Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where a browser process (chrome.exe) accesses the microphone or camera within a 2-minute temporal window of communicating with 'gemini.google.com'. This rule is intended to identify potential unauthorized use of system peripherals in the context of an AI-agent session.
Detects instances where a browser process (chrome.exe) accesses the microphone or camera within a 2-minute temporal window of communicating with 'gemini.google.com'. This rule is intended to identify potential unauthorized use of system peripherals in the context of an AI-agent session.
Detects instances where a browser process (chrome.exe) accesses the microphone or camera within a 2-minute temporal window of communicating with 'gemini.google.com'. This rule is intended to identify potential unauthorized use of system peripherals in the context of an AI-agent session.
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
This rule detects network communication, email interaction, or identity logon events related to known spoofed IC3 (Internet Crime Complaint Center) domains used in business email compromise (BEC) campaigns. The detection covers multiple telemetry sources including email URL information, device network events, and identity logon logs to identify attempts to interact with fraudulent portals.
This rule detects network communication, email interaction, or identity logon events related to known spoofed IC3 (Internet Crime Complaint Center) domains used in business email compromise (BEC) campaigns. The detection covers multiple telemetry sources including email URL information, device network events, and identity logon logs to identify attempts to interact with fraudulent portals.
This rule monitors for file and process events involving 'pubspec.yaml' configuration files or specific Flutter-related components such as 'universal_file_viewer' and 'surveyjs_flutter'. This detection logic is designed to track development activities or the inclusion of specific software packages within a Flutter project environment.
This rule detects the use of the 7-Zip utility (7z.exe) located in 'C:\Users\Public\Documents\' to archive files, specifically monitoring for the creation of an archive file named 'p.7z' within the same directory. This pattern of staging files and using an archive utility in public, writeable directories is a common behavior observed in adversary data exfiltration preparation.
Detects the loading or execution of 'core.dll' from non-standard system directories by common Windows proxy execution binaries (rundll32.exe, regsvr32.exe, cmd.exe, powershell.exe), which is a common indicator of DLL side-loading or malicious library hijacking.
Detects the placement of potentially malicious executable or script files onto a network share followed by the execution of that specific file path from a different host within a short timeframe. This behavior is indicative of lateral movement using tainted shared content.
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
Page 360 of 1870


