptive content to human users.
Detects web servers serving significantly different content sizes to AI crawlers (e.g., ChatGPT-User, ClaudeBot) compared to human web browsers for the same URL, which is a technique used to serve benign content to automated scrapers while delivering malicious or deceptive content to human users.
Detects web servers serving significantly different content sizes to AI crawlers (e.g., ChatGPT-User, ClaudeBot) compared to human web browsers for the same URL, which is a technique used to serve benign content to automated scrapers while delivering malicious or deceptive content to human users.
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
