Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects OAuth2 permission consent events where a user grants a third-party or newly registered application access to high-risk scopes (such as Mail, Files, or Directory). This technique is commonly used to establish persistence and bypass MFA by gaining access to user accounts via malicious or compromised OAuth applications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects mass-phishing consent campaigns by monitoring non-admin users consenting to multi-tenant or unverified-publisher applications requesting non-basic-profile OAuth scopes. The rule aggregates multiple consent events for the same application over a 1-hour window to identify potentially malicious consent-phishing activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to Microsoft Entra ID (formerly Azure AD) cross-tenant access settings. This rule alerts on changes that allow external tenants to interact with the environment, such as enabling inbound/outbound trusts, automatic redemption, or trusting MFA claims, which can be leveraged to establish persistence or facilitate lateral movement between tenants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to Microsoft Entra ID (formerly Azure AD) Conditional Access policies that lower security posture. This includes disabling policies, switching them to report-only mode, removing Multi-Factor Authentication (MFA) or grant control requirements, or expanding exclusion lists to exempt users, groups, or locations from security controls. Such modifications are often indicative of an adversary attempting to maintain persistent access or bypass MFA requirements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects OAuth application consent grants where the application requests both 'offline_access' (enabling refresh tokens for long-term access) and sensitive mailbox permission scopes (such as Mail.Read, Mail.ReadWrite, Mail.Send, or IMAP.AccessAsUser.All). This combination is indicative of consent phishing attacks designed to establish persistent, silent access to user email accounts, bypassing password resets and multi-factor authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to Microsoft Entra ID (formerly Azure AD) Conditional Access policies that lower security posture. This includes disabling policies, switching them to report-only mode, removing Multi-Factor Authentication (MFA) or grant control requirements, or expanding exclusion lists to exempt users, groups, or locations from security controls. Such modifications are often indicative of an adversary attempting to maintain persistent access or bypass MFA requirements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the reuse of the same user's refresh token from two different countries within a 15-minute window. This behavior is a strong indicator of token theft or session hijacking, commonly associated with AiTM phishing, infostealer malware, or session cookie extraction, where an adversary uses stolen credentials from a remote location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a potential Primary Refresh Token (PRT) or device code phishing attack by identifying a two-step authentication sequence: first, a successful user sign-in via device code flow, followed shortly by a subsequent sign-in from a different, unmanaged, or untrusted device. This behavioral pattern often indicates an adversary using stolen device code session data to authenticate a new device session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to federated domain authentication, identity provider trusts, or federation settings in cloud environments (e.g., Entra ID, Okta). Unauthorized changes to these configurations can be used to establish persistence, enable SAML token forgery, or bypass Multi-Factor Authentication (MFA).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the assignment of highly privileged Azure AD/Entra ID directory roles (e.g., Global Administrator, Application Administrator) to a service principal. Assigning such roles to service principals is a common persistence technique, as these identities can be used to bypass conditional access policies and MFA through non-interactive authentication methods like client credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the assignment of highly privileged Azure AD/Entra ID directory roles (e.g., Global Administrator, Application Administrator) to a service principal. Assigning such roles to service principals is a common persistence technique, as these identities can be used to bypass conditional access policies and MFA through non-interactive authentication methods like client credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the granting of sensitive, high-privilege Microsoft Graph API delegated or application permissions to an application or service principal in an Entra ID environment. Such permissions, including directory and user management or full application access, are frequently used by adversaries for persistence and privilege escalation within cloud environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the assignment of highly privileged Azure AD/Entra ID directory roles (e.g., Global Administrator, Application Administrator) to a service principal. Assigning such roles to service principals is a common persistence technique, as these identities can be used to bypass conditional access policies and MFA through non-interactive authentication methods like client credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the granting of sensitive, high-privilege Microsoft Graph API delegated or application permissions to an application or service principal in an Entra ID environment. Such permissions, including directory and user management or full application access, are frequently used by adversaries for persistence and privilege escalation within cloud environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the granting of sensitive, high-privilege Microsoft Graph API delegated or application permissions to an application or service principal in an Entra ID environment. Such permissions, including directory and user management or full application access, are frequently used by adversaries for persistence and privilege escalation within cloud environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects OAuth2 permission consent events where a user grants a third-party or newly registered application access to high-risk scopes (such as Mail, Files, or Directory). This technique is commonly used to establish persistence and bypass MFA by gaining access to user accounts via malicious or compromised OAuth applications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects mass-phishing consent campaigns by monitoring non-admin users consenting to multi-tenant or unverified-publisher applications requesting non-basic-profile OAuth scopes. The rule aggregates multiple consent events for the same application over a 1-hour window to identify potentially malicious consent-phishing activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to Microsoft Entra ID (formerly Azure AD) cross-tenant access settings. This rule alerts on changes that allow external tenants to interact with the environment, such as enabling inbound/outbound trusts, automatic redemption, or trusting MFA claims, which can be leveraged to establish persistence or facilitate lateral movement between tenants.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the addition of suspicious redirect URIs, such as those containing wildcards, non-HTTPS protocols, or known URL-shortening services, to an OAuth application registration. Such configurations can be exploited by attackers to perform OAuth authorization code or token interception (e.g., through adversary-controlled endpoints).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000