Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects potential Remus infostealer activity by monitoring unauthorized processes accessing AI agent credential directories (Claude, Cursor, OpenCode, Codex) or cryptocurrency wallet files, specifically when combined with .lnk shortcut file access behavior.
Detects suspicious processes accessing cryptocurrency wallet data files or web browser extension storage folders associated with popular crypto wallets. This behavior is indicative of credential theft or wallet data exfiltration by malware targeting digital assets.
Detects a sequence of API calls (NtAllocateVirtualMemory, WriteProcessMemory, and CreateRemoteThread) targeting browser processes (chrome.exe, msedge.exe) from a non-browser process, consistent with shellcode injection patterns used by the Remus infostealer to bypass browser security features.
This rule detects unauthorized access attempts by non-browser processes to specific browser extension storage directories. It focuses on directories associated with password managers, 2FA authenticators, and cryptocurrency wallets, as well as core browser credential files (e.g., Login Data, Cookies, logins.json). This behavior is characteristic of info-stealer malware, such as the Remus infostealer, attempting to exfiltrate sensitive data stored by browsers.
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
This rule monitors DeviceNetworkEvents for any outbound network connections made to the specific IP address 79.133.56.90. This address is identified as malicious or a known indicator of compromise (IoC) and may indicate command and control (C2) communication or unauthorized data transfer originating from a managed endpoint.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Page 237 of 1871

