Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects potential supply chain or local configuration tampering involving the Model Context Protocol (MCP). The rule identifies modification of common MCP configuration files, followed by the execution of a tool runner (node, python, npx) that spawns a scripting shell, which subsequently initiates an unusual outbound network connection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects anomalous AI-assisted activity where multiple processes (specifically AI developer tools) appear to be chaining operations by writing to and reading from shared local directories (e.g., 'handoff', 'artifacts') followed by network requests to known AI service APIs. This pattern may indicate automated task chaining or unauthorized exfiltration of context/code to AI platforms.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
1706
This rule detects network requests directed at raw.githubusercontent.com that attempt to retrieve 'init.dat' or files named with a specific GUID format, patterns which are characteristic of the Kimsuky threat group using GitHub as a dead drop resolver for C2 infrastructure discovery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
115
Detects the execution of PowerShell with hidden window styles and encoded commands, initiated with High Integrity (Admin) privileges. This pattern is often indicative of bypasses for User Account Control (UAC) or malicious script execution where an adversary attempts to run elevated code while minimizing user visibility.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
103
Detects modifications to Group Policy Objects (GPOs) or GPO links in Active Directory, specifically targeting known malicious GPO identifiers, GPO payloads, or changes to policy versioning and linking that indicate unauthorized configuration changes for persistence or privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
405
Detects a cluster of Windows Event IDs 4740 (Account Lockout) or 4724 (Password Reset) targeting the local 'Administrator' account across multiple hosts within a short time window. This activity is indicative of automated or mass account manipulation often associated with ransomware payloads or centralized GPO-based credential tampering.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects the presence of PAYLOAD ransomware ELF binaries specifically configured to target VMware ESXi environments. The detection logic looks for a combination of ELF magic bytes, the 'PAYLOAD' string, references to common virtual machine file extensions (e.g., .vmdk, .vmx), and usage of ESXi-specific administration tools such as esxcli or vim-cmd.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects a suspicious pattern across the environment where a large number of devices apply Group Policy Objects (GPO) shortly after rebooting. This behavior is indicative of potential unauthorized GPO modification used as a persistence or execution mechanism, where malicious logic is staged within a GPO to trigger across the domain upon machine startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects a significant number of endpoints processing Group Policy computer configurations within a short time window. This activity is indicative of a synchronized event, such as a domain-wide application of a newly modified or deployed Group Policy Object (GPO), which may follow a 'time-bomb' malicious GPO detonation or unauthorized policy change.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
005
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a behavioral pattern characteristic of Everest ransomware, where a sequence of rapid process terminations occurs within a 20-second window. The rule identifies the coordinated termination of security/analysis tools, antivirus/backup/database services, and other high-memory processes on a single device, excluding known legitimate maintenance processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000