Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
KQL Query from file: Carbonato: Privileged Container Escape
Detects the execution of PowerShell with the -NoProfile flag initiated by wscript.exe or cscript.exe, containing sleep/delay commands alongside network download functions. This pattern is characteristic of malware loaders or RMM phishing kits attempting to evade sandbox analysis before initiating a remote download.
Detects anomalous, high-frequency, multi-channel probing of AI agent input surfaces. The rule identifies external actors sending instruction-injection style keywords across different communication channels (e.g., email, Teams, calendar) within a short window, which may indicate an attempt to identify and manipulate an organization's autonomous agents. Covers T1595.002
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
Detects outbound HTTP GET requests directed towards FingerprintJS CDN services that are triggered from or referred by pages hosted on disposable platforms such as Vercel or Netlify. This pattern is commonly indicative of evasion gates or bot-fingerprinting lures used in phishing campaigns to profile victim environments before delivering secondary payloads.
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
Detects HTTP requests and responses involving the download of an executable file named 'ClaudeDesktop.exe' from the 'claude.ai' host, which is indicative of a malicious campaign distributing SectopRAT.
Detects potential malicious activity where a process associated with a Claude agent (or a downloader utility) references a 'SKILL.md' configuration file. This behavior is indicative of a poisoned skill file being used to trigger unauthorized payload downloads or re-establish persistence.
Detects a malicious payload masquerading as a ClaudeDesktop installer that uses DLL sideloading via a tampered libcef.dll and a repurposed JetBrains binary to execute the SectopRAT .NET RAT.
Detects the enrollment of a new security key or passkey shortly after an unfamiliar or suspicious sign-in event within Google Workspace. This behavior is indicative of an adversary establishing persistent access following a successful session hijack or credential phishing campaign, specifically targeting authentication mechanisms to bypass existing security controls.
Detects network communication to domains and specific file paths associated with the MacSync macOS stealer, which is used for malware dropper delivery and command-and-control (C2) operations. The rule monitors DeviceNetworkEvents for indicators such as specific malicious URLs, iCloud path abuse, and C2 infrastructure interaction.
Detects HTTP responses containing script content indicative of anti-analysis or anti-debugging techniques, such as timing checks, debugger detection, and proof-of-work challenges commonly used on adversary-in-the-middle (AiTM) phishing landing pages.
Detects network requests (DNS queries or HTTP requests) to a predefined list of lookalike domains associated with the JWR phishing kit. These domains are designed to impersonate legitimate transport (LTA, OneMotoring, ERP) or courier/postal brands (Ninja Van, SingPost, Emirates Post) to deliver malicious payloads or credential harvesting pages.
Detects network activity associated with the JWR/Outsider phishing kit, which leverages legitimate e-commerce platform parameters (e.g., Shopify/WooCommerce 'cart_data') to mimic storefront infrastructure. The rule correlates requests containing these e-commerce parameters with the loading of the phishing kit's client-side engine scripts or WebSocket workers from the same host, indicating the use of a compromised or malicious storefront-mimicry domain.
Detects outbound network connections to known JWR phishing framework endpoints. The rule identifies suspicious interaction sequences, including initial beaconing via 'addClick' or 'getSyncSettings' followed by exfiltration of sensitive data (payment card info, OTPs) through POST requests to 'the_final_interface' or 'addCvv', or via a specific WebSocket channel pattern.
Detects outbound network requests to VAPI.ai APIs that are associated with the initiation of AI-powered voice agents. This telemetry can indicate the use of automation or malicious scripts, such as those used by AnonyMousKIT to launch persona-based voice phishing (vishing) campaigns.
Detects sustained WebSocket connections to known C2 infrastructure associated with the JWR phishing framework. The rule identifies long-running sessions or frequent reconnection patterns characteristic of a live human operator interacting with a victim, as opposed to automated, one-time form submissions.
Detects the AnonyMousKIT vishing activity pattern by monitoring Twilio API call creation events followed by specific status or gather webhook callbacks from the same host within a one-hour window, consistent with automated voice phishing to collect DTMF-entered passcodes.
Detects the specific network-observable behavior of the JWR client engine. The rule identifies a device loading the engine script (main.js) followed within a short time window by either a fallback redirection to a_index.html or the initiation of a WebSocket connection using a specific obfuscated path pattern associated with JWR command and control.


