Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

KQL Query from file: Carbonato: Privileged Container Escape
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
101
Detects the execution of PowerShell with the -NoProfile flag initiated by wscript.exe or cscript.exe, containing sleep/delay commands alongside network download functions. This pattern is characteristic of malware loaders or RMM phishing kits attempting to evade sandbox analysis before initiating a remote download.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects anomalous, high-frequency, multi-channel probing of AI agent input surfaces. The rule identifies external actors sending instruction-injection style keywords across different communication channels (e.g., email, Teams, calendar) within a short window, which may indicate an attempt to identify and manipulate an organization's autonomous agents. Covers T1595.002
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
001
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
101
Detects outbound HTTP GET requests directed towards FingerprintJS CDN services that are triggered from or referred by pages hosted on disposable platforms such as Vercel or Netlify. This pattern is commonly indicative of evasion gates or bot-fingerprinting lures used in phishing campaigns to profile victim environments before delivering secondary payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
101
Detects rapid, machine-speed, sequential attack-path adaptation by suspected AI agent binaries. The rule monitors for a correlation of four stages occurring within a tight 20-minute window: 1) Failed service connections across three or more distinct protocols (SMB, SSH, HTTP, RDP, WinRM), 2) Credential access attempts (Logon events or execution of known credential-dumping tools), and 3) A lateral movement pivot to a new, previously un-targeted internal destination. The rule specifically keys on the InitiatingProcessId and InitiatingProcessCreationTime to ensure the sequence is attributed to a single process instance, distinguishing it from human manual penetration testing activity. Covers T1190, T1210, T1078
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
101
Detects rapid, multi-category system and network enumeration performed by AI-assisted development tools (e.g., Cursor, Claude, ChatGPT). The rule triggers when an AI agent process performs a comprehensive scan of the host environment, specifically covering machine/OS identity, network configuration, process listings, installed software, and access to sensitive credential files within a 10-minute window. It requires at least 5 distinct discovery categories and 6 total events to reduce noise from routine debugging. Covers T1082, T1016, T1057, T1518
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
11 days ago
101
Detects HTTP requests and responses involving the download of an executable file named 'ClaudeDesktop.exe' from the 'claude.ai' host, which is indicative of a malicious campaign distributing SectopRAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects potential malicious activity where a process associated with a Claude agent (or a downloader utility) references a 'SKILL.md' configuration file. This behavior is indicative of a poisoned skill file being used to trigger unauthorized payload downloads or re-establish persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a malicious payload masquerading as a ClaudeDesktop installer that uses DLL sideloading via a tampered libcef.dll and a repurposed JetBrains binary to execute the SectopRAT .NET RAT.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the enrollment of a new security key or passkey shortly after an unfamiliar or suspicious sign-in event within Google Workspace. This behavior is indicative of an adversary establishing persistent access following a successful session hijack or credential phishing campaign, specifically targeting authentication mechanisms to bypass existing security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects network communication to domains and specific file paths associated with the MacSync macOS stealer, which is used for malware dropper delivery and command-and-control (C2) operations. The rule monitors DeviceNetworkEvents for indicators such as specific malicious URLs, iCloud path abuse, and C2 infrastructure interaction.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
11 days ago
001
Detects HTTP responses containing script content indicative of anti-analysis or anti-debugging techniques, such as timing checks, debugger detection, and proof-of-work challenges commonly used on adversary-in-the-middle (AiTM) phishing landing pages.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects network requests (DNS queries or HTTP requests) to a predefined list of lookalike domains associated with the JWR phishing kit. These domains are designed to impersonate legitimate transport (LTA, OneMotoring, ERP) or courier/postal brands (Ninja Van, SingPost, Emirates Post) to deliver malicious payloads or credential harvesting pages.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
102
Detects network activity associated with the JWR/Outsider phishing kit, which leverages legitimate e-commerce platform parameters (e.g., Shopify/WooCommerce 'cart_data') to mimic storefront infrastructure. The rule correlates requests containing these e-commerce parameters with the loading of the phishing kit's client-side engine scripts or WebSocket workers from the same host, indicating the use of a compromised or malicious storefront-mimicry domain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects outbound network connections to known JWR phishing framework endpoints. The rule identifies suspicious interaction sequences, including initial beaconing via 'addClick' or 'getSyncSettings' followed by exfiltration of sensitive data (payment card info, OTPs) through POST requests to 'the_final_interface' or 'addCvv', or via a specific WebSocket channel pattern.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects outbound network requests to VAPI.ai APIs that are associated with the initiation of AI-powered voice agents. This telemetry can indicate the use of automation or malicious scripts, such as those used by AnonyMousKIT to launch persona-based voice phishing (vishing) campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects sustained WebSocket connections to known C2 infrastructure associated with the JWR phishing framework. The rule identifies long-running sessions or frequent reconnection patterns characteristic of a live human operator interacting with a victim, as opposed to automated, one-time form submissions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the AnonyMousKIT vishing activity pattern by monitoring Twilio API call creation events followed by specific status or gather webhook callbacks from the same host within a one-hour window, consistent with automated voice phishing to collect DTMF-entered passcodes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects the specific network-observable behavior of the JWR client engine. The rule identifies a device loading the engine script (main.js) followed within a short time window by either a fallback redirection to a_index.html or the initiation of a WebSocket connection using a specific obfuscated path pattern associated with JWR command and control.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002