Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
100
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
16 days ago
000
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
16 days ago
000
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
16 days ago
000
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
000
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
000
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
000
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
000
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
This rule monitors DeviceNetworkEvents for any outbound network connections made to the specific IP address 79.133.56.90. This address is identified as malicious or a known indicator of compromise (IoC) and may indicate command and control (C2) communication or unauthorized data transfer originating from a managed endpoint.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
1 month ago
5033
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects Network, File, or Process events associated with known C2 IOCs
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
101
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
101
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Page 236 of 1871