Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects a suspicious pattern of activity where a single source IP performs network reconnaissance followed by rapid-fire failed authentication attempts against multiple distinct hosts within a short time window. This behavior is indicative of automated, agentic AI-driven offensive tooling rather than manual activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects command-line execution patterns that exhibit hallmark traits of LLM-generated code, such as overly verbose and explanatory comments, appearing alongside common obfuscation or decoding primitives (e.g., base64, iex, eval). This combination suggests the use of AI to assist in creating decoy logic or burying malicious payloads within legitimate-appearing scripts to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects high-velocity, automated authentication failures originating from a single IP against internet-exposed management interfaces. The rule monitors for a rapid sequence of distinct user accounts being targeted in a short time window, indicating AI-driven or automated credential stuffing/brute force activity targeting VPNs or firewalls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a two-stage activity: first, the potential unauthorized reading or access of LLM provider API keys from files, environment variables, or command-line arguments; and second, the subsequent use of those same credentials to authenticate to LLM provider APIs (OpenAI, Anthropic, Azure, Bedrock) from a different, unrecognized source IP address, indicating potential credential theft and session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects bulk insertions or content updates into vector databases, document stores, or knowledge bases that contain suspected instruction-override, jailbreak, or role-hijacking phrases, particularly when performed by unauthenticated or unknown identities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects high-volume, systematic querying of LLM inference endpoints, which may indicate unauthorized model extraction, distillation attempts, or targeted data exfiltration from an LLM.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the use of 'COPY TO PROGRAM' syntax within Cisco Email Security Appliance (ESA) logs. This pattern is indicative of potential command injection or OS command execution attempts often associated with exploitation of database-related functionalities, specifically targeting Cisco ESA management or backend interfaces.
avatar
Arnold Chan@slaz
avatar
Hunters
21 days ago
6022
Detects malicious prompt injection attempts within an LLM conversation session. The rule monitors for ingested content containing common instruction-override keywords (e.g., 'ignore previous instructions', 'system prompt override'), followed immediately by the agent process executing unauthorized actions such as process launch, network connections, or file creation within the same session/user context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a suspicious pattern of activity where a single source IP performs network reconnaissance followed by rapid-fire failed authentication attempts against multiple distinct hosts within a short time window. This behavior is indicative of automated, agentic AI-driven offensive tooling rather than manual activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects command-line execution patterns that exhibit hallmark traits of LLM-generated code, such as overly verbose and explanatory comments, appearing alongside common obfuscation or decoding primitives (e.g., base64, iex, eval). This combination suggests the use of AI to assist in creating decoy logic or burying malicious payloads within legitimate-appearing scripts to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects high-velocity, automated authentication failures originating from a single IP against internet-exposed management interfaces. The rule monitors for a rapid sequence of distinct user accounts being targeted in a short time window, indicating AI-driven or automated credential stuffing/brute force activity targeting VPNs or firewalls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a two-stage activity: first, the potential unauthorized reading or access of LLM provider API keys from files, environment variables, or command-line arguments; and second, the subsequent use of those same credentials to authenticate to LLM provider APIs (OpenAI, Anthropic, Azure, Bedrock) from a different, unrecognized source IP address, indicating potential credential theft and session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects bulk insertions or content updates into vector databases, document stores, or knowledge bases that contain suspected instruction-override, jailbreak, or role-hijacking phrases, particularly when performed by unauthenticated or unknown identities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous outbound network connections initiated by security and developer tooling (Trivy, Checkmarx, LiteLLM, Telnyx). This behavior is consistent with supply-chain attacks, such as those attributed to the UNC6780/TeamPCP threat group, where compromised tooling is leveraged to exfiltrate sensitive cloud credentials or API keys to external, non-vendor infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects high-volume, individually-tailored spear-phishing campaigns likely assisted by Generative AI. The rule monitors for a single sender targeting a high number of unique recipients with distinct, non-identical email subjects within a short timeframe. It specifically flags activity involving newly registered look-alike domains and interactions with credential-harvesting patterns in URLs.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a suspicious sequence of events where a user engagement (voice/video call) involving themes of urgency or helpdesk interaction is closely followed by a high-risk administrative action (e.g., password reset, MFA device enrollment, or financial transfer) by the same user, where the communication session context differs from standard activity, indicative of a deepfake-enabled vishing attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects outbound HTTPS connections to major generative AI inference endpoints originating from non-browser, non-development tool processes at regular intervals. This activity is indicative of beaconing behavior, where malware (specifically families like LAMEHUG) leverages LLM APIs for dynamic command generation, payload obfuscation, or C2 instruction retrieval, bypassing traditional security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects endpoint behavior consistent with AI-assisted exploit development, characterized by the execution of reverse engineering and vulnerability research tools (e.g., IDA Pro, Ghidra, AFL) interleaved with frequent outbound network connections to LLM APIs, followed by the local compilation of a new executable or DLL.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous, high-velocity enumeration of IAM entities and cloud infrastructure resources by a single principal within a 5-minute window. This behavior is consistent with automated reconnaissance performed by agentic AI or scripted tools, often used to map cloud environments prior to exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects network exploitation attempts targeting Fortinet FortiOS and FortiProxy vulnerabilities (CVE-2024-55591, CVE-2025-24472) involving authentication bypass via HTTP header manipulation (Forwarded, X-Forwarded-For) and unauthorized access to the /jsconsole endpoint.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
000