Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,252 detections

Detects a suspicious sequence of browser navigation/redirection events followed shortly by the manual execution of command-line utilities (PowerShell, CMD, or MSHTA) via explorer.exe, characteristic of 'ClickFix' social engineering attacks where users are tricked into copying and executing commands from their clipboard.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a single account requesting an abnormally high number of distinct Kerberos TGS (Ticket Granting Service) tickets for SPN-mapped accounts within a 15-minute window. This behavior is indicative of Kerberoasting, where an attacker requests service tickets to perform offline brute-force cracking of service account passwords, often used for lateral movement.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the registration or installation of an MCP (Model Context Protocol) server or agent tool containing suspicious prompt-injection strings (e.g., instructions to ignore safety guardrails or role overrides), immediately followed by the execution of shell commands or unauthorized network connections originating from that tool.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
202
Detects unauthorized modifications to AI agent configuration files, including system prompts, tool allow-lists, and MCP server registration files. Such changes are often performed by processes outside of approved configuration management or infrastructure-as-code pipelines, potentially allowing for persistent manipulation of AI model behavior and capabilities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a suspicious sequence of events where a user or system initiates a PowerShell script (update1.ps1) via Windows Explorer in close temporal proximity (within 5 minutes) to the execution of known update-related tasks or scripts (OneDriveUpdateScheduler or update1.vbs). This correlation aims to identify potential persistence or malicious activity masquerading as update processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
004
Detects the invocation of Windows Subsystem for Linux (WSL) binaries (wsl.exe or wslconfig.exe) using command-line arguments that enable arbitrary command execution, such as -e, --exec, or shell interpreters (bash -c, sh -c), or web-based retrieval tools like curl/wget. This technique is often used to execute commands or download payloads within a Linux environment on Windows, potentially bypassing security controls focused on native Windows processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
203
This rule detects the loading of known-vulnerable or malicious kernel drivers (BYOVD) followed by the termination of major EDR or security-related processes on the same host within a 10-minute window. This behavior is indicative of an adversary attempting to disable security controls to evade detection after achieving kernel-level privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
003
Detects a two-stage activity: first, the potential unauthorized reading or access of LLM provider API keys from files, environment variables, or command-line arguments; and second, the subsequent use of those same credentials to authenticate to LLM provider APIs (OpenAI, Anthropic, Azure, Bedrock) from a different, unrecognized source IP address, indicating potential credential theft and session hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
This rule detects interactive or user-triggered execution of PowerShell carrying indicators of payload downloading, inline evaluation, or Base64 encoding. Because explorer.exe is the parent process, it typically signifies a payload delivered via email/web that a user opened directly such as an .lnk shortcut.
avatar
Kaung Khant Ko@kaungkhantko
avatar
Hunters
16 days ago
104
Detects the installation of Windows services (Event ID 4697 or 7045) where the service binary path points to command interpreters (PowerShell, cmd.exe) or suspicious directories such as Temp, user profile paths, or file extensions associated with scripts (.ps1, .vbs, .bat). This behavior is often indicative of persistence mechanisms or lateral movement attempts where an attacker attempts to execute arbitrary code via a service.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
17 days ago
405
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Hunters
15 days ago
103
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
003
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
15 days ago
003
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
avatar
Arnold Chan@slaz
Defender - KQL
16 days ago
004
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
004
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
avatar
Arnold Chan@slaz
avatar
Hunters
16 days ago
104
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
16 days ago
004
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
13 days ago
102
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
This rule detects known malicious activity including network connections to a specific C2 IP address (69.48.229.140), downloading files from specific C2 URLs, the presence of known malicious file hashes (SHA256), and communications involving specific actor-associated email addresses.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Page 96 of 1870