Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

This rule monitors package installation logs for indicators of packages potentially generated or suggested by AI tools (e.g., Copilot, code assistants) being installed in a target environment. It specifically looks for a low volume of installations (<=3) for packages that have been published within the last 14 days, which is a pattern often associated with the 'Publish Hallucinated Entities' technique in AI systems, where malicious or hallucinated code packages are introduced into the supply chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
This rule monitors package installation logs for indicators of packages potentially generated or suggested by AI tools (e.g., Copilot, code assistants) being installed in a target environment. It specifically looks for a low volume of installations (<=3) for packages that have been published within the last 14 days, which is a pattern often associated with the 'Publish Hallucinated Entities' technique in AI systems, where malicious or hallucinated code packages are introduced into the supply chain.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000