Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
001
Detects a multi-stage, automated attack chain performed by AI-based development agents (e.g., Claude, Copilot, Cursor). The rule correlates process discovery, credential access, file collection (staging), and exfiltration over web services within a tight 15-minute window, identifying potential autonomous exploitation and data exfiltration. Covered T1046, T1552.001, T1078, T1005, T1567
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
001
This rule detects non-standard processes attempting to access sensitive web browser files (e.g., 'Login Data', 'Cookies', 'key4.db') that are typically only accessed by legitimate web browsers. It excludes known browser processes and trusted security or sync applications to identify potential credential theft attempts.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
105
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
KQL Query
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101
KQL Query from file: Network detection - C2 domains and static key
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001
KQL Query from file: Network detection - C2 domains and static key
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
12 days ago
101
KQL Query from file: Network detection - C2 domains and static key
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
101
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
101
Detects instances where processes typically associated with browser-related tasks (smartscreen.exe, ctfmon.exe) load ntdll.dll while another process on the same device is running with browser-specific command-line arguments (e.g., --user-data-dir, --profile-directory). This pattern is often indicative of process injection or credential harvesting attempts where an adversary attempts to interact with or scrape data from active browser sessions.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
101
This rule detects internal users submitting potentially sensitive data to public generative AI applications (e.g., ChatGPT, Claude, Gemini) where Microsoft Purview DLP or a comparable inspection service has triggered a policy match. It correlates cloud application outbound signals with content inspection logs to identify high-risk exfiltration events while excluding sanctioned enterprise-licensed AI instances.
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
101
KQL Query from file: Network detection - C2 domains and static key
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
12 days ago
001
This rule detects scenarios where an AI agent executes shell commands or system-level tools immediately after receiving a prompt injection attack from an untrusted source. It correlates agent audit logs—specifically identifying tool calls flagged for prompt injection—with actual endpoint process creation events. It flags process execution as 'High' severity if the command line matches common malicious patterns like encoded commands, IEX, or attempts to access credential material (e.g., lsass, mimikatz).
avatar
Arnold Chan@slaz
avatar
Hunters
12 days ago
001
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
101
Detects reconnaissance behavior (System Information, Account, and Network Discovery) performed by processes associated with AI and LLM coding assistants. The rule monitors for a chain of suspicious activities, such as executing discovery commands or excessive network scanning within a 10-minute window, identifying potential misuse of developer-oriented agent tools for post-exploitation reconnaissance.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
101
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
001
Detects the creation of a new local account that is immediately followed by (or associated with) execution from a process identified as an AI development or agent-based tool (e.g., Cursor, GitHub Copilot, Ollama). The rule correlates process creation events with Windows Security Event ID 4720 (User account created) and optionally checks for subsequent addition to the local Administrators group. This logic aims to surface potential unauthorized credential creation triggered by automated AI coding assistants or LLM-driven workflows.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
101
This rule detects potentially unauthorized device registration or Intune enrollment activity by monitoring Azure Sign-in logs. It specifically flags accounts that exhibit rapid, multiple device registration attempts (>= 2 in 5 minutes) combined with suspicious indicators such as scripted User Agents ('python-requests'), the presence of Primary Refresh Tokens (PRT), specific device naming patterns, or concurrent Intune enrollment activity. These behaviors are common indicators of automated adversary activity aiming to bypass conditional access policies by enrolling illicit devices.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
19 days ago
6010
Detects HTTP(S) requests to known SideCopy/ReverseRAT payload-delivery URLs identified in Operation SideCopy spear-phishing campaigns targeting Indian academia.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
002
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
14 days ago
002
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
14 days ago
002