Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects access to sensitive cryptocurrency wallet files (e.g., wallet.dat, keystore) by processes typically associated with LOLBins (Living-off-the-land Binaries) like PowerShell, MSBuild, or non-executable utilities. This activity is indicative of credential theft or data staging for exfiltration of cryptocurrency assets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of PowerShell scripts containing specific obfuscation or encoding patterns. The rule identifies potential malicious intent by searching for hardcoded suspicious strings or common binary-to-string conversion methods used to hide script content from security monitoring.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects the execution of PowerShell or Unix shell commands (such as those containing encoded arguments, IEX, or clipboard reading) that are initiated by GUI-based applications or interactive shell environments like Windows Explorer, terminal emulators, or runtime brokers, often indicating potential malicious command injection or living-off-the-land activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
19 days ago
309
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
15 days ago
203
Detects unauthorized code injection attempts into web browser processes (chrome.exe, msedge.exe) by non-browser related processes. This behavior involves using APIs like CreateRemoteThread, NtAllocateVirtualMemory, or NtWriteVirtualMemory to modify memory and execute remote threads, which is a common technique used by information stealers such as LummaC2 to bypass browser security controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
103
This rule detects potential data staging activity associated with the REMUS malware. It correlates Windows Management Instrumentation (WMI) queries for antivirus information (e.g., 'AntiVirusProduct', 'WbemLocator') with subsequent file creation events in non-standard directories. This behavior is indicative of an adversary preparing or staging system profile data for exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
703
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
15 days ago
103
Detects execution of PowerShell or Python scripts characterized by common patterns found in AI-generated code, including specific obfuscation techniques (base64, string manipulation), boilerplate error handling structures, verbose comments, and generic variable naming conventions. High scores indicate a higher probability of automated or obfuscated script execution.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
This rule identifies potential prompt injection attempts against Microsoft Copilot and Azure OpenAI services by monitoring CloudAppEvents for specific adversarial markers, encoded instruction blocks, or hidden text patterns. It flags recurring attempts from a single user as suspicious probing activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
301
Detects network connections from server or workload identities (excluding SYSTEM) to known public Generative-AI inference API domains. This may indicate the use of AI services for data exfiltration, automated content generation, or C2 communication via legitimate web services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
301
Detects coordinated credential stuffing campaigns originating from shared IP infrastructure. The rule identifies patterns where multiple distinct accounts are targeted with failed sign-in attempts, characterized by rapidly rotating user-agent/device fingerprints while remaining under standard per-account and per-IP throttling limits. It focuses on the combination of high unique account counts, rotating user-agents, and sustained activity over a specific time window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
This rule monitors incoming email events for potential phishing attempts by identifying messages from unknown sender domains (not seen in the last 90 days) that contain known AI-generated response phrases in the subject line or personalized content matching the recipient's display name. This helps detect spearphishing lures that attempt to build trust through impersonation or leverage LLM-generated phrasing common in automated phishing campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects the transmission of sensitive credential-like patterns (such as API keys, private keys, and connection strings) to known external AI coding assistant and IDE plugin endpoints. This rule monitors cloud application events originating from developer workstations or CI/CD runners where such sensitive information may be inadvertently or maliciously sent to third-party AI services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
This rule detects potential data exfiltration by monitoring corporate user activities involving consumer generative AI services (e.g., ChatGPT, Gemini, Claude). It identifies suspicious patterns such as large volume submissions, repeated chunked prompts, and the presence of sensitive content (e.g., PII markers, classification labels) or obfuscated payloads (base64/rot13) that suggest an attempt to bypass DLP or detection controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects autonomous AI coding-agent processes (e.g., Claude Code, Cursor, Aider) spawning shell or git processes to perform potentially destructive actions such as recursive file deletion, forced git pushes, database manipulation, or unauthorized access to sensitive credential files, indicating agentic 'excessive agency' or compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
201
Detects evidence of indirect prompt injection (IPI) attempts within email and document content processed by enterprise AI assistants. The rule flags instruction-hijack phrases, hidden obfuscation characters (e.g., zero-width, white-on-white text), and encoded blocks specifically targeting AI model behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects large outbound POST requests or file uploads from managed endpoints to public,
consumer-grade generative-AI chatbot domains (ChatGPT, Gemini, and equivalents). Data pasted
or uploaded into these services may be retained by the provider for logging or model
training outside company control, representing a persistent shadow-AI governance gap.
This detects the network-observable behavior (large uploads to these domains); confirming
the payload contains classification markers, source code, or PII/PCI requires DLP content
inspection integrated with the proxy.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects video and audio conferencing clients (e.g., Zoom, Microsoft Teams, Webex) loading either unsigned DLLs or DLLs commonly associated with virtual camera and audio injection tools (e.g., OBS VirtualCam, Snap Camera). This behavior is characteristic of deepfake injection techniques used to manipulate video conference participants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects web reconnaissance activity characterized by the use of User-Agent strings associated with automated AI agent frameworks and headless browser libraries (e.g., LangChain, AutoGPT, Playwright, Selenium, python-requests). These tools are frequently utilized in autonomous exploitation scenarios to scan multiple URI paths on a web server in a short timeframe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
The following analytic identifies the `finger.exe` utility being spawned with a command line containing an `@` character, indicating a remote host/server was specified.
The Finger protocol utility is largely obsolete in modern environments and has been abused by adversaries as a living-off-the-land binary (LOLBIN) to retrieve encoded payloads or establish covert command-and-control communication with an attacker-controlled finger server.
This behavior is uncommon in legitimate enterprise usage and warrants investigation.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
15 days ago
503
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
15 days ago
103