Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
101
Detects network communication to a suspicious staging domain (pdf.gusercontent.com) that mimics legitimate services. This traffic is associated with the 'onInstalled' event handler of a malicious browser extension, often used to signal a successful infection or initiate secondary payload delivery.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the behavior of LunexStealer targeting cryptocurrency wallets. The rule monitors for the enumeration of known crypto wallet files and browser-stored extension data, followed closely by the creation of a 'wallet.zip' archive by the same process, which is indicative of staged data collection for exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
109
Detects a multi-stage attack pattern against publicly exposed AI service endpoints. The detection correlates: (1) Enumeration of sensitive AI/MCP-related API endpoints (minimum 3 distinct hits) in a 10-minute window; (2) Subsequent POST requests to AI service endpoints within 15 minutes of the enumeration; and (3) A spike of 5 or more server errors (HTTP 5xx) within 10 minutes following the POST activity. This pattern suggests automated reconnaissance followed by attempted exploitation of exposed AI model interfaces or orchestration services. Covers T1595.002, T1190
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
101
Detects a multi-stage attack pattern against publicly exposed AI service endpoints. The detection correlates: (1) Enumeration of sensitive AI/MCP-related API endpoints (minimum 3 distinct hits) in a 10-minute window; (2) Subsequent POST requests to AI service endpoints within 15 minutes of the enumeration; and (3) A spike of 5 or more server errors (HTTP 5xx) within 10 minutes following the POST activity. This pattern suggests automated reconnaissance followed by attempted exploitation of exposed AI model interfaces or orchestration services. Covers T1595.002, T1190
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
101
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
101
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
101
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a suspected ClickFix infection sequence associated with Psychedelic Stealer. The rule identifies a user navigating to known malicious lure pages (often mimicking Cloudflare CAPTCHAs) followed shortly by the Windows Run dialog (explorer.exe) initiating msiexec.exe to execute a remote MSI file.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
001
Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
101
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
101
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
001
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
Detects successful logons (Event ID 4624) that use NTLM authentication or a LogonType of 9 (NewCredentials), where the LogonProcessName involves 'seclogo'. This pattern is often associated with the use of the secondary logon service, which can be abused by tools to execute processes under different user contexts or to perform credential-based attacks.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
14 days ago
002
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
101
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
001