Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule detects unauthorized processes attempting to read sensitive configuration files (secrets.json, config.yaml) associated with AI coding assistants like Cline and Continue. By filtering out known, legitimate IDE and development processes, the rule highlights potential file-grabber activity indicative of an infostealer attempting to exfiltrate plaintext LLM API keys.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects instances where a browser or agentic-browser process initiates a file download and subsequently executes that same file within a five-minute window, without the intervention of a user-driven process like explorer.exe. This pattern is indicative of automated 'agentic' browser activity, potentially signifying hijacked web instructions or malicious automated tool execution flows.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
201
Detects instances where a browser or agentic-browser process initiates a file download and subsequently executes that same file within a five-minute window, without the intervention of a user-driven process like explorer.exe. This pattern is indicative of automated 'agentic' browser activity, potentially signifying hijacked web instructions or malicious automated tool execution flows.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects potential Command and Control (C2) activity leveraging the OpenAI Assistants API. The rule identifies non-standard processes (e.g., PowerShell, Python, cmd) that establish network connections to OpenAI API endpoints, specifically those often used for interaction with AI models, suggesting potential abuse of AI services for command issuance or data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
This rule detects potential backdoor deployment or persistence mechanisms in AI coding assistants like Claude Code and Cursor. It identifies when specific configuration or hook files (e.g., settings.json, hooks.js) are modified, followed within a two-hour window by the execution of suspicious child processes (e.g., powershell.exe, curl.exe, python) initiated by the coding assistant's CLI tool.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the creation of potential hook or startup scripts within hidden AI coding assistant directories (.claude, .vscode, .cursor) followed by the execution of a process from those same directories. This pattern is consistent with supply chain compromises where trojanized extensions or MCP servers are leveraged for code execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the execution of PowerShell with hidden flags and encoded commands spawned by a 'conhost.exe' process running in '--headless' mode. This specific process pattern is indicative of the obfuscated execution chain used by LausivLoader.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
This rule detects a specific network exploit attempt targeting Dahua devices (CVE-2021-33045), where an attacker attempts to bypass authentication by manipulating the login parameters, specifically by forcing the system to interpret requests as coming from the local loopback interface.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects a potential AI agent data poisoning event where a file is downloaded from an untrusted source (browser or sync client) and subsequently read within one hour by a process associated with AI agent activity (e.g., semantic_kernel, SKAgent). This pattern is often used to inject malicious context or prompt injection vectors into RAG (Retrieval-Augmented Generation) systems.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects instances where package management tools (pip, npm, docker) spawn child processes that immediately attempt to read sensitive files (SSH keys, cloud/container credentials) or perform outbound network connections. This behavior is indicative of a trojanized supply-chain package executing malicious post-install logic to exfiltrate secrets or establish initial communication with a C2 server.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects common runtime processes (Node.js, npx, Python) often used for Model Context Protocol (MCP) servers accessing sensitive local credential files such as AWS credentials, SSH private keys, or environment files. This behavior is indicative of potential credential harvesting by unauthorized MCP servers in developer environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects network connections to common public LLM inference APIs (OpenAI, HuggingFace, Anthropic, etc.) originating from processes other than standard web browsers or authorized developer tools. This behavior may indicate an attempt to exfiltrate data, utilize remote compute, or perform automated C2 communication via public generative AI services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects persistence and execution abuse within hidden IDE/AI assistant workspace directories (e.g., .vscode, .cursor, .claude). The rule monitors for the creation or modification of configuration files used for automated task execution and identifies process execution patterns originating from these directories that invoke downloaders (curl, wget) or decoders (base64) to fetch or execute payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects attempts to exploit CVE-2021-33044, an authentication bypass vulnerability in Dahua NetKeyboard hardware. The rule triggers when a POST request containing 'global.login', 'clientType: NetKeyboard', and 'loginType: Direct' is observed, which allows unauthorized access by manipulating authentication parameters.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects network traffic attempting to exploit the Dahua CVE-2021-33044 vulnerability, which allows an unauthenticated user to bypass authentication mechanisms on affected NetKeyboard devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects coordinated usage of 'xattr' to manipulate the com.apple.quarantine attribute and 'chmod' to grant executable permissions on sensitive macOS system or library paths. This behavior is indicative of an adversary attempting to bypass Gatekeeper or bypass execution restrictions on malicious payloads placed in system directories.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
203
The following analytic detects the usage of wevtutil.exe with parameters for clearing event logs such as Application, Security, Setup, Trace, or System.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments.
This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
If confirmed malicious, this behavior could allow an attacker to erase evidence of their activities, making it difficult to trace their actions and understand the full scope of the compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
003
Detects incoming HTTP requests where the 'pagename' parameter contains directory traversal sequences (e.g., '../', '..%2f'). These attempts are typically indicative of automated vulnerability scanning or exploitation attempts targeting WordPress page-template resolution logic, specifically related to CVE-2026-87902.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects Node.js or NPM process executions that reference Twilio-specific credential variables (ACCOUNT_SID, AUTH_TOKEN) within the command line, likely indicating an attempt to harvest these secrets from a developer environment.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects the installation of a specific malicious Firefox browser extension identified by its unique internal ID 'pdf-para-texto@extensao.local' or by its name 'PDF Identity Verifier'. This behavior is characteristic of adversaries using browser extensions for persistence or credential theft.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001
Detects Node.js processes, such as npm package postinstall hooks, spawning shell commands used for host enumeration. This includes accessing system environment variables, network configurations, and filesystem metadata, a pattern frequently utilized by malicious packages for initial reconnaissance post-installation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
11 days ago
001