Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,273 detections

Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
000
Detects instances where AI coding and agent tools (e.g., Claude Code, Cursor, Copilot CLI, Ollama, LangGraph) create archive or database files containing potentially sensitive data and subsequently initiate network connections to non-AI-provider or non-developer services (exfiltration services or non-standard port connections).
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
000
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
101
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
101
Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.
avatar
Arnold Chan@slaz
Defender - KQL
25 days ago
306
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
000
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
000
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
000
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
000
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
000
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
000
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
000
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
000
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
16 days ago
000
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
16 days ago
000
Detects the loading or installation of specific NVIDIA file system filter drivers ('Alinubx.sys', 'CcProtect.sys', 'nvfsflt64.sys') or services related to the 'NvFsFilter'. These drivers are associated with NVIDIA driver components; however, they can be targeted for unauthorized usage or mimicry.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Detects instances where the Visual Studio Debugger (vsdbg.exe) spawns a child process that is not expected, such as common VS diagnostic tools or standard Microsoft/Windows binaries. This is used to identify potential process injection or abuse of the debugger for executing unauthorized payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
21 days ago
002
Page 246 of 1871