Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects network exploitation attempts targeting Fortinet FortiOS and FortiProxy vulnerabilities (CVE-2024-55591, CVE-2025-24472) involving authentication bypass via HTTP header manipulation (Forwarded, X-Forwarded-For) and unauthorized access to the /jsconsole endpoint.
Detects unauthorized modifications to AI agent configuration files, including system prompts, tool allow-lists, and MCP server registration files. Such changes are often performed by processes outside of approved configuration management or infrastructure-as-code pipelines, potentially allowing for persistent manipulation of AI model behavior and capabilities.
Detects malicious prompt injection attempts within an LLM conversation session. The rule monitors for ingested content containing common instruction-override keywords (e.g., 'ignore previous instructions', 'system prompt override'), followed immediately by the agent process executing unauthorized actions such as process launch, network connections, or file creation within the same session/user context.
Detects a suspicious pattern of activity where a single source IP performs network reconnaissance followed by rapid-fire failed authentication attempts against multiple distinct hosts within a short time window. This behavior is indicative of automated, agentic AI-driven offensive tooling rather than manual activity.
This rule establishes a daily baseline of request volumes to mail.google.com per user and per host using proxy logs. It identifies anomalous spikes in traffic or unexpected users/hosts accessing personal webmail, which may indicate data exfiltration using a legitimate web service.
Detects high-velocity, automated authentication failures originating from a single IP against internet-exposed management interfaces. The rule monitors for a rapid sequence of distinct user accounts being targeted in a short time window, indicating AI-driven or automated credential stuffing/brute force activity targeting VPNs or firewalls.
Detects bulk insertions or content updates into vector databases, document stores, or knowledge bases that contain suspected instruction-override, jailbreak, or role-hijacking phrases, particularly when performed by unauthenticated or unknown identities.
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
Detects anomalous outbound network connections initiated by security and developer tooling (Trivy, Checkmarx, LiteLLM, Telnyx). This behavior is consistent with supply-chain attacks, such as those attributed to the UNC6780/TeamPCP threat group, where compromised tooling is leveraged to exfiltrate sensitive cloud credentials or API keys to external, non-vendor infrastructure.
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
Detects anomalous, high-volume file access by a single process, followed by local file compression or archiving, and subsequent outbound data transfer to a non-internal IP address. This pattern is characteristic of automated agents (like those used in the GTG-1002/Anthropic AI-orchestrated campaigns) performing rapid data triage and staging for exfiltration.
Detects potential runtime polymorphic malware that modifies its own executable or script content while simultaneously communicating with generative AI or LLM API endpoints. This behavior indicates an adversary using LLMs to regenerate obfuscated code or mutate malware signatures dynamically at runtime.
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
Detects anomalous account recovery or MFA reset activity performed by a single help-desk user account. A high volume of reset actions across numerous distinct users within a short duration is a key behavioral indicator of potential help-desk account compromise or insider abuse involving unauthorized account takeovers.
Detects the registration of a new MFA device or authenticator by a user shortly after a password reset event, where the registration originates from an IP address classified as a hosting provider, datacenter, or VPN. This pattern is indicative of a help-desk or vishing-based account takeover attack where an adversary registers their own MFA device to gain persistent access.
Detects potential vishing or account takeover precursor activity where an external or guest Microsoft Teams user, impersonating IT or Help Desk support, communicates with a user who subsequently modifies their credentials or MFA configuration within the same 24-hour period.
Detects MFA or credential reset activities on high-value or privileged accounts that lack a corresponding out-of-band verification signal, such as manager approval or identity proofing, within a one-hour window. This behavior is indicative of social engineering attempts where attackers manipulate help-desk procedures to bypass identity protections.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.


