
Goksel Atakan
@gokselatakanIstanbulTrusted contributorCompletionist
0 followers8 downloads348 copies9 likes688 views
45 detections
Filters
Last updated
All Time
Detection languages
36
9
Categories
13
8
8
7
6
Platforms
18
16
15
10
7
Products / Services
12
11
8
6
6
MITRE Techniques
22
12
7
6
6
CVEs
1
This takes the earliest available snapshot per agent instead of comparing two states. If an agent is born already carrying MCP access and org-wide sharing there is no baseline to drift from, so this needs its own check rather than a diff.
This rule detects potentially malicious modifications to agent configurations by monitoring for multiple significant changes within a short time frame (2 days) compared to a 14-day baseline. Monitored indicators include: changes to instructions, addition of new Model Context Protocol (MCP) servers, addition of new owners, and expansion of access permissions to include the entire organization. An alert is triggered when an agent exhibits at least two of these signals simultaneously.
The query builds a 14-day baseline snapshot and a 2-day current snapshot per agent from AgentsInfo, computes the four signals independently, then correlates them by AgentId and surfaces only agents with 2 or more signals firing in the same window. Output is a prioritized triage list instead of four separate alert streams.
The query builds a 14-day baseline snapshot and a 2-day current snapshot per agent from AgentsInfo, computes the four signals independently, then correlates them by AgentId and surfaces only agents with 2 or more signals firing in the same window. Output is a prioritized triage list instead of four separate alert streams.
This rule monitors for security alerts related to Azure AI services, specifically detecting credential theft attempts and LLM jailbreak attempts that have been blocked or detected by Azure's built-in content filtering mechanisms.
Lists all users who recently enabled Out-of-Office along with their latest sign-in activity. SOC analysts can reference this when triaging unfamiliar sign-in or impossible travel alerts to quickly determine if the user is on vacation.
This rule detects anomalous or risky sign-in events for user accounts that have recently configured an active out-of-office (OOF) auto-reply. An attacker may leverage a user's known absence to gain access to their email or other corporate resources using compromised credentials, as the user is less likely to notice suspicious account activity while away.
