Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

7 detections

Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
1 month ago
002
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
avatar
Hunters
26 days ago
000
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
1 month ago
001
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
Defender - KQL
1 month ago
000
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
1 month ago
000
This rule detects the presence of GRE (Generic Routing Encapsulation) tunnel traffic (IP protocol 47) originating from any source IP address to the local network. It triggers an alert if three such GRE packets are observed from the same source within a 60-second window. This could indicate an attempt to establish a GRE tunnel, potentially for defense evasion or to bypass network security controls.
avatar
Darshan Thummar@Mighty
avatar
Detections.ai Community
4 months ago
006
This query helps you design client firewall rules based on data stored within DeviceNetworkEvents. Folder paths are alias'ed to help represent the
files making or receiving network connections without dealing with duplication from path variance due to different root drive letter or user profile
association.
To make the report easy to read, inbound remote IP addresses are not calculated by default (this can be changed by setting the value of IncludeInboundRemoteIPs to true).
Also, the ephemeral range is defaulted to 49152 to help eliminate false detections.
Azure Sentinel@AzureSentinel
avatar
AzureSentinel
1 year ago
1089