Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
002
Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
102
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
102
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
002
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
102
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
202
This rule detects potentially malicious Command and Control (C2) traffic utilizing DNS over HTTPS (DoH) to interact with public resolvers like Cloudflare, Google, and Quad9. It identifies both high-frequency, repeated direct-to-resolver TLS sessions and specific HTTP requests to these resolvers that resolve domains associated with known C2 infrastructure, such as the ClickFix campaign.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
This rule detects potentially malicious Command and Control (C2) traffic utilizing DNS over HTTPS (DoH) to interact with public resolvers like Cloudflare, Google, and Quad9. It identifies both high-frequency, repeated direct-to-resolver TLS sessions and specific HTTP requests to these resolvers that resolve domains associated with known C2 infrastructure, such as the ClickFix campaign.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
This rule detects potentially malicious Command and Control (C2) traffic utilizing DNS over HTTPS (DoH) to interact with public resolvers like Cloudflare, Google, and Quad9. It identifies both high-frequency, repeated direct-to-resolver TLS sessions and specific HTTP requests to these resolvers that resolve domains associated with known C2 infrastructure, such as the ClickFix campaign.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects a suspicious sequence where a process loads the .NET CLR (clr.dll or mscoree.dll) and shortly thereafter accesses specific low-prevalence file extensions (.raw or .pak) within high-risk directories (AppData/Local/Temp, ProgramData, or Users/Public). This behavior is characteristic of shellcode loaders (such as the WAV-shellcode loader) that decrypt and execute RAT payloads from obfuscated containers in memory. The rule intentionally excludes common desktop applications to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Detects a suspicious sequence where a process loads the .NET CLR (clr.dll or mscoree.dll) and shortly thereafter accesses specific low-prevalence file extensions (.raw or .pak) within high-risk directories (AppData/Local/Temp, ProgramData, or Users/Public). This behavior is characteristic of shellcode loaders (such as the WAV-shellcode loader) that decrypt and execute RAT payloads from obfuscated containers in memory. The rule intentionally excludes common desktop applications to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects a suspicious sequence where a process loads the .NET CLR (clr.dll or mscoree.dll) and shortly thereafter accesses specific low-prevalence file extensions (.raw or .pak) within high-risk directories (AppData/Local/Temp, ProgramData, or Users/Public). This behavior is characteristic of shellcode loaders (such as the WAV-shellcode loader) that decrypt and execute RAT payloads from obfuscated containers in memory. The rule intentionally excludes common desktop applications to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects a suspicious sequence where a process loads the .NET CLR (clr.dll or mscoree.dll) and shortly thereafter accesses specific low-prevalence file extensions (.raw or .pak) within high-risk directories (AppData/Local/Temp, ProgramData, or Users/Public). This behavior is characteristic of shellcode loaders (such as the WAV-shellcode loader) that decrypt and execute RAT payloads from obfuscated containers in memory. The rule intentionally excludes common desktop applications to minimize false positives.
avatar
Arnold Chan@slaz
Defender - KQL
7 days ago
000
Detects a .NET-hosting PE module (e.g. I++u.dll) that references both the NuGet-package-concealed Build.dat loader stage and the subsequent execute_engine_disconnect.raw decrypted container, matching the V2 ClickFix loader chain
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects a .NET-hosting PE module (e.g. I++u.dll) that references both the NuGet-package-concealed Build.dat loader stage and the subsequent execute_engine_disconnect.raw decrypted container, matching the V2 ClickFix loader chain
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
Detects a .NET-hosting PE module (e.g. I++u.dll) that references both the NuGet-package-concealed Build.dat loader stage and the subsequent execute_engine_disconnect.raw decrypted container, matching the V2 ClickFix loader chain
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
Detects a .NET-hosting PE module (e.g. I++u.dll) that references both the NuGet-package-concealed Build.dat loader stage and the subsequent execute_engine_disconnect.raw decrypted container, matching the V2 ClickFix loader chain
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
7 days ago
000
Detects the execution of PowerShell with a bypass execution policy that performs a download or web request to save content to a file in the user's temp directory, followed by the immediate execution of that file. This pattern is characteristic of multi-stage malware droppers or fileless attack techniques attempting to stage and execute malicious scripts from temporary locations.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
7 days ago
000
Detects the execution of PowerShell with a bypass execution policy that performs a download or web request to save content to a file in the user's temp directory, followed by the immediate execution of that file. This pattern is characteristic of multi-stage malware droppers or fileless attack techniques attempting to stage and execute malicious scripts from temporary locations.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000
This rule detects suspicious persistence activity involving known tools or names that are often masqueraded. It looks for the creation of registry run keys or scheduled tasks using names associated with common tools ('Canon Configuration Reader', 'Stardock DeElevation Tool') when the initiating process is not located in the expected vendor-authorized directories. The rule specifically alerts on devices exhibiting these behaviors within a short time window.
avatar
Arnold Chan@slaz
avatar
Hunters
7 days ago
000
This rule detects suspicious persistence activity involving known tools or names that are often masqueraded. It looks for the creation of registry run keys or scheduled tasks using names associated with common tools ('Canon Configuration Reader', 'Stardock DeElevation Tool') when the initiating process is not located in the expected vendor-authorized directories. The rule specifically alerts on devices exhibiting these behaviors within a short time window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
7 days ago
000