Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a suspicious pattern of activity where a single source IP performs network reconnaissance followed by rapid-fire failed authentication attempts against multiple distinct hosts within a short time window. This behavior is indicative of automated, agentic AI-driven offensive tooling rather than manual activity.
Detects command-line execution patterns that exhibit hallmark traits of LLM-generated code, such as overly verbose and explanatory comments, appearing alongside common obfuscation or decoding primitives (e.g., base64, iex, eval). This combination suggests the use of AI to assist in creating decoy logic or burying malicious payloads within legitimate-appearing scripts to evade detection.
Detects high-velocity, automated authentication failures originating from a single IP against internet-exposed management interfaces. The rule monitors for a rapid sequence of distinct user accounts being targeted in a short time window, indicating AI-driven or automated credential stuffing/brute force activity targeting VPNs or firewalls.
Detects a two-stage activity: first, the potential unauthorized reading or access of LLM provider API keys from files, environment variables, or command-line arguments; and second, the subsequent use of those same credentials to authenticate to LLM provider APIs (OpenAI, Anthropic, Azure, Bedrock) from a different, unrecognized source IP address, indicating potential credential theft and session hijacking.
Detects bulk insertions or content updates into vector databases, document stores, or knowledge bases that contain suspected instruction-override, jailbreak, or role-hijacking phrases, particularly when performed by unauthenticated or unknown identities.
Detects high-volume, systematic querying of LLM inference endpoints, which may indicate unauthorized model extraction, distillation attempts, or targeted data exfiltration from an LLM.
Detects the use of 'COPY TO PROGRAM' syntax within Cisco Email Security Appliance (ESA) logs. This pattern is indicative of potential command injection or OS command execution attempts often associated with exploitation of database-related functionalities, specifically targeting Cisco ESA management or backend interfaces.
Detects malicious prompt injection attempts within an LLM conversation session. The rule monitors for ingested content containing common instruction-override keywords (e.g., 'ignore previous instructions', 'system prompt override'), followed immediately by the agent process executing unauthorized actions such as process launch, network connections, or file creation within the same session/user context.
Detects a suspicious pattern of activity where a single source IP performs network reconnaissance followed by rapid-fire failed authentication attempts against multiple distinct hosts within a short time window. This behavior is indicative of automated, agentic AI-driven offensive tooling rather than manual activity.
Detects command-line execution patterns that exhibit hallmark traits of LLM-generated code, such as overly verbose and explanatory comments, appearing alongside common obfuscation or decoding primitives (e.g., base64, iex, eval). This combination suggests the use of AI to assist in creating decoy logic or burying malicious payloads within legitimate-appearing scripts to evade detection.
Detects high-velocity, automated authentication failures originating from a single IP against internet-exposed management interfaces. The rule monitors for a rapid sequence of distinct user accounts being targeted in a short time window, indicating AI-driven or automated credential stuffing/brute force activity targeting VPNs or firewalls.
Detects a two-stage activity: first, the potential unauthorized reading or access of LLM provider API keys from files, environment variables, or command-line arguments; and second, the subsequent use of those same credentials to authenticate to LLM provider APIs (OpenAI, Anthropic, Azure, Bedrock) from a different, unrecognized source IP address, indicating potential credential theft and session hijacking.
Detects bulk insertions or content updates into vector databases, document stores, or knowledge bases that contain suspected instruction-override, jailbreak, or role-hijacking phrases, particularly when performed by unauthenticated or unknown identities.
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
Detects anomalous outbound network connections initiated by security and developer tooling (Trivy, Checkmarx, LiteLLM, Telnyx). This behavior is consistent with supply-chain attacks, such as those attributed to the UNC6780/TeamPCP threat group, where compromised tooling is leveraged to exfiltrate sensitive cloud credentials or API keys to external, non-vendor infrastructure.
Detects high-volume, individually-tailored spear-phishing campaigns likely assisted by Generative AI. The rule monitors for a single sender targeting a high number of unique recipients with distinct, non-identical email subjects within a short timeframe. It specifically flags activity involving newly registered look-alike domains and interactions with credential-harvesting patterns in URLs.
Detects a suspicious sequence of events where a user engagement (voice/video call) involving themes of urgency or helpdesk interaction is closely followed by a high-risk administrative action (e.g., password reset, MFA device enrollment, or financial transfer) by the same user, where the communication session context differs from standard activity, indicative of a deepfake-enabled vishing attack.
Detects outbound HTTPS connections to major generative AI inference endpoints originating from non-browser, non-development tool processes at regular intervals. This activity is indicative of beaconing behavior, where malware (specifically families like LAMEHUG) leverages LLM APIs for dynamic command generation, payload obfuscation, or C2 instruction retrieval, bypassing traditional security controls.
Detects endpoint behavior consistent with AI-assisted exploit development, characterized by the execution of reverse engineering and vulnerability research tools (e.g., IDA Pro, Ghidra, AFL) interleaved with frequent outbound network connections to LLM APIs, followed by the local compilation of a new executable or DLL.
Detects anomalous, high-velocity enumeration of IAM entities and cloud infrastructure resources by a single principal within a 5-minute window. This behavior is consistent with automated reconnaissance performed by agentic AI or scripted tools, often used to map cloud environments prior to exploitation.
Detects network exploitation attempts targeting Fortinet FortiOS and FortiProxy vulnerabilities (CVE-2024-55591, CVE-2025-24472) involving authentication bypass via HTTP header manipulation (Forwarded, X-Forwarded-For) and unauthorized access to the /jsconsole endpoint.

