Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where a user grants consent to an Azure AD application with highly sensitive permissions (such as ReadWrite access to Directory, Roles, or Applications). This pattern is commonly used in OAuth consent phishing attacks to maintain persistence or escalate privileges by authorizing a malicious application to act on behalf of the user or the entire directory.
This rule detects unscheduled modifications to federation, application, or service principal credentials, including ADFS token-signing certificates, in both Azure AD (via O365 management activity logs) and local Windows environments (via Security Event Logs). It filters these events against a known rotation schedule to highlight suspicious, non-routine changes that may indicate persistence establishment or identity provider tampering.
No description available.
This rule detects modifications to multi-factor authentication (MFA) settings performed by privileged users (e.g., Global Admins) from IP addresses not previously associated with their account. The rule tracks actions such as registering new security information, changing default MFA methods, or deleting authentication methods. High-risk indicators like an unknown IP address for a privileged account are flagged for further investigation.
No description available.
This rule detects modifications to multi-factor authentication (MFA) settings performed by privileged users (e.g., Global Admins) from IP addresses not previously associated with their account. The rule tracks actions such as registering new security information, changing default MFA methods, or deleting authentication methods. High-risk indicators like an unknown IP address for a privileged account are flagged for further investigation.
Detects impossible travel activity for Azure AD accounts by calculating the speed between consecutive sign-in events using the Haversine formula. The rule correlates sign-ins sharing the same SessionId or DeviceId and identifies instances where the calculated travel speed exceeds 900 km/h over a distance greater than 300 km. It includes filtering to exclude known corporate VPN egress points to reduce noise.
This rule detects when new credentials (secrets or certificates) are added to an Azure Active Directory Service Principal. It flags this activity as suspicious if it occurs outside of typical business hours or if it exhibits signs of 'rapid re-keying', where multiple credentials are added to the same service principal within a 24-hour window. This behavior is a common indicator of persistence maintenance or credential rotation to support unauthorized access.
Detects impossible travel activity for Azure AD accounts by calculating the speed between consecutive sign-in events using the Haversine formula. The rule correlates sign-ins sharing the same SessionId or DeviceId and identifies instances where the calculated travel speed exceeds 900 km/h over a distance greater than 300 km. It includes filtering to exclude known corporate VPN egress points to reduce noise.
This rule monitors Azure AD and Office 365 non-interactive sign-in logs to identify anomalous spikes in activity from previously unseen applications or devices. It uses a 30-day baseline to determine if a sign-in pair (User/App/Device) is known. It further flags sign-ins from unrecognized locations (ASN/Country), flagging them with higher severity. This behavior is often indicative of automated credential abuse or token exploitation.
Detects a sequence where an OAuth application is granted 'Mail.ReadWrite' or 'MailboxSettings.ReadWrite' permissions, followed shortly thereafter (within 4 hours) by the creation or modification of an Inbox Rule by that same application within the same mailbox. This pattern is indicative of a persistence mechanism where an adversary uses elevated OAuth permissions to manipulate mailbox mail flow rules for stealth or exfiltration.
This rule detects scenarios where an external user is invited to an Azure AD tenant and subsequently granted a highly privileged role (such as Global Administrator or User Administrator) within a short window of time (1 hour). This pattern is indicative of potential persistence establishment or privilege escalation by an adversary using guest accounts.
Detects OAuth application consent events in Azure Active Directory where the application is from an unverified publisher, requests high-risk scopes (specifically offline_access plus at least two others like Mail, Files, Contacts, or Directory), and potentially indicates a mass-campaign if multiple users consent to the same application.
This rule monitors Office 365 management logs for device registration or join events in Azure Active Directory where the resulting device state is flagged as both non-compliant and unmanaged, despite having a 'Workplace' or 'AzureAd' trust type. It further aggregates these events by user to identify potential suspicious patterns, such as bulk registrations or rapid activity within a 30-minute window, which may indicate account compromise or unauthorized device enrollment.
Detects the reactivation of a Microsoft Entra ID (Azure AD) service principal that has been inactive for 90 or more days, specifically flagging those that perform privileged Graph API operations after their return. This rule helps identify potentially compromised or stale service principals being leveraged by adversaries for persistent access.
This rule monitors Office 365 management logs for device registration or join events in Azure Active Directory where the resulting device state is flagged as both non-compliant and unmanaged, despite having a 'Workplace' or 'AzureAd' trust type. It further aggregates these events by user to identify potential suspicious patterns, such as bulk registrations or rapid activity within a 30-minute window, which may indicate account compromise or unauthorized device enrollment.
Detects the reactivation of a Microsoft Entra ID (Azure AD) service principal that has been inactive for 90 or more days, specifically flagging those that perform privileged Graph API operations after their return. This rule helps identify potentially compromised or stale service principals being leveraged by adversaries for persistent access.
No description available.
Detects modifications to Microsoft 365 tenant configurations that weaken security posture, specifically the disabling of Security Defaults or the re-enabling of legacy/basic authentication methods (e.g., POP, IMAP, ActiveSync).
Detects modifications to an Azure Active Directory application where a new Redirect URI is added, particularly when the URI points to localhost, a raw IP address, or a non-corporate domain. The rule additionally correlates this change with recent OAuth grant activities to identify potential adversary attempts to hijack tokens or maintain persistent access via malicious application configurations.
Detects instances where a user grants an OAuth application consent to high-risk scopes (such as mail reading, file access, or directory reading) without administrator oversight. This behavior is a common indicator of OAuth abuse where an attacker lures a user into granting excessive permissions to a malicious application, providing the attacker persistent access to the user's data.
