Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
Detects a suspicious execution sequence associated with the SectopRAT loader. The rule monitors for ReportDump.exe being launched from a ProgramData directory by common scheduling or service host processes, followed immediately by the loading of a malicious sdkcra.dll library.
Detects anomalous, bulk file access activity targeting browser credential databases, cryptocurrency wallet data, and application-specific configuration stores, characteristic of the SectopRAT 'DeployBrowserKey' command.
Detects outbound network connections to known SectopRAT C2 infrastructure, specifically targeting the hardcoded IP 98.142.252.140 or the non-standard port 15847 often used for encrypted exfiltration.
Detects the specific command-line sequence used by SectopRAT for self-deletion. The malware uses 'choice' to create a delay followed by a 'del' command to remove its own executable, a technique for deleting files after the process has terminated.
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
This rule detects the suspicious pattern of a process reading a 'pool.db' file followed immediately by the loading of .NET Common Language Runtime (CLR) modules (clr.dll or mscoreei.dll). This behavior is characteristic of fileless execution chains where a secondary payload is retrieved and executed directly in memory.
Detects the SectopRAT shellcode execution stage by identifying the concurrent access of a specific encrypted database file (Activation.Desktop.db) and the loading of a malicious DLL (stp_aim_x64_vc15.dll) on the same device within a 5-minute window. This behavior suggests the decryption and execution of shellcode via DLL callback abuse.
Detects the ReportDump.exe process initiating a network connection on port 15847 followed by the loading of GDI/User32 libraries shortly thereafter. This behavior is indicative of SectopRAT establishing a command-and-control channel and initializing screen capture capabilities.
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
Detects instances where common AI agent orchestration runtimes (e.g., LangChain, AutoGPT, CrewAI) spawn command-line or scripting interpreters as child processes. This behavior is highly suspicious and often indicative of malicious command execution triggered by prompt injection attacks, where an adversary manipulates the agent into executing arbitrary system commands.
This rule detects the installation of common AI agent and orchestration frameworks (e.g., LangChain, AutoGen, CrewAI) using command-line package managers (pip, npm, conda) that point to non-standard or unverified package indexes. This behavior is a common indicator of a potential software supply-chain compromise, where an adversary attempts to inject malicious code by forcing the installation of packages from an attacker-controlled source.
Detects command-line operations indicative of bulk data export, dumping, or unauthorized scanning against vector databases (e.g., Pinecone, Chroma, Milvus, Qdrant) and caching backends (e.g., Redis). Such activities may indicate an adversary attempting to exfiltrate training data, embeddings, or context stored within an AI agent's memory backend.
Detects scenarios where common download utilities are used to fetch a file from the internet, followed by the immediate execution or loading of that same file within a 10-minute window, indicative of an Ingress Tool Transfer followed by execution.
This rule detects automated browser-based processes (such as chromedriver, msedgedriver, geckodriver, playwright, or node/python scripts leveraging browser automation frameworks) initiating network connections to domains or URLs identified in active threat intelligence as malicious. This behavior is indicative of an AI agent or automated script being steered toward attacker-controlled infrastructure, potentially for drive-by compromise or exploitation.
Detects DNS query activity from processes commonly used as AI agent runtimes (e.g., python.exe, node.exe) toward domains characterized by DGA-like patterns, such as long alphanumeric strings or high-consonant density, which may indicate command-and-control communication.
Detects successful remote authentication events (Network or Interactive) performed by AI agent orchestration service accounts. This rule monitors for atypical lateral movement patterns where an automated service account pivots to remote hosts using protocols such as RDP or WinRM, diverging from its standard operational context.
Detects a burst of file delete or overwrite operations initiated by a configured AI agent service identity. This behavior, if deviating from established baselines, may indicate a compromised agent performing malicious destructive activities such as mass data deletion or ransomware-style file destruction.
Detects attempts to inject code into an AI agent orchestrator process by monitoring for suspicious CreateRemoteThread events. This rule is designed to identify potential process hijacking attacks by malicious actors seeking to bypass application-layer controls, while excluding common legitimate security monitoring tools that may exhibit similar behavior.
Page 92 of 1870


