Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
12 days ago
101
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
101
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
avatar
Arnold Chan@slaz
Defender - KQL
12 days ago
101
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
12 days ago
101
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
12 days ago
301
Detects the execution of known malicious MSI files associated with the LegionLoader malware family by monitoring process creation events involving msiexec.exe. The rule matches on specific file hashes and filenames identified in technical analysis of LegionLoader variants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the loading of a known malicious 7z.dll file within the 'Traiolx Custom Utils' directory. This behavior is indicative of DLL sideloading used by LegionLoader to achieve code execution under the guise of a legitimate application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the loading of a known malicious 7z.dll file within the 'Traiolx Custom Utils' directory. This behavior is indicative of DLL sideloading used by LegionLoader to achieve code execution under the guise of a legitimate application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the presence of a suspicious or known malicious 'Normaliz.dll' file located within the 'Traiolx Custom Utils' directory, indicative of a DLL sideloading attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This behavior is often associated with malware or malicious loaders (such as LegionLoader) that use secondary instances to facilitate malicious code execution or persistence while masquerading as legitimate update utilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the installation or registration of the legitimate gitlab-runner.exe binary as a persistent Windows service. Adversaries can leverage this technique to establish a command-and-control (C2) channel or persistent backdoor by masquerading as legitimate CI/CD infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects unsigned or non-standard Python processes loading core Windows system modules like kernel32.dll or ntdll.dll. This behavior is consistent with NarwhalRAT's fileless execution technique, which utilizes ctypes to interact with low-level Windows APIs (VirtualAlloc, RtlMoveMemory, CFUNCTYPE) for in-memory payload allocation and execution, bypassing traditional disk-based detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the BTR.sys driver, a tool identified as being extracted from Microsoft's MpEngine.dll and repurposed for kernel-level file and registry manipulation. The rule matches on specific SHA-256 file hashes or combinations of PE metadata strings, indicating the presence of this driver on the system.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
This rule detects the creation of a new service in HKLM\SYSTEM\CurrentControlSet\Services that includes specific suspicious command-line arguments (containing ':changelist') and is configured to start automatically (Start value '1') or belongs to the 'Boot Bus Extender' group. This behavior is often associated with persistence mechanisms where adversaries register a service to execute malicious payloads upon system startup.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects repeated large HTTP PUT or POST requests (exceeding 5MB) from a internal host to external destinations. This pattern is indicative of potential bulk data exfiltration over web services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the execution of BTR_CLI.exe with command line arguments indicative of installing or interacting with the Mimikatz driver (mimidrv.sys). This behavior is associated with loading the malicious driver to facilitate credential dumping from kernel memory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the creation of .bat files within the Windows Startup folder. Adversaries often use this technique to achieve persistence by ensuring a script executes automatically upon user login.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects the execution of PowerShell with suspicious command-line flags often associated with malicious scripts (e.g., hidden windows, no profile, bypassed execution policies) when the script is located in the Windows Temporary directory.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects instances of the Windows Character Map utility (charmap.exe) loading graphics-related libraries such as System.Drawing.dll or gdiplus.dll. These modules are typically not required by charmap.exe and their loading is a common indicator of process injection for the purpose of capturing the screen or desktop interface.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects instances where PowerShell is launched as a child process of WScript.exe or CScript.exe with suspicious command line flags intended to hide window visibility, bypass execution policies, or run in a non-interactive mode. This behavior is frequently used by adversaries to execute obfuscated or malicious scripts while minimizing user awareness.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002
Detects instances where PowerShell.exe spawns the .NET C# compiler (csc.exe) with command-line arguments referencing a '.cmdline' file. This pattern is commonly used by adversaries to compile malicious code in-memory, bypassing traditional disk-based file scanning.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
002