Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects outbound HTTP GET requests where the user agent is set to 'WebClient' and the URI ends in '.ps1'. This behavior is characteristic of PowerShell download cradles, which are often used by adversaries to fetch and execute remote malicious scripts directly into memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects the creation or modification of script files (bat, ps1, vbs, cmd) within the Windows Startup folder initiated by processes commonly associated with AI agents or developer frameworks (e.g., dotnet, python, w3wp). This activity indicates an AI agent environment being exploited to establish persistence, potentially facilitating delayed remote code execution upon user logon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
202
This rule detects potential remote code execution (RCE) attempts targeting AI agent applications, specifically those utilizing the Semantic Kernel framework. It identifies suspicious command-line patterns indicative of a Python type hierarchy traversal attack (CVE-2026-26030), which is used to bypass security blocklists within an eval() sink to execute arbitrary commands like 'os.system()'. The rule monitors for the spawning of common shell or utility processes by Python or .NET processes associated with AI agent activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects anomalous file access patterns by Semantic Kernel agent processes attempting to read sensitive host files such as SSH keys, configuration files, and credential stores. This activity is indicative of malicious use of agent file-transfer capabilities, potentially exploiting path traversal vulnerabilities or prompt injection to exfiltrate sensitive data from the host environment into the agent sandbox.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects anomalous file access patterns by Semantic Kernel agent processes attempting to read sensitive host files such as SSH keys, configuration files, and credential stores. This activity is indicative of malicious use of agent file-transfer capabilities, potentially exploiting path traversal vulnerabilities or prompt injection to exfiltrate sensitive data from the host environment into the agent sandbox.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects anomalous file access patterns by Semantic Kernel agent processes attempting to read sensitive host files such as SSH keys, configuration files, and credential stores. This activity is indicative of malicious use of agent file-transfer capabilities, potentially exploiting path traversal vulnerabilities or prompt injection to exfiltrate sensitive data from the host environment into the agent sandbox.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
Detects anomalous HTTP POST requests to a suspected C2 endpoint ('/beacon/pre-register') on a typosquatted domain ('thecovnresation') characterized by an application/octet-stream content type, which is indicative of encrypted C2 beacon registration activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
003
Detects potential misuse of AI agentic frameworks (e.g., Semantic Kernel) where the host process executes destructive commands (e.g., file deletion, wiping, shadow copy deletion) or performs large-scale file deletion, which may indicate unauthorized tool invocation or compromised AI agents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
202
Detects anomalous access to SharePoint or OneDrive by identities identified as bots, agents, or service principals. The rule specifically monitors for multiple file accesses where the file names suggest the presence of secrets, passwords, or API keys, which may indicate a compromised or malicious AI agent attempting to harvest credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
102
Detects non-browser and non-approved application processes establishing outbound network connections to known public LLM/AI API endpoints, such as OpenAI or Azure OpenAI services. This behavior is indicative of potential command-and-control (C2) activity where an attacker abuses legitimate AI APIs as a bidirectional communication channel to poll for instructions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
002
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
505
Detects the execution of MicrosoftIME.exe or the creation of scheduled tasks referencing it from non-standard directories such as User, Temp, or AppData folders. This behavior is indicative of masquerading or persistence mechanisms where a malicious process mimics the legitimate Microsoft Input Method Editor (IME) binary.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
003
This rule detects administrative or user activity within Azure via AzureActivity logs and web request patterns in AppServiceHTTPLogs that originate from a predefined list of known malicious IP addresses.
avatar
Ankit Mehta@Secvyn
avatar
01 | 🇨🇭 Swiss Cyber Hunters
7 days ago
000
This rule detects administrative or user activity within Azure via AzureActivity logs and web request patterns in AppServiceHTTPLogs that originate from a predefined list of known malicious IP addresses.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects the presence of known Vidar infostealer samples by matching file hashes against a list of identified malicious artifacts. The rule monitors for file creation events, process execution (both as the primary process and as an initiating process), and network activity originating from these known malicious files.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
14 days ago
104
Detects the BotHelper RAT utilizing its msedge_proxy.exe process to execute 'ClipperStart' or 'ClipperStop' commands. These commands are indicative of the malware's clipboard-address substitution functionality, which is used to redirect cryptocurrency transactions by modifying clipboard content.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects potential command injection attempts or unauthorized access attempts directed at WatchGuard Access Point management interfaces, identified by suspicious strings typically used in exploitation payloads within device logs.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
7 days ago
000
Detects potential command injection attempts or unauthorized access attempts directed at WatchGuard Access Point management interfaces, identified by suspicious strings typically used in exploitation payloads within device logs.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
7 days ago
000
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
14 days ago
004
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
14 days ago
504
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
14 days ago
004