Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the execution of PowerShell scripts located in Windows temporary directories (AppData/Local/Temp or Temp) that utilize common evasion flags such as hidden window style, bypass execution policy, or non-interactive mode. This behavior is frequently associated with initial stagers, droppers, or malicious script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects instances where wscript.exe spawns cscript.exe with a VBScript file in the command line. This sequence often indicates an attempt to run obfuscated or malicious scripts using built-in Windows scripting engines, which is a common technique for initial access or execution by adversaries.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
This rule detects access (creation, modification, renaming, or reading) to browser-specific sensitive credential files ('Login Data' or 'Local State') located in the user data directories of Chrome, Edge, or Brave. It filters out legitimate activity by ensuring the initiating process is not the browser's own application executable, which is indicative of credential theft or dumping by unauthorized tools.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects the execution of Windows Package Manager and configuration-related server binaries (WindowsPackageManagerServer.exe, ConfigurationRemotingServer.exe, DSCourier.exe) when not initiated by the authorized 'winget.exe' process. The rule further correlates these processes with the absence or delayed loading of the 'Microsoft.Management.Configuration' library, which may indicate unauthorized usage or tampering with package/configuration management components.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
This rule monitors for the creation or renaming of executable files (.exe) within the 'Users\Public' directory. This directory is commonly used by adversaries for staging malicious payloads, as it is writable by standard users and often overlooked by security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects anomalous, high-volume, low-severity events flagged for human review originating from a single AI agent or source within a 10-minute window. This behavior is indicative of an adversary flooding the human-in-the-loop (HITL) review queue with chaff data (noise) to exhaust analyst capacity or conceal malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the execution of PowerShell or Command Prompt with common adversarial flags (e.g., encoded commands, bypass, hidden windows) initiated by the Windows Explorer process. This pattern correlates the execution event with recent user interaction with the Windows Run MRU registry key, suggesting a possible manual execution of malicious commands via the 'Run' dialog box.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects usage of msiexec.exe to execute an MSI package from a remote URL. This technique is often used to download and execute malicious installers directly from the internet, bypassing local file storage.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects the execution of PowerShell with obfuscation-related flags (-NoProfile, -WindowStyle Hidden, -EncodedCommand) initiated by common scripting interpreters (wscript.exe, mshta.exe, cscript.exe). This pattern is often indicative of malicious scripts, such as HTA or VBScript files, attempting to execute encoded PowerShell commands in a high-privilege context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
This rule detects potential command-and-control (C2) activity by monitoring network connections to a specific malicious IP address (91.196.32.232) over port 8089 and correlating this with suspicious PowerShell commands. The rule looks for PowerShell scripts executing 'Invoke-RestMethod' to reach out to the C2, as well as obfuscated or beaconing-like behavior involving 'Start-Sleep' intervals paired with C2-related keywords.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects the creation or modification of a Windows Registry 'Run' key that triggers a PowerShell script named 'Update.ps1' with hidden execution policies. The rule also captures direct execution of the same PowerShell script via process creation events.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects unauthorized or anomalous write operations (upsert/insert) to a vector database, which could indicate a Retrieval-Augmented Generation (RAG) injection attack. The rule monitors for writes from non-sanctioned identities, operations outside of established maintenance or ingestion windows, or entries that lack necessary provenance metadata such as source document IDs or content hashes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule detects potential Training Data Poisoning (AML.T0020) by monitoring for anomalous activities in ML data pipelines. It triggers when ingestion jobs utilize untrusted sources, unregistered source paths, unauthorized accounts write to datasets, or when significant data volume bursts or schema/checksum drifts occur immediately prior to a scheduled training run.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule detects the unauthorized download of complete ML model checkpoint or weight files from a model registry or object storage. It monitors for common model file extensions in download events that are not associated with a legitimate deployment justification or a pre-approved change management window, helping to identify potential intellectual property theft or model exfiltration attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects instances where an LLM agent initiates sensitive or out-of-sandbox tool calls (such as file system access or arbitrary command execution) following input that contains suspicious directive-override or prompt injection patterns. This behavior indicates that the agent has been compromised by a prompt injection attack, allowing an unauthorized actor to control the agent's tool-calling capabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects modifications to Microsoft Entra ID (formerly Azure AD) authentication policies, specifically the registration, enablement, or modification of External Authentication Methods (EAMs). This activity can indicate an attempt to add a rogue authentication provider for persistent unauthorized access, bypassing standard MFA or conditional access policies.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects Cost Harvesting activity (AML.T0034) targeting ML inference services, characterized by a significant spike in request volume or compute consumption coupled with low payload uniqueness. This behavior suggests an adversary is intentionally driving up billing costs by submitting redundant or low-value requests to the API.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the presence or execution of artifacts associated with the TrustSink proof-of-concept (deploy.py, cleanup_eam.py, deploy_state.json), which is used to register or remove rogue Entra authentication providers.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects anomalous access patterns to machine learning model inference endpoints, including unauthorized access attempts such as credential failures, scope violations, and quota exhaustion, indicating potential misuse or compromise of private model APIs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects potential Denial of ML Service (DoMLs) attacks targeting inference endpoints. The rule identifies anomalous behavior characterized by large request payloads (oversized requests) correlated with increased latency or high GPU utilization, suggesting an attempt to exhaust compute resources and impact model availability.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001