What SecAI detects, and what it does about it
Every detection the agent and the platform make, derived from the detector modules in the agent and the response policy in the platform. Each row names its signal, its response, and the source it was read from. Last reviewed 20 September 2026.
How to read this page
Response says what happens after the detection. Exactly one action ever runs without a person: blocking an address identified as attacking the server, and only on a server set to Automatic; those rows are marked automatic. Rows marked approval propose an action that waits for you. Rows marked protect are survival mode, which every server starts with switched to record only. Everything else is reported with its evidence and no action is proposed.
MITRE ATT&CK is filled only where a detection maps to one technique without argument. Most rows are empty on purpose: a suspicious process or a changed configuration file can belong to many techniques, and a table that guesses is worth less than one that does not. Nothing here is a coverage score.
Authentication
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| SSH brute force | Failed logins per source address from the authentication log; three sightings within thirty minutes | automatic Automatic block (Automatic mode); waits in Awaiting Approval. Block the address through the host firewall; expires after 24h. | T1110.001 Brute Force: Password Guessing | All supported Linux | ssh_monitor.rs, services/ip_safety.py |
| SSH login success after failures, or from a new source | Successful login with username, source and method, correlated with prior failures | alert Reported with evidence; no action proposed | — | All supported Linux | ssh_monitor.rs |
| Root login over SSH | A successful root session | alert Reported with evidence; no action proposed. Hardening fix to disable root login is proposable. | — | All supported Linux | ssh_monitor.rs, hardening.rs |
| Privilege change outside any administrator session | A new account, sudo grant or key with no interactive session behind it | alert Reported with evidence; no action proposed | — | All supported Linux | admin_session.rs |
Accounts and privilege
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| New local user account | /etc/passwd change, attributed to the package or session that created it | alert Reported with evidence; no action proposed. Disable account is proposable; always waits for a person. | T1136.001 Create Account: Local Account | All supported Linux | priv_esc.rs, account_origin.rs |
| New SSH authorized key | authorized_keys change with the key fingerprint and comment | alert Reported with evidence; no action proposed | T1098.004 Account Manipulation: SSH Authorized Keys | All supported Linux | priv_esc.rs, file_integrity.rs |
| Sudo grant added or sudoers changed | sudoers and sudoers.d changes with the text before and after | alert Reported with evidence; no action proposed | T1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo Caching | All supported Linux | priv_esc.rs, file_integrity.rs |
| New or changed setuid, setgid or capability binary | Privileged binaries in system directories; cleared when dpkg -V or rpm -V vouches for the file | alert Reported with evidence; no action proposed | T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid | All supported Linux | priv_esc.rs |
| Account with an empty password | /etc/shadow read for a yes/no only | alert Reported with evidence; no action proposed | — | All supported Linux | priv_esc.rs |
Persistence
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| Cron entry added or changed | /etc/crontab, /etc/cron.d, per-user crontabs, with the text before and after | alert Reported with evidence; no action proposed | T1053.003 Scheduled Task/Job: Cron | All supported Linux | file_integrity.rs |
| Systemd service or timer added or changed | /etc/systemd/system units, with the text before and after | alert Reported with evidence; no action proposed | T1543.002 Create or Modify System Process: Systemd Service | All supported Linux | file_integrity.rs |
| Authentication database or PAM change | passwd, shadow, group, gshadow, pam.d, nsswitch.conf, hosts: hash before and after | alert Reported with evidence; no action proposed | — | All supported Linux | file_integrity.rs |
| SSH daemon configuration change | sshd_config and sshd_config.d: hash before and after; effective settings via sshd -T | alert Reported with evidence; no action proposed. Hardening fixes proposable for weak settings. | — | All supported Linux | file_integrity.rs, hardening.rs |
| SecAI agent unit tampered with | The agent's own systemd unit: text before and after any edit | alert Reported with evidence; no action proposed | T1562.001 Impair Defenses: Disable or Modify Tools | All supported Linux | file_integrity.rs |
Rootkit-style
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| Hidden process | The process table and the kernel disagree about what exists | alert Reported with evidence; no action proposed | T1014 Rootkit | All supported Linux | rootkit.rs |
| Hidden network connection | A connection the process table cannot account for | alert Reported with evidence; no action proposed | T1014 Rootkit | All supported Linux | rootkit.rs |
| ld.so.preload entry | /etc/ld.so.preload present or changed | alert Reported with evidence; no action proposed | T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking | All supported Linux | rootkit.rs |
| Kernel module appeared | Loaded modules compared with the baseline | alert Reported with evidence; no action proposed | T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions | All supported Linux | rootkit.rs |
| File made immutable | Immutable attribute on a system file | alert Reported with evidence; no action proposed | T1222.002 File and Directory Permissions Modification: Linux and Mac | All supported Linux | rootkit.rs |
Processes
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| Process running from a world-writable temp directory | Any process whose executable resolves into /tmp, /var/tmp, /dev/shm or /run/shm, whether or not the file has since been deleted: PID, path, command line. A deleted binary elsewhere is not flagged, because package upgrades cause that constantly | alert Reported with evidence; no action proposed | — | All supported Linux | proc_monitor.rs |
| Cryptominer signatures in files and schedules | Miner markers (stratum+tcp://, xmrig, cryptonight) in PHP files and shell scripts under web roots, and a new cron line that runs a known miner | approval Proposed; waits for approval. Quarantine of the file is proposable; never pre-approved. | T1496 Resource Hijacking | All supported Linux; file scanning on Pro and above | webshell.rs, services/cron_diff.py |
| Sustained high CPU, memory or outbound data volume | A metric above the server's own baseline for five consecutive reports; the finding closes itself after five calm ones | alert Reported with evidence; no action proposed. Under Protect, a process group exhausting the server may be throttled or frozen, never killed. | — | All supported Linux | api/routers/agents.py, services/anomaly_lifecycle.py |
Web
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| Web shell candidate | A PHP file in a web root matching a web-shell or reverse-shell signature, or recently modified: path, signature, size, SHA-256, first 200 bytes, screened automatically before it becomes a finding | approval Proposed; waits for approval. Quarantine (mode 000 in place); never pre-approved; restore never needs approval. | T1505.003 Server Software Component: Web Shell | Servers hosting websites | webshell.rs, services/quarantine.py |
| Web root file change | Hash before and after for served directories, including WordPress core, plugins and themes | alert Reported with evidence; no action proposed | — | Servers hosting websites; WordPress integrity on Pro and above | file_integrity.rs, wordpress.rs |
| Vulnerability scanner probing | Scanner signatures in web server and control panel access logs | automatic Automatic block (Automatic mode); waits in Awaiting Approval. Block the source address; expires after 24h. | T1595.002 Active Scanning: Vulnerability Scanning | nginx, Apache, Caddy, cPanel, Plesk, DirectAdmin | web_monitor.rs |
| Web attack attempts | Injection and traversal patterns in access logs, attributed to the site they targeted | alert Reported with evidence; no action proposed | — | Servers with a web server or control panel | web_monitor.rs |
| WordPress login brute force | Repeated wp-login and XML-RPC attempts per source | automatic Automatic block (Automatic mode); waits in Awaiting Approval. Block the source address; expires after 24h. | T1110 Brute Force | Servers hosting WordPress | web_monitor.rs, wordpress.rs |
| Website content drift (monitored sites) | Page fingerprint change: title, redirects, hidden links, outbound domains, lexicon hits; cloaking check against a search-engine user agent | alert Reported with evidence; no action proposed | — | Monitored websites (Pro and above) | services/page_watch.py |
| Website outage and certificate expiry | HTTP checks from outside and from the host; TLS certificate as served | alert Reported with evidence; no action proposed | — | Monitored websites (Pro and above) | services/website_monitor.py |
Network
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| New outbound destination | An outbound connection to an address the server has not spoken to before, with port and owning process | alert Reported with evidence; no action proposed | — | All supported Linux | egress.rs |
| SYN flood | SYN backlog and SYN-cookie counters from the kernel; conntrack | automatic Automatic block (Automatic mode); waits in Awaiting Approval. Block the source where a source is identifiable; a flooding source may be dropped under Protect. | T1498.001 Network Denial of Service: Direct Network Flood | All supported Linux | network_flood.rs, ladder.rs |
| HTTP flood | Request rate per source from access logs and connection state | automatic Automatic block (Automatic mode); waits in Awaiting Approval. Block the source address; expires after 24h. | T1499.002 Endpoint Denial of Service: Service Exhaustion Flood | Servers with a web server or control panel | web_monitor.rs, network_flood.rs |
| Connection exhaustion | Connection counters and conntrack saturation, with the source where one is identifiable | automatic Automatic block (Automatic mode); waits in Awaiting Approval. Block the source address; expires after 24h. | — | All supported Linux | network_flood.rs |
| UDP flood | UDP counters from the kernel | alert Reported with evidence; no action proposed. A flooding source may be dropped under Protect. | — | All supported Linux | network_flood.rs, ladder.rs |
| Local resource exhaustion (fork bomb, memory, descriptors, CPU) | Per-second pressure, memory, OOM, fork, descriptor and socket counters | protect Survival mode, Protect only; undone when the episode ends. Cap, throttle or freeze the one responsible process group; never init, SSH, the agent, a database, a web server, a panel or a login session. | — | All supported Linux (record only by default) | blackbox.rs, ladder.rs |
Packages
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| Vulnerable package (CVE) | Installed packages matched against OSV.dev every twelve hours; CVE, severity, fixed version | approval Proposed; waits for approval. Package update proposable; waits for approval. | — | Ubuntu, Debian, Alpine, Rocky Linux, AlmaLinux (Red Hat Enterprise Linux itself is not matched) | packages.rs, services/vulnerability_scan.py |
| End-of-life PHP | Installed PHP major.minor past its end of life | alert Reported with evidence; no action proposed | — | Servers with PHP | services/severity_policy.py |
Posture
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| Weak SSH configuration | Effective sshd -T settings: password authentication, root login, and others | approval Proposed; waits for approval. Hardening fix proposable, applied with a copy for undo. | — | All supported Linux | hardening.rs |
| Firewall inactive, pending security updates, disk pressure, failed units, clock drift, backups | Posture report each cycle | alert Reported with evidence; no action proposed. Hardening fixes proposable where one exists. | — | All supported Linux | posture.rs, hardening.rs |
| Exposed services and server hygiene | Listening sockets reachable from the internet; web-root hygiene; abuse exposure: Tor relays and onion services, open mail relays, open DNS recursion (configuration read, nothing sent) | alert Reported with evidence; no action proposed. Hardening fixes proposable where one exists. | — | All supported Linux | hygiene.rs, posture.rs |
| Certificate expiring or mismatched, as visitors see it | The served certificate read by TLS handshake; Cloudflare-fronted sites rated by what the edge serves | alert Reported with evidence; no action proposed | — | Servers hosting TLS sites | posture.rs, services/served_certificates |
Agent health
| Detection | Signal | Response | MITRE ATT&CK | Systems | Source |
|---|---|---|---|---|---|
| Agent offline, restart loop, or stop signal received | Missing telemetry; thin telemetry hours; stopping beacons | alert Reported with evidence; no action proposed | — | All supported Linux | services/agent_health.py |
| Attack while unreachable | The agent's survival record, delivered when the link returns: what happened, and which silence it was (backend unreachable, link down, DNS, flooded) | alert Reported with evidence; no action proposed | — | All supported Linux | link.rs, services/survival_report.py |
What is not on this page
- Network packet inspection. The agent reads the kernel's connection tables, never packet contents.
- Web application firewall rules. Web attacks are read from access logs and attributed; requests are not inspected in flight.
- Volumetric DDoS. A saturated link is reported as saturated; the mitigation is upstream.
- Signature antivirus. There is no signature database; the web-shell rules flag files for screening, they do not convict.
- Anything inside containers. The host's view of a container is what is monitored.
Read next
See the findings on a server of yours
Start with the free, read-only assessment; the agent's first report shows which of these rows apply to your server.