Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects OAuth2 permission consent events where a user grants a third-party or newly registered application access to high-risk scopes (such as Mail, Files, or Directory). This technique is commonly used to establish persistence and bypass MFA by gaining access to user accounts via malicious or compromised OAuth applications.
Detects mass-phishing consent campaigns by monitoring non-admin users consenting to multi-tenant or unverified-publisher applications requesting non-basic-profile OAuth scopes. The rule aggregates multiple consent events for the same application over a 1-hour window to identify potentially malicious consent-phishing activity.
Detects modifications to Microsoft Entra ID (formerly Azure AD) cross-tenant access settings. This rule alerts on changes that allow external tenants to interact with the environment, such as enabling inbound/outbound trusts, automatic redemption, or trusting MFA claims, which can be leveraged to establish persistence or facilitate lateral movement between tenants.
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
Detects modifications to Microsoft Entra ID (formerly Azure AD) Conditional Access policies that lower security posture. This includes disabling policies, switching them to report-only mode, removing Multi-Factor Authentication (MFA) or grant control requirements, or expanding exclusion lists to exempt users, groups, or locations from security controls. Such modifications are often indicative of an adversary attempting to maintain persistent access or bypass MFA requirements.
Detects OAuth application consent grants where the application requests both 'offline_access' (enabling refresh tokens for long-term access) and sensitive mailbox permission scopes (such as Mail.Read, Mail.ReadWrite, Mail.Send, or IMAP.AccessAsUser.All). This combination is indicative of consent phishing attacks designed to establish persistent, silent access to user email accounts, bypassing password resets and multi-factor authentication.
Detects modifications to Microsoft Entra ID (formerly Azure AD) Conditional Access policies that lower security posture. This includes disabling policies, switching them to report-only mode, removing Multi-Factor Authentication (MFA) or grant control requirements, or expanding exclusion lists to exempt users, groups, or locations from security controls. Such modifications are often indicative of an adversary attempting to maintain persistent access or bypass MFA requirements.
This rule detects the reuse of the same user's refresh token from two different countries within a 15-minute window. This behavior is a strong indicator of token theft or session hijacking, commonly associated with AiTM phishing, infostealer malware, or session cookie extraction, where an adversary uses stolen credentials from a remote location.
Detects a potential Primary Refresh Token (PRT) or device code phishing attack by identifying a two-step authentication sequence: first, a successful user sign-in via device code flow, followed shortly by a subsequent sign-in from a different, unmanaged, or untrusted device. This behavioral pattern often indicates an adversary using stolen device code session data to authenticate a new device session.
Detects modifications to federated domain authentication, identity provider trusts, or federation settings in cloud environments (e.g., Entra ID, Okta). Unauthorized changes to these configurations can be used to establish persistence, enable SAML token forgery, or bypass Multi-Factor Authentication (MFA).
Detects the assignment of highly privileged Azure AD/Entra ID directory roles (e.g., Global Administrator, Application Administrator) to a service principal. Assigning such roles to service principals is a common persistence technique, as these identities can be used to bypass conditional access policies and MFA through non-interactive authentication methods like client credentials.
Detects the assignment of highly privileged Azure AD/Entra ID directory roles (e.g., Global Administrator, Application Administrator) to a service principal. Assigning such roles to service principals is a common persistence technique, as these identities can be used to bypass conditional access policies and MFA through non-interactive authentication methods like client credentials.
This rule detects the granting of sensitive, high-privilege Microsoft Graph API delegated or application permissions to an application or service principal in an Entra ID environment. Such permissions, including directory and user management or full application access, are frequently used by adversaries for persistence and privilege escalation within cloud environments.
Detects the assignment of highly privileged Azure AD/Entra ID directory roles (e.g., Global Administrator, Application Administrator) to a service principal. Assigning such roles to service principals is a common persistence technique, as these identities can be used to bypass conditional access policies and MFA through non-interactive authentication methods like client credentials.
This rule detects the granting of sensitive, high-privilege Microsoft Graph API delegated or application permissions to an application or service principal in an Entra ID environment. Such permissions, including directory and user management or full application access, are frequently used by adversaries for persistence and privilege escalation within cloud environments.
This rule detects the granting of sensitive, high-privilege Microsoft Graph API delegated or application permissions to an application or service principal in an Entra ID environment. Such permissions, including directory and user management or full application access, are frequently used by adversaries for persistence and privilege escalation within cloud environments.
Detects OAuth2 permission consent events where a user grants a third-party or newly registered application access to high-risk scopes (such as Mail, Files, or Directory). This technique is commonly used to establish persistence and bypass MFA by gaining access to user accounts via malicious or compromised OAuth applications.
Detects mass-phishing consent campaigns by monitoring non-admin users consenting to multi-tenant or unverified-publisher applications requesting non-basic-profile OAuth scopes. The rule aggregates multiple consent events for the same application over a 1-hour window to identify potentially malicious consent-phishing activity.
Detects modifications to Microsoft Entra ID (formerly Azure AD) cross-tenant access settings. This rule alerts on changes that allow external tenants to interact with the environment, such as enabling inbound/outbound trusts, automatic redemption, or trusting MFA claims, which can be leveraged to establish persistence or facilitate lateral movement between tenants.
Detects high-risk activities related to SAML token-signing certificates, including certificate export from Active Directory Federation Services (AD FS) or Active Directory Certificate Services (AD CS) and unauthorized configuration changes to enterprise application certificate management. These activities are potential precursors to Golden SAML attacks, where an adversary attempts to forge authentication tokens.
Detects the addition of suspicious redirect URIs, such as those containing wildcards, non-HTTPS protocols, or known URL-shortening services, to an OAuth application registration. Such configurations can be exploited by attackers to perform OAuth authorization code or token interception (e.g., through adversary-controlled endpoints).
