Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a suspicious sequence of browser navigation/redirection events followed shortly by the manual execution of command-line utilities (PowerShell, CMD, or MSHTA) via explorer.exe, characteristic of 'ClickFix' social engineering attacks where users are tricked into copying and executing commands from their clipboard.
Detects a single account requesting an abnormally high number of distinct Kerberos TGS (Ticket Granting Service) tickets for SPN-mapped accounts within a 15-minute window. This behavior is indicative of Kerberoasting, where an attacker requests service tickets to perform offline brute-force cracking of service account passwords, often used for lateral movement.
Detects the registration or installation of an MCP (Model Context Protocol) server or agent tool containing suspicious prompt-injection strings (e.g., instructions to ignore safety guardrails or role overrides), immediately followed by the execution of shell commands or unauthorized network connections originating from that tool.
Detects unauthorized modifications to AI agent configuration files, including system prompts, tool allow-lists, and MCP server registration files. Such changes are often performed by processes outside of approved configuration management or infrastructure-as-code pipelines, potentially allowing for persistent manipulation of AI model behavior and capabilities.
Detects a suspicious sequence of events where a user or system initiates a PowerShell script (update1.ps1) via Windows Explorer in close temporal proximity (within 5 minutes) to the execution of known update-related tasks or scripts (OneDriveUpdateScheduler or update1.vbs). This correlation aims to identify potential persistence or malicious activity masquerading as update processes.
Detects the invocation of Windows Subsystem for Linux (WSL) binaries (wsl.exe or wslconfig.exe) using command-line arguments that enable arbitrary command execution, such as -e, --exec, or shell interpreters (bash -c, sh -c), or web-based retrieval tools like curl/wget. This technique is often used to execute commands or download payloads within a Linux environment on Windows, potentially bypassing security controls focused on native Windows processes.
This rule detects the loading of known-vulnerable or malicious kernel drivers (BYOVD) followed by the termination of major EDR or security-related processes on the same host within a 10-minute window. This behavior is indicative of an adversary attempting to disable security controls to evade detection after achieving kernel-level privileges.
Detects a two-stage activity: first, the potential unauthorized reading or access of LLM provider API keys from files, environment variables, or command-line arguments; and second, the subsequent use of those same credentials to authenticate to LLM provider APIs (OpenAI, Anthropic, Azure, Bedrock) from a different, unrecognized source IP address, indicating potential credential theft and session hijacking.
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
This rule detects interactive or user-triggered execution of PowerShell carrying indicators of payload downloading, inline evaluation, or Base64 encoding. Because explorer.exe is the parent process, it typically signifies a payload delivered via email/web that a user opened directly such as an .lnk shortcut.
Detects the installation of Windows services (Event ID 4697 or 7045) where the service binary path points to command interpreters (PowerShell, cmd.exe) or suspicious directories such as Temp, user profile paths, or file extensions associated with scripts (.ps1, .vbs, .bat). This behavior is often indicative of persistence mechanisms or lateral movement attempts where an attacker attempts to execute arbitrary code via a service.
Detects rapid, multi-category reconnaissance activity initiated by AI-agent binaries (e.g., Claude, Cursor, ChatGPT). The rule identifies sessions that perform four or more distinct discovery operations—spanning account, network service, system information, and network configuration discovery—within a short time window, indicating potentially malicious autonomous exploration by an AI agent. Covers T1046, T1087, T1083, T1016
Detects a multi-stage attack chain where an AI-agent's configuration file (e.g., mcp.json) is modified, followed immediately by the execution of a tool process (node/python) spawned by the agent, the subsequent spawning of a shell process, and finally an outbound network connection to a rare, non-standard domain. This sequence is indicative of AI agent tool poisoning, where malicious tool definitions are introduced to execute arbitrary commands and exfiltrate data. Coverts T1195.002, T1565.001, T1059
Detects anomalous behavioral patterns where an AI agent process (e.g., Claude Code, Cursor, Aider) performs multi-category discovery of its own runtime environment, plugins, and host configuration. The rule identifies agents that trigger processes spanning at least three distinct discovery categories (Network, File/Plugin, Software, or System) within a short timeframe, indicating potential reconnaissance of agent-authorized capabilities and tools rather than standard host exploration. Covers T1082, T1518, T1083, T1016
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
Detects high or medium severity security alerts related to Kerberos Golden Ticket forgery, as identified by Microsoft Defender for Identity. This rule filters for specific alert names indicative of forged TGTs minted from the krbtgt account, excluding generic or informational ticket anomalies.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Detects a sequence of activity characteristic of lateral movement and credential theft: the deployment or execution of PsExec service followed by the use of Windows utilities (vssadmin, ntdsutil, esentutl) to perform Volume Shadow Copy-based extraction of the NTDS.dit database or SYSTEM hive on the same host.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
This rule detects known malicious activity including network connections to a specific C2 IP address (69.48.229.140), downloading files from specific C2 URLs, the presence of known malicious file hashes (SHA256), and communications involving specific actor-associated email addresses.
Page 96 of 1870



