Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects scenarios where a user account modifies Conditional Access (CA) policies (specifically targeting user or group inclusion/exclusion settings) within one hour of that same user account modifying authentication method policies. This pattern is potentially indicative of an adversary weakening security controls by adjusting authentication requirements and subsequently tampering with CA policies to maintain persistence or bypass MFA.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects Large Language Model (LLM) responses that contain instructions designed to propagate the current prompt to other users, systems, or agents. This pattern is indicative of a self-replicating prompt worm, which aims to spread malicious instructions across an AI ecosystem by leveraging the model's ability to generate text that instructs subsequent interactions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous process spawning behavior initiated by Python interpreters (pip/conda) on machine learning developer or training hosts, which may indicate a supply chain compromise where a malicious package executes code during or shortly after installation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule detects three distinct suspicious behaviors related to potential file manipulation and persistence mechanisms: 1. Use of 'copy /b' command to reconstruct files from fragments (e.g., header.doc, body.doc), commonly associated with file joining or data reconstruction. 2. File access within '_rels' directories targeting document fragments, often used in malicious document analysis or extraction. 3. Execution of 'Windowsupdate.exe' from the 'AppData\Local' directory, a technique often used for masquerading as a legitimate Windows service to establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects the execution of the Windows FTP client (ftp.exe) using command-line arguments that include scripts (-s:), initiated by unconventional parent processes such as explorer.exe or cmd.exe. This behavior is often associated with the execution of automated FTP scripts for data exfiltration or malware delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
004
Detects Azure sign-in events claiming successful hardware-key or FIDO2 authentication where the authentication issuer is not part of a known-good allow-list. This behavior is indicative of a rogue MFA provider, such as the TrustSink attack, which issues forged tokens claiming MFA requirements were satisfied.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
This rule monitors for indicators of compromise (IOCs) associated with the TrustSink rogue MFA provider, specifically tracking the domain 'trident-sip-filter.ngrok-free.dev' and its associated OIDC discovery path. It aggregates signals from sign-in logs, audit logs, DNS queries, and network proxy traffic to identify attempts to interact with this malicious infrastructure.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects instances where an AI agent or LLM invokes a high-privilege or sensitive tool (such as code execution, outbound HTTP, or credential store access) immediately following a prompt that exhibits characteristics of prompt injection or jailbreaking. This behavior matches MITRE ATLAS pattern AML.T0053, suggesting an attempt to use the AI agent as a pivot or execution vehicle for unauthorized actions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous, exploratory query patterns by an API key or service account against an AI model inference API. High distinct resource access volume in a short timeframe, potentially combined with off-hours activity, indicates reconnaissance phases such as output-ontology or model-family enumeration, which may precede adversarial-example crafting or verification attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects recovered scripts/payloads that harvest environment variables, API keys, bearer tokens, and Kubernetes secrets/configmaps into a variable named LOOT
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
This rule detects potentially malicious activity where an identity performs enumeration of Kubernetes secrets or configmaps and subsequently performs a search action within Slack from the same IP address within a one-hour window. This behavioral pattern is indicative of post-breakout reconnaissance, where a compromised identity or token is used to exfiltrate sensitive cloud configuration data and then perform internal reconnaissance in SaaS collaboration tools to identify further targets or credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
Detects suspicious processes frequently polling Hugging Face repository endpoints (discussions, raw files, commits). This behavior is characteristic of adversaries using public code/dataset hosting services as a covert command-and-control (C2) channel to fetch instructions or exfiltrate data, bypassing traditional network filters by blending in with legitimate developer traffic.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
8 days ago
000
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
Defender - KQL
14 days ago
103
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
003
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
003
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
103
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
003
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
14 days ago
003
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
003
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
003
This rule detects potentially malicious emails that impersonate Microsoft account security notifications or security advisories. It looks for emails with specific social engineering themes in the sender name, sender address, or subject line, accompanied by .zip attachments that contain suspicious file names related to cybersecurity warnings or OTP abuse, which are common lures for malware delivery.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104