avatar

Goksel Atakan

@gokselatakan
IstanbulTrusted contributorCompletionist
0 followers8 downloads348 copies9 likes688 views

45 detections

This takes the earliest available snapshot per agent instead of comparing two states. If an agent is born already carrying MCP access and org-wide sharing there is no baseline to drift from, so this needs its own check rather than a diff.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
29047
This rule detects potentially malicious modifications to agent configurations by monitoring for multiple significant changes within a short time frame (2 days) compared to a 14-day baseline. Monitored indicators include: changes to instructions, addition of new Model Context Protocol (MCP) servers, addition of new owners, and expansion of access permissions to include the entire organization. An alert is triggered when an agent exhibits at least two of these signals simultaneously.
The query builds a 14-day baseline snapshot and a 2-day current snapshot per agent from AgentsInfo, computes the four signals independently, then correlates them by AgentId and surfaces only agents with 2 or more signals firing in the same window. Output is a prioritized triage list instead of four separate alert streams.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
2 months ago
27038
This rule monitors for security alerts related to Azure AI services, specifically detecting credential theft attempts and LLM jailbreak attempts that have been blocked or detected by Azure's built-in content filtering mechanisms.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
3 months ago
6022
Lists all users who recently enabled Out-of-Office along with their latest sign-in activity. SOC analysts can reference this when triaging unfamiliar sign-in or impossible travel alerts to quickly determine if the user is on vacation.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
3 months ago
105
This rule detects anomalous or risky sign-in events for user accounts that have recently configured an active out-of-office (OOF) auto-reply. An attacker may leverage a user's known absence to gain access to their email or other corporate resources using compromised credentials, as the user is less likely to notice suspicious account activity while away.
avatar
Goksel Atakan@gokselatakan
avatar
Detections.ai Community
3 months ago
205