Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects changes to federation settings on an Entra ID domain, including modifications to IssuerUri, ActiveLogOnUri, MetadataExchangeUri, or SigningCertificate, as well as transitions between Managed and Federated authentication types. Such changes can facilitate 'Golden SAML' attacks by allowing an adversary to forge authentication tokens for the tenant.
Detects the addition of a new federated domain or a modification to an existing domain's authentication settings to Federated, where the domain was not previously verified within a standard verification window. This technique is often used by adversaries to establish persistence and perform self-issued token forgery (e.g., SAML/JWT) by trusting an attacker-controlled identity provider.
Detects changes to federation settings on an Entra ID domain, including modifications to IssuerUri, ActiveLogOnUri, MetadataExchangeUri, or SigningCertificate, as well as transitions between Managed and Federated authentication types. Such changes can facilitate 'Golden SAML' attacks by allowing an adversary to forge authentication tokens for the tenant.
Detects the addition of a new federated domain or a modification to an existing domain's authentication settings to Federated, where the domain was not previously verified within a standard verification window. This technique is often used by adversaries to establish persistence and perform self-issued token forgery (e.g., SAML/JWT) by trusting an attacker-controlled identity provider.
Detects changes to federation settings on an Entra ID domain, including modifications to IssuerUri, ActiveLogOnUri, MetadataExchangeUri, or SigningCertificate, as well as transitions between Managed and Federated authentication types. Such changes can facilitate 'Golden SAML' attacks by allowing an adversary to forge authentication tokens for the tenant.
Detects when a user is added as an owner to an Azure AD Application or Service Principal, specifically highlighting instances where the new owner does not currently hold a privileged directory role. This pattern is often used as a persistence mechanism to maintain long-term access to an environment without requiring high-level administrative credentials.
Detects changes to federation settings on an Entra ID domain, including modifications to IssuerUri, ActiveLogOnUri, MetadataExchangeUri, or SigningCertificate, as well as transitions between Managed and Federated authentication types. Such changes can facilitate 'Golden SAML' attacks by allowing an adversary to forge authentication tokens for the tenant.
Detects when a user is added as an owner to an Azure AD Application or Service Principal, specifically highlighting instances where the new owner does not currently hold a privileged directory role. This pattern is often used as a persistence mechanism to maintain long-term access to an environment without requiring high-level administrative credentials.
Detects the creation or modification of federated identity credentials within Azure Active Directory (Entra ID). This technique allows external services like GitHub Actions, Kubernetes, or other identity providers to authenticate as an application without stored secrets, bypassing traditional secret-rotation and credential-scanning security controls. The rule identifies potential unauthorized persistence by highlighting external or unrecognized issuers.
Detects the creation or modification of federated identity credentials within Azure Active Directory (Entra ID). This technique allows external services like GitHub Actions, Kubernetes, or other identity providers to authenticate as an application without stored secrets, bypassing traditional secret-rotation and credential-scanning security controls. The rule identifies potential unauthorized persistence by highlighting external or unrecognized issuers.
Detects unauthorized modifications to Microsoft Entra Conditional Access (CA) policies, including deleting policies, disabling them, removing MFA requirements, or excluding specific users. These actions are common techniques used by adversaries to establish persistence or facilitate unauthorized access by weakening security controls.
Detects the addition of secrets or certificates to service principals by identities that are not currently registered as owners of those applications, or modifications occurring outside of standard business hours. This behavior is often indicative of an adversary with compromised administrative privileges (e.g., Application Administrator) attempting to establish persistent, lateral access without alerting legitimate application owners.
Detects the addition of a Service Principal to an Azure AD group that has the 'isAssignableToRole' property set to true. This behavior is a known privilege escalation technique where the service principal inherits the privileged roles assigned to that group, bypassing standard direct role-assignment monitoring.
Detects a potential Business Email Compromise (BEC) persistence chain where a user grants an OAuth application mail-read or mail-write permissions, followed by the creation of a malicious inbox rule designed to forward, move, or delete sensitive email threads. This combination enables persistent exfiltration and stealth, bypassing password resets as the OAuth token remains active.
This rule detects non-interactive sign-in events using AzureAD tokens from unmanaged devices. This pattern is indicative of potential session or refresh token hijacking, where an adversary replays a stolen session token from their own environment. While a single event is not definitive for impossible travel, it serves as a high-confidence seed for identifying compromised sessions when combined with other indicators.
Detects the configuration of cross-tenant access trust policies or cross-tenant synchronization settings within an Azure tenant, specifically where inbound trust for MFA or device compliance/hybrid-join claims is explicitly enabled. This activity may indicate an adversary attempting to establish persistence or facilitate lateral movement by leveraging trusted relationships between partner organizations.
Detects anomalous sign-in activity for Azure Service Principals by comparing the current source IP/ASN and country against a 30-day historical baseline. This alert identifies potentially compromised service principals, where attackers exfiltrate secrets or certificates and attempt to authenticate from their own infrastructure.
This rule detects modifications to domain federation settings in Azure Active Directory (Microsoft Entra ID), specifically when a domain is set to federated or when critical federation URLs (IssuerUri, ActiveLogOnUri, MetadataExchangeUri) are changed. Such modifications can indicate an attempt to establish malicious domain federation, allowing an adversary to authenticate as any user within the tenant.
This rule detects modifications to domain federation settings in Azure Active Directory (Microsoft Entra ID), specifically when a domain is set to federated or when critical federation URLs (IssuerUri, ActiveLogOnUri, MetadataExchangeUri) are changed. Such modifications can indicate an attempt to establish malicious domain federation, allowing an adversary to authenticate as any user within the tenant.
Detects unauthorized or suspicious modifications to Azure Active Directory (Azure AD) Conditional Access Policies. This includes deleting a policy, disabling an enabled policy, narrowing the scope of users or groups targeted by a policy, or removing MFA requirements from existing policies.
Detects when a Service Principal is assigned to a highly privileged administrative role in Azure Active Directory (Entra ID). This activity can be an indicator of an adversary establishing persistence or escalating privileges by leveraging non-human identities.
