Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects network exploitation attempts targeting Fortinet FortiOS and FortiProxy vulnerabilities (CVE-2024-55591, CVE-2025-24472) involving authentication bypass via HTTP header manipulation (Forwarded, X-Forwarded-For) and unauthorized access to the /jsconsole endpoint.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized modifications to AI agent configuration files, including system prompts, tool allow-lists, and MCP server registration files. Such changes are often performed by processes outside of approved configuration management or infrastructure-as-code pipelines, potentially allowing for persistent manipulation of AI model behavior and capabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects malicious prompt injection attempts within an LLM conversation session. The rule monitors for ingested content containing common instruction-override keywords (e.g., 'ignore previous instructions', 'system prompt override'), followed immediately by the agent process executing unauthorized actions such as process launch, network connections, or file creation within the same session/user context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a suspicious pattern of activity where a single source IP performs network reconnaissance followed by rapid-fire failed authentication attempts against multiple distinct hosts within a short time window. This behavior is indicative of automated, agentic AI-driven offensive tooling rather than manual activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule establishes a daily baseline of request volumes to mail.google.com per user and per host using proxy logs. It identifies anomalous spikes in traffic or unexpected users/hosts accessing personal webmail, which may indicate data exfiltration using a legitimate web service.
avatar
Disney Intel&Coffee@Ills3C
avatar
Detections.ai Community
16 days ago
105
Detects high-velocity, automated authentication failures originating from a single IP against internet-exposed management interfaces. The rule monitors for a rapid sequence of distinct user accounts being targeted in a short time window, indicating AI-driven or automated credential stuffing/brute force activity targeting VPNs or firewalls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects bulk insertions or content updates into vector databases, document stores, or knowledge bases that contain suspected instruction-override, jailbreak, or role-hijacking phrases, particularly when performed by unauthenticated or unknown identities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
This rule correlates web clicks on Google Sites URLs containing keywords related to GlobalProtect with the subsequent creation or renaming of an unsigned or improperly signed GlobalProtect.msi file on the same endpoint within a 30-minute window. This behavior is indicative of a spearphishing attempt using a masqueraded landing page to deliver malicious or unauthorized software.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
Detects anomalous outbound network connections initiated by security and developer tooling (Trivy, Checkmarx, LiteLLM, Telnyx). This behavior is consistent with supply-chain attacks, such as those attributed to the UNC6780/TeamPCP threat group, where compromised tooling is leveraged to exfiltrate sensitive cloud credentials or API keys to external, non-vendor infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous remote access patterns on a single endpoint, specifically involving AnyDesk or TeamViewer sessions originating from multiple distinct geographical locations combined with usage by multiple distinct user accounts. This pattern is consistent with DPRK IT worker fraud (Wagemole) involving shared laptop farms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects anomalous, high-volume file access by a single process, followed by local file compression or archiving, and subsequent outbound data transfer to a non-internal IP address. This pattern is characteristic of automated agents (like those used in the GTG-1002/Anthropic AI-orchestrated campaigns) performing rapid data triage and staging for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects potential runtime polymorphic malware that modifies its own executable or script content while simultaneously communicating with generative AI or LLM API endpoints. This behavior indicates an adversary using LLMs to regenerate obfuscated code or mutate malware signatures dynamically at runtime.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000
This rule detects potential persistence mechanisms associated with the GlobalProtect VPN application where the binary is unsigned. It specifically monitors for unauthorized 'RunOnce' registry entries, the creation of suspicious scheduled tasks, or updates to scheduled tasks involving 'GlobalProtect.exe'. These actions are initiated by either 'msiexec.exe' or 'GlobalProtect.exe', suggesting a possible attempt to masquerade malicious activity as a legitimate VPN update or installation process.
avatar
Arnold Chan@slaz
Defender - KQL
8 days ago
000
Detects anomalous account recovery or MFA reset activity performed by a single help-desk user account. A high volume of reset actions across numerous distinct users within a short duration is a key behavioral indicator of potential help-desk account compromise or insider abuse involving unauthorized account takeovers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects the registration of a new MFA device or authenticator by a user shortly after a password reset event, where the registration originates from an IP address classified as a hosting provider, datacenter, or VPN. This pattern is indicative of a help-desk or vishing-based account takeover attack where an adversary registers their own MFA device to gain persistent access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects potential vishing or account takeover precursor activity where an external or guest Microsoft Teams user, impersonating IT or Help Desk support, communicates with a user who subsequently modifies their credentials or MFA configuration within the same 24-hour period.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects MFA or credential reset activities on high-value or privileged accounts that lack a corresponding out-of-band verification signal, such as manager approval or identity proofing, within a one-hour window. This behavior is indicative of social engineering attempts where attackers manipulate help-desk procedures to bypass identity protections.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
avatar
Arnold Chan@slaz
avatar
Hunters
8 days ago
000