Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,261 detections

Detects instances where a browser process (chrome.exe) accesses the microphone or camera within a 2-minute temporal window of communicating with 'gemini.google.com'. This rule is intended to identify potential unauthorized use of system peripherals in the context of an AI-agent session.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
000
Detects instances where a browser process (chrome.exe) accesses the microphone or camera within a 2-minute temporal window of communicating with 'gemini.google.com'. This rule is intended to identify potential unauthorized use of system peripherals in the context of an AI-agent session.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
000
Detects instances where a browser process (chrome.exe) accesses the microphone or camera within a 2-minute temporal window of communicating with 'gemini.google.com'. This rule is intended to identify potential unauthorized use of system peripherals in the context of an AI-agent session.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
000
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
avatar
Arnold Chan@slaz
Defender - KQL
22 days ago
000
Detects the 'Comet.exe' process, associated with the Perplexity Comet AI agent, accessing sensitive system files or configuration directories outside its expected scope. This pattern of file interaction is characteristic of unauthorized data collection or exfiltration attempts, specifically linked to the BragJack threat activity.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
000
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
000
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
000
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
000
This rule detects network communication, email interaction, or identity logon events related to known spoofed IC3 (Internet Crime Complaint Center) domains used in business email compromise (BEC) campaigns. The detection covers multiple telemetry sources including email URL information, device network events, and identity logon logs to identify attempts to interact with fraudulent portals.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
27 days ago
002
This rule detects network communication, email interaction, or identity logon events related to known spoofed IC3 (Internet Crime Complaint Center) domains used in business email compromise (BEC) campaigns. The detection covers multiple telemetry sources including email URL information, device network events, and identity logon logs to identify attempts to interact with fraudulent portals.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
27 days ago
002
This rule monitors for file and process events involving 'pubspec.yaml' configuration files or specific Flutter-related components such as 'universal_file_viewer' and 'surveyjs_flutter'. This detection logic is designed to track development activities or the inclusion of specific software packages within a Flutter project environment.
avatar
Nate Dunning@nateossprey
avatar
Ossprey Open Source Supply Chain Detections
30 days ago
105
This rule detects the use of the 7-Zip utility (7z.exe) located in 'C:\Users\Public\Documents\' to archive files, specifically monitoring for the creation of an archive file named 'p.7z' within the same directory. This pattern of staging files and using an archive utility in public, writeable directories is a common behavior observed in adversary data exfiltration preparation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
001
Detects the loading or execution of 'core.dll' from non-standard system directories by common Windows proxy execution binaries (rundll32.exe, regsvr32.exe, cmd.exe, powershell.exe), which is a common indicator of DLL side-loading or malicious library hijacking.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
25 days ago
001
Detects the placement of potentially malicious executable or script files onto a network share followed by the execution of that specific file path from a different host within a short timeframe. This behavior is indicative of lateral movement using tainted shared content.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
106
This rule detects potential lateral movement by identifying suspicious child processes (such as cmd, powershell, or rundll32) spawned by WmiPrvSE.exe shortly after a remote interactive or network logon on the same device.
avatar
Arnold Chan@slaz
Defender - KQL
28 days ago
003
Page 360 of 1870