Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
This rule monitors DeviceNetworkEvents for any outbound network connections made to the specific IP address 79.133.56.90. This address is identified as malicious or a known indicator of compromise (IoC) and may indicate command and control (C2) communication or unauthorized data transfer originating from a managed endpoint.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
C2 Ioc Detection
YARA-L
Detects Network, File, or Process events associated with known C2 IOCs
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Page 236 of 1871

