Detection coverage

What SecAI detects, and what it does about it

Every detection the agent and the platform make, derived from the detector modules in the agent and the response policy in the platform. Each row names its signal, its response, and the source it was read from. Last reviewed 20 September 2026.

43
detections
6
can act on their own (Automatic mode)
4
propose an action that waits for approval
32
report with evidence only
19
mapped to a MITRE ATT&CK technique

How to read this page

Response says what happens after the detection. Exactly one action ever runs without a person: blocking an address identified as attacking the server, and only on a server set to Automatic; those rows are marked automatic. Rows marked approval propose an action that waits for you. Rows marked protect are survival mode, which every server starts with switched to record only. Everything else is reported with its evidence and no action is proposed.

MITRE ATT&CK is filled only where a detection maps to one technique without argument. Most rows are empty on purpose: a suspicious process or a changed configuration file can belong to many techniques, and a table that guesses is worth less than one that does not. Nothing here is a coverage score.

Authentication

DetectionSignalResponseMITRE ATT&CKSystemsSource
SSH brute forceFailed logins per source address from the authentication log; three sightings within thirty minutesautomatic
Automatic block (Automatic mode); waits in Awaiting Approval. Block the address through the host firewall; expires after 24h.
T1110.001 Brute Force: Password Guessing
All supported Linuxssh_monitor.rs, services/ip_safety.py
SSH login success after failures, or from a new sourceSuccessful login with username, source and method, correlated with prior failuresalert
Reported with evidence; no action proposed
—All supported Linuxssh_monitor.rs
Root login over SSHA successful root sessionalert
Reported with evidence; no action proposed. Hardening fix to disable root login is proposable.
—All supported Linuxssh_monitor.rs, hardening.rs
Privilege change outside any administrator sessionA new account, sudo grant or key with no interactive session behind italert
Reported with evidence; no action proposed
—All supported Linuxadmin_session.rs

Accounts and privilege

DetectionSignalResponseMITRE ATT&CKSystemsSource
New local user account/etc/passwd change, attributed to the package or session that created italert
Reported with evidence; no action proposed. Disable account is proposable; always waits for a person.
T1136.001 Create Account: Local Account
All supported Linuxpriv_esc.rs, account_origin.rs
New SSH authorized keyauthorized_keys change with the key fingerprint and commentalert
Reported with evidence; no action proposed
T1098.004 Account Manipulation: SSH Authorized Keys
All supported Linuxpriv_esc.rs, file_integrity.rs
Sudo grant added or sudoers changedsudoers and sudoers.d changes with the text before and afteralert
Reported with evidence; no action proposed
T1548.003 Abuse Elevation Control Mechanism: Sudo and Sudo Caching
All supported Linuxpriv_esc.rs, file_integrity.rs
New or changed setuid, setgid or capability binaryPrivileged binaries in system directories; cleared when dpkg -V or rpm -V vouches for the filealert
Reported with evidence; no action proposed
T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid
All supported Linuxpriv_esc.rs
Account with an empty password/etc/shadow read for a yes/no onlyalert
Reported with evidence; no action proposed
—All supported Linuxpriv_esc.rs

Persistence

DetectionSignalResponseMITRE ATT&CKSystemsSource
Cron entry added or changed/etc/crontab, /etc/cron.d, per-user crontabs, with the text before and afteralert
Reported with evidence; no action proposed
T1053.003 Scheduled Task/Job: Cron
All supported Linuxfile_integrity.rs
Systemd service or timer added or changed/etc/systemd/system units, with the text before and afteralert
Reported with evidence; no action proposed
T1543.002 Create or Modify System Process: Systemd Service
All supported Linuxfile_integrity.rs
Authentication database or PAM changepasswd, shadow, group, gshadow, pam.d, nsswitch.conf, hosts: hash before and afteralert
Reported with evidence; no action proposed
—All supported Linuxfile_integrity.rs
SSH daemon configuration changesshd_config and sshd_config.d: hash before and after; effective settings via sshd -Talert
Reported with evidence; no action proposed. Hardening fixes proposable for weak settings.
—All supported Linuxfile_integrity.rs, hardening.rs
SecAI agent unit tampered withThe agent's own systemd unit: text before and after any editalert
Reported with evidence; no action proposed
T1562.001 Impair Defenses: Disable or Modify Tools
All supported Linuxfile_integrity.rs

Rootkit-style

DetectionSignalResponseMITRE ATT&CKSystemsSource
Hidden processThe process table and the kernel disagree about what existsalert
Reported with evidence; no action proposed
T1014 Rootkit
All supported Linuxrootkit.rs
Hidden network connectionA connection the process table cannot account foralert
Reported with evidence; no action proposed
T1014 Rootkit
All supported Linuxrootkit.rs
ld.so.preload entry/etc/ld.so.preload present or changedalert
Reported with evidence; no action proposed
T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking
All supported Linuxrootkit.rs
Kernel module appearedLoaded modules compared with the baselinealert
Reported with evidence; no action proposed
T1547.006 Boot or Logon Autostart Execution: Kernel Modules and Extensions
All supported Linuxrootkit.rs
File made immutableImmutable attribute on a system filealert
Reported with evidence; no action proposed
T1222.002 File and Directory Permissions Modification: Linux and Mac
All supported Linuxrootkit.rs

Processes

DetectionSignalResponseMITRE ATT&CKSystemsSource
Process running from a world-writable temp directoryAny process whose executable resolves into /tmp, /var/tmp, /dev/shm or /run/shm, whether or not the file has since been deleted: PID, path, command line. A deleted binary elsewhere is not flagged, because package upgrades cause that constantlyalert
Reported with evidence; no action proposed
—All supported Linuxproc_monitor.rs
Cryptominer signatures in files and schedulesMiner markers (stratum+tcp://, xmrig, cryptonight) in PHP files and shell scripts under web roots, and a new cron line that runs a known minerapproval
Proposed; waits for approval. Quarantine of the file is proposable; never pre-approved.
T1496 Resource Hijacking
All supported Linux; file scanning on Pro and abovewebshell.rs, services/cron_diff.py
Sustained high CPU, memory or outbound data volumeA metric above the server's own baseline for five consecutive reports; the finding closes itself after five calm onesalert
Reported with evidence; no action proposed. Under Protect, a process group exhausting the server may be throttled or frozen, never killed.
—All supported Linuxapi/routers/agents.py, services/anomaly_lifecycle.py

Web

DetectionSignalResponseMITRE ATT&CKSystemsSource
Web shell candidateA PHP file in a web root matching a web-shell or reverse-shell signature, or recently modified: path, signature, size, SHA-256, first 200 bytes, screened automatically before it becomes a findingapproval
Proposed; waits for approval. Quarantine (mode 000 in place); never pre-approved; restore never needs approval.
T1505.003 Server Software Component: Web Shell
Servers hosting websiteswebshell.rs, services/quarantine.py
Web root file changeHash before and after for served directories, including WordPress core, plugins and themesalert
Reported with evidence; no action proposed
—Servers hosting websites; WordPress integrity on Pro and abovefile_integrity.rs, wordpress.rs
Vulnerability scanner probingScanner signatures in web server and control panel access logsautomatic
Automatic block (Automatic mode); waits in Awaiting Approval. Block the source address; expires after 24h.
T1595.002 Active Scanning: Vulnerability Scanning
nginx, Apache, Caddy, cPanel, Plesk, DirectAdminweb_monitor.rs
Web attack attemptsInjection and traversal patterns in access logs, attributed to the site they targetedalert
Reported with evidence; no action proposed
—Servers with a web server or control panelweb_monitor.rs
WordPress login brute forceRepeated wp-login and XML-RPC attempts per sourceautomatic
Automatic block (Automatic mode); waits in Awaiting Approval. Block the source address; expires after 24h.
T1110 Brute Force
Servers hosting WordPressweb_monitor.rs, wordpress.rs
Website content drift (monitored sites)Page fingerprint change: title, redirects, hidden links, outbound domains, lexicon hits; cloaking check against a search-engine user agentalert
Reported with evidence; no action proposed
—Monitored websites (Pro and above)services/page_watch.py
Website outage and certificate expiryHTTP checks from outside and from the host; TLS certificate as servedalert
Reported with evidence; no action proposed
—Monitored websites (Pro and above)services/website_monitor.py

Network

DetectionSignalResponseMITRE ATT&CKSystemsSource
New outbound destinationAn outbound connection to an address the server has not spoken to before, with port and owning processalert
Reported with evidence; no action proposed
—All supported Linuxegress.rs
SYN floodSYN backlog and SYN-cookie counters from the kernel; conntrackautomatic
Automatic block (Automatic mode); waits in Awaiting Approval. Block the source where a source is identifiable; a flooding source may be dropped under Protect.
T1498.001 Network Denial of Service: Direct Network Flood
All supported Linuxnetwork_flood.rs, ladder.rs
HTTP floodRequest rate per source from access logs and connection stateautomatic
Automatic block (Automatic mode); waits in Awaiting Approval. Block the source address; expires after 24h.
T1499.002 Endpoint Denial of Service: Service Exhaustion Flood
Servers with a web server or control panelweb_monitor.rs, network_flood.rs
Connection exhaustionConnection counters and conntrack saturation, with the source where one is identifiableautomatic
Automatic block (Automatic mode); waits in Awaiting Approval. Block the source address; expires after 24h.
—All supported Linuxnetwork_flood.rs
UDP floodUDP counters from the kernelalert
Reported with evidence; no action proposed. A flooding source may be dropped under Protect.
—All supported Linuxnetwork_flood.rs, ladder.rs
Local resource exhaustion (fork bomb, memory, descriptors, CPU)Per-second pressure, memory, OOM, fork, descriptor and socket countersprotect
Survival mode, Protect only; undone when the episode ends. Cap, throttle or freeze the one responsible process group; never init, SSH, the agent, a database, a web server, a panel or a login session.
—All supported Linux (record only by default)blackbox.rs, ladder.rs

Packages

DetectionSignalResponseMITRE ATT&CKSystemsSource
Vulnerable package (CVE)Installed packages matched against OSV.dev every twelve hours; CVE, severity, fixed versionapproval
Proposed; waits for approval. Package update proposable; waits for approval.
—Ubuntu, Debian, Alpine, Rocky Linux, AlmaLinux (Red Hat Enterprise Linux itself is not matched)packages.rs, services/vulnerability_scan.py
End-of-life PHPInstalled PHP major.minor past its end of lifealert
Reported with evidence; no action proposed
—Servers with PHPservices/severity_policy.py

Posture

DetectionSignalResponseMITRE ATT&CKSystemsSource
Weak SSH configurationEffective sshd -T settings: password authentication, root login, and othersapproval
Proposed; waits for approval. Hardening fix proposable, applied with a copy for undo.
—All supported Linuxhardening.rs
Firewall inactive, pending security updates, disk pressure, failed units, clock drift, backupsPosture report each cyclealert
Reported with evidence; no action proposed. Hardening fixes proposable where one exists.
—All supported Linuxposture.rs, hardening.rs
Exposed services and server hygieneListening sockets reachable from the internet; web-root hygiene; abuse exposure: Tor relays and onion services, open mail relays, open DNS recursion (configuration read, nothing sent)alert
Reported with evidence; no action proposed. Hardening fixes proposable where one exists.
—All supported Linuxhygiene.rs, posture.rs
Certificate expiring or mismatched, as visitors see itThe served certificate read by TLS handshake; Cloudflare-fronted sites rated by what the edge servesalert
Reported with evidence; no action proposed
—Servers hosting TLS sitesposture.rs, services/served_certificates

Agent health

DetectionSignalResponseMITRE ATT&CKSystemsSource
Agent offline, restart loop, or stop signal receivedMissing telemetry; thin telemetry hours; stopping beaconsalert
Reported with evidence; no action proposed
—All supported Linuxservices/agent_health.py
Attack while unreachableThe agent's survival record, delivered when the link returns: what happened, and which silence it was (backend unreachable, link down, DNS, flooded)alert
Reported with evidence; no action proposed
—All supported Linuxlink.rs, services/survival_report.py

What is not on this page

  • Network packet inspection. The agent reads the kernel's connection tables, never packet contents.
  • Web application firewall rules. Web attacks are read from access logs and attributed; requests are not inspected in flight.
  • Volumetric DDoS. A saturated link is reported as saturated; the mitigation is upstream.
  • Signature antivirus. There is no signature database; the web-shell rules flag files for screening, they do not convict.
  • Anything inside containers. The host's view of a container is what is monitored.

Read next

See the findings on a server of yours

Start with the free, read-only assessment; the agent's first report shows which of these rows apply to your server.