Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
7 detections
Filters
Last updated
All Time
Detection languages
6
1
Contributors
5
1
1
Categories
5
5
1
1
1
Platforms
6
5
1
Products / Services
5
5
1
1
1
MITRE Techniques
17,957
15,455
12,307
8,184
6,031
IDS Classtypes
1
IDS Protocols
1
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
Detects command-line execution of tools (route, netsh, sysctl) intended to modify host routing tables or enable IP forwarding. Such activity on workstation endpoints may indicate an attempt to bridge network segments, bypass network security boundaries, or facilitate lateral movement/C2 communications.
This rule detects the presence of GRE (Generic Routing Encapsulation) tunnel traffic (IP protocol 47) originating from any source IP address to the local network. It triggers an alert if three such GRE packets are observed from the same source within a 60-second window. This could indicate an attempt to establish a GRE tunnel, potentially for defense evasion or to bypass network security controls.
This query helps you design client firewall rules based on data stored within DeviceNetworkEvents. Folder paths are alias'ed to help represent the
files making or receiving network connections without dealing with duplication from path variance due to different root drive letter or user profile
association.
To make the report easy to read, inbound remote IP addresses are not calculated by default (this can be changed by setting the value of IncludeInboundRemoteIPs to true).
Also, the ephemeral range is defaulted to 49152 to help eliminate false detections.
files making or receiving network connections without dealing with duplication from path variance due to different root drive letter or user profile
association.
To make the report easy to read, inbound remote IP addresses are not calculated by default (this can be changed by setting the value of IncludeInboundRemoteIPs to true).
Also, the ephemeral range is defaulted to 49152 to help eliminate false detections.

