Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects exploit attempts targeting a Python prompt-injection vulnerability (CVE-2026-26030). The rule identifies command lines attempting to traverse Python's object hierarchy (e.g., using __class__, __base__, __subclasses__) to import the os module and execute system commands. It also flags subsequent child processes (e.g., calc.exe, cmd.exe) spawned by Python interpreters or Semantic Kernel host processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects the creation of potentially malicious script or executable files (.bat, .ps1, .exe, .vbs) within the Windows Startup folder. It triggers when these files are created by processes typically used for automation or development (dotnet, python) or processes utilizing specific semantic/download-related command lines. The rule further correlates this activity with the presence of PowerShell commands indicative of script downloading or code execution (e.g., IEX, DownloadString) by the same device within the same timeframe, suggesting persistent execution of potentially malicious code.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
402
Detects anomalous, high-frequency interaction with AI model endpoints characterized by a high volume of requests with a near 1:1 ratio of distinct inputs. This pattern is indicative of automated knowledge-distillation or model extraction attacks against AI services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
This rule identifies non-browser processes (and those not originating from standard installation directories of common browsers) that exhibit persistent, repeated network connections to the OpenAI API. This pattern is indicative of potential C2 traffic, where adversaries abuse the OpenAI Assistants API as a covert communication channel (e.g., SesameOp).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects outbound HTTP GET requests containing a .ps1 file extension in the URI, originating from a host without a specified User-Agent, and targeting domains other than Microsoft or Windows Update. This pattern is characteristic of a persistence mechanism executing a PowerShell script to download a secondary payload (e.g., via Net.WebClient).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where browser automation tools (e.g., Selenium, Puppeteer, Playwright) or headless browser instances initiate command-line interpreters or scripting hosts. This behavior is indicative of potential automated exploitation, such as browser-based attacks where a malicious script attempts to execute commands directly on the host operating system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects scenarios where a browser or agent process downloads a file and subsequently initiates a local process that references the downloaded file within a very short timeframe (2 minutes). This pattern is indicative of automated or agentic behavior (such as AI-assisted malware execution) where a download is followed by immediate, non-human-mediated execution of the downloaded content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects potential AI agent prompt injection by monitoring email subjects or attachment names for keywords often associated with system instruction overrides. It correlates these potentially malicious emails with subsequent execution of common administrative or script-interpreting binaries (e.g., PowerShell, cmd.exe) on the recipient's device within a one-hour window, suggesting a potential successful hijack of an automated process or AI agent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects the installation of AI-related packages (e.g., mcp, tiktoken_mcp) via common package managers (pip, npm, docker) followed by an outbound network connection from the same host within 10 minutes. This behavior is consistent with supply chain attacks where trojanized AI/MCP components are used to initiate command-and-control communication shortly after deployment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects instances where an identity with no prior compute-provisioning history in the last 14 days successfully provisions high-performance GPU-enabled virtual machines in Azure. This behavior is indicative of potential resource hijacking, such as LLMjacking, where compromised identities are leveraged to deploy infrastructure for unauthorized resource-intensive workloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects unauthorized processes (non-browser) reading sensitive browser session and credential files (e.g., Cookies, Login Data) across multiple user profiles, followed by immediate outbound network connections. This behavior is highly characteristic of commodity information stealers (e.g., LummaC2, Stealc, Vidar) attempting to exfiltrate browser-stored credentials and session data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
This rule detects outbound HTTP GET requests initiated by a process using a 'WebClient' user-agent to retrieve a file named 'shell.ps1'. This behavior is characteristic of adversaries downloading second-stage PowerShell payloads to a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects outbound network requests to OpenAI Assistants API endpoints (threads, assistants, runs) that do not originate from common web browsers. This activity may indicate malicious usage of AI services, such as command and control communication via AI agents or automated exfiltration scripts, as opposed to legitimate user-initiated browsing.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects instances where an AI agent (e.g., Semantic Kernel) launches command-line tools commonly used to perform bulk data destruction or system wiping, such as file deletion commands, volume shadow copy removal, or disk formatting. This rule flags suspicious orchestration by AI agents that may be acting outside of expected parameters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the creation or modification of documents in common formats (e.g., .txt, .md, .docx, .pdf) that contain strings indicative of prompt-injection attempts. These strings are commonly used to manipulate the behavior of AI agents or Large Language Models (LLMs) that may process or index these files automatically.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects outbound network traffic to Microsoft Graph API originating from a user-agent string identified as 'python-httpx'. This behavior is characteristic of automated scripts or malicious tools using Python libraries to interact with Microsoft cloud services, potentially for data exfiltration or unauthorized API interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
20 days ago
5115
Detects the installation of a Windows service where the ImagePath points to a gitlab-runner executable but the ServiceName deviates from the default 'gitlab-runner' name. This technique is often used to mask persistence or evade simple naming-based detections by utilizing the --service flag to rename the runner service.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects execution of the BTR_CLI.exe utility with specific command-line arguments. The flags monitored include -a, -chain, -item, -trigger, and -cleanup, which suggest administrative, chaining, or automated triggering behaviors of a custom or proprietary command-line interface tool. This rule tracks the command-line usage to identify potential automated task execution or system configuration changes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the execution of BTR_CLI.exe with cleanup parameters that correlate with the deletion of specific registry keys (services) and related file artifacts (e.g., .dat or changelist files) within a short time window. This pattern is indicative of a post-compromise cleanup routine aimed at removing traces of malicious services or payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects the execution of BTR_CLI.exe with command line arguments indicative of installing or interacting with the Mimikatz driver (mimidrv.sys). This behavior is associated with loading the malicious driver to facilitate credential dumping from kernel memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
003
Detects rapid deletion of Windows Defender or WdFilter service registry keys by non-standard processes (not System or ntoskrnl.exe). This pattern is consistent with kernel-mode tamper protection bypass attempts, such as the use of the BTR.sys driver to force the removal of defensive configuration entries, effectively disabling Windows Defender.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
103