Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects a sequence of events where a potential multimedia lure (PDF, image, or media file) is created or downloaded via a web browser or communication client, followed by an AI agent (e.g., ChatGPT, Claude) accessing the file, and subsequently initiating a shell execution process (PowerShell, CMD, etc.) involving suspicious command-line patterns or references to the original file. This behavior is indicative of an AI-assisted prompt injection attack where malicious content is processed and executed through agent tooling.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects web servers serving significantly different content sizes to AI crawlers (e.g., ChatGPT-User, ClaudeBot) compared to human web browsers for the same URL, which is a technique used to serve benign content to automated scrapers while delivering malicious or deceptive content to human users.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects web servers serving significantly different content sizes to AI crawlers (e.g., ChatGPT-User, ClaudeBot) compared to human web browsers for the same URL, which is a technique used to serve benign content to automated scrapers while delivering malicious or deceptive content to human users.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects web servers serving significantly different content sizes to AI crawlers (e.g., ChatGPT-User, ClaudeBot) compared to human web browsers for the same URL, which is a technique used to serve benign content to automated scrapers while delivering malicious or deceptive content to human users.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects web servers serving significantly different content sizes to AI crawlers (e.g., ChatGPT-User, ClaudeBot) compared to human web browsers for the same URL, which is a technique used to serve benign content to automated scrapers while delivering malicious or deceptive content to human users.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects anomalous activity where AI assistant processes (e.g., Claude, ChatGPT, GitHub Copilot) execute a high volume of diverse discovery commands. The rule correlates multiple discovery categories, such as account, network service, system information, and network configuration discovery, occurring within a short timeframe to identify potential abuse of AI-integrated development tools for host reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects anomalous, rapid enumeration of system, network, process, and software configuration settings by AI coding assistant processes (e.g., Claude, Cursor, ChatGPT). This behavior often signifies an AI agent being coerced or configured to perform environment discovery or credential gathering, indicating potential compromise or abuse of the LLM-integrated development environment.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
This rule detects potential AI prompt injection attacks delivered via email. It identifies users clicking external links directed at AI platforms (like OpenAI, Claude, or Perplexity) that contain suspicious URL parameters or instructions designed to manipulate or override the AI's standard behavior. It correlates the web request with a subsequent process execution on the host that includes suspicious keywords in the command line, suggesting an attempt to automate or exploit the AI assistant through local system interaction.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000