Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects potentially malicious activity related to AI agent tool manipulation. It flags two primary scenarios: 1) The invocation of an AI tool shortly after an unmanaged or potentially unauthorized modification to its definition, and 2) Detection of prompt injection patterns within the output generated by an AI agent tool, which could indicate an attacker attempting to override the agent's instructions.
This rule detects potentially malicious activity related to AI agent tool manipulation. It flags two primary scenarios: 1) The invocation of an AI tool shortly after an unmanaged or potentially unauthorized modification to its definition, and 2) Detection of prompt injection patterns within the output generated by an AI agent tool, which could indicate an attacker attempting to override the agent's instructions.
This rule detects anomalous behavior in AI agent tool invocations, specifically monitoring for high volumes of tool calls, high costs associated with token consumption, or suspicious tool interactions following a flagged indirect prompt injection. This behavior is indicative of potential resource exhaustion (denial of service) or abusive agent behavior as defined by the MITRE ATLAS framework for AI security.
Detects potential sensitive data leakage from an AI model response (AIGatewayLogs_CL). The rule monitors AI responses for patterns indicative of PII (SSN, credit card numbers), secrets (API keys, tokens), or sensitive document markers. It correlates these signals with RAG (Retrieval-Augmented Generation) ingestion logs to identify data cross-tenant violations or improper access to confidential/restricted datasets.
This rule detects anomalous behavior in AI agent tool invocations, specifically monitoring for high volumes of tool calls, high costs associated with token consumption, or suspicious tool interactions following a flagged indirect prompt injection. This behavior is indicative of potential resource exhaustion (denial of service) or abusive agent behavior as defined by the MITRE ATLAS framework for AI security.
Detects potential sensitive data leakage from an AI model response (AIGatewayLogs_CL). The rule monitors AI responses for patterns indicative of PII (SSN, credit card numbers), secrets (API keys, tokens), or sensitive document markers. It correlates these signals with RAG (Retrieval-Augmented Generation) ingestion logs to identify data cross-tenant violations or improper access to confidential/restricted datasets.
This rule detects potential Denial of Service (DoS) attacks against AI inference endpoints. It monitors for sustained high latency and high error rates combined with a high volume of 'heavy' requests (those exceeding a token/character count threshold) from specific source IPs. This pattern suggests an attempt to exhaust system resources by forcing the processing of complex or overly large prompts.
Detects autonomous AI agents triggered by routine, non-interactive workflows (such as scheduled tasks, tickets, or calendar invites) that subsequently invoke sensitive tools. The rule correlates these invocations with content hashes previously flagged as containing malicious indirect prompt injections, indicating an attack where a payload remains dormant until processed by an automated agent.
This rule monitors package installation logs for indicators of packages potentially generated or suggested by AI tools (e.g., Copilot, code assistants) being installed in a target environment. It specifically looks for a low volume of installations (<=3) for packages that have been published within the last 14 days, which is a pattern often associated with the 'Publish Hallucinated Entities' technique in AI systems, where malicious or hallucinated code packages are introduced into the supply chain.
Detects potential sensitive data leakage from an AI model response (AIGatewayLogs_CL). The rule monitors AI responses for patterns indicative of PII (SSN, credit card numbers), secrets (API keys, tokens), or sensitive document markers. It correlates these signals with RAG (Retrieval-Augmented Generation) ingestion logs to identify data cross-tenant violations or improper access to confidential/restricted datasets.
Detects autonomous AI agents triggered by routine, non-interactive workflows (such as scheduled tasks, tickets, or calendar invites) that subsequently invoke sensitive tools. The rule correlates these invocations with content hashes previously flagged as containing malicious indirect prompt injections, indicating an attack where a payload remains dormant until processed by an automated agent.
This rule monitors package installation logs for indicators of packages potentially generated or suggested by AI tools (e.g., Copilot, code assistants) being installed in a target environment. It specifically looks for a low volume of installations (<=3) for packages that have been published within the last 14 days, which is a pattern often associated with the 'Publish Hallucinated Entities' technique in AI systems, where malicious or hallucinated code packages are introduced into the supply chain.
Detects suspicious modifications or registrations of AI agent tools within the registry. The rule identifies three core indicators of compromise: usage of an unverified or external registry source, unauthorized tool definition modifications (hash mismatch against baseline), and a suspicious 'update chain' where a non-standard maintainer pushes a tool update that simultaneously increases requested operational scopes.
This rule detects the execution of common Windows administration utilities (vssadmin.exe, wmic.exe, wbadmin.exe, bcdedit.exe) being used to delete Volume Shadow Copies, backup catalogs, or modify boot configuration data to disable automatic recovery. These actions are frequently performed by ransomware to prevent data restoration.
Detects instances where Microsoft Office applications or Windows Explorer (via LNK file execution) spawn suspicious child processes, such as script interpreters or known LOLBins, within a short timeframe. This is a common pattern for initial access via spearphishing attachments where a malicious document or shortcut executes a payload.
Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
Detects the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, bash, wget) spawned by processes associated with public-facing appliances like Fortinet SSL-VPN, Veeam Backup & Replication, Citrix ADC, and cPanel/WHM. This behavior is often indicative of exploitation of public-facing applications (T1190) for initial access, frequently associated with ransomware actors targeting unpatched infrastructure.
This rule detects successful authentication events for remote access applications (VPN, RDP, Azure AD App Proxy) where the source IP address or ASN has not been observed in the user's login history within the preceding 14 days. This behavior is indicative of potential account takeover using compromised credentials sourced from infostealers or other credential-harvesting activities.
This rule detects various process injection techniques (such as CreateRemoteThread, QueueUserAPC, and remote memory writes) initiated by external processes targeting high-value, commonly abused Windows system processes like svchost.exe, lsass.exe, and explorer.exe. These techniques are often used by ransomware and other malware to hide malicious code execution within trusted system memory space.
Detects high-volume file rename and modification operations occurring across multiple directories, combined with the creation of files indicative of ransom notes (e.g., readme, decrypt, how-to-restore). This pattern is strongly associated with the encryption phase of a ransomware attack.
