Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous sign-in activity for service principals (non-interactive accounts) where the same application authenticates from multiple distinct countries within a 24-hour window. This behavior often indicates the unauthorized use of compromised service principal credentials, such as client secrets or certificates, from distributed attacker-controlled infrastructure.
Detects anomalous sign-in activity for service principals (non-interactive accounts) where the same application authenticates from multiple distinct countries within a 24-hour window. This behavior often indicates the unauthorized use of compromised service principal credentials, such as client secrets or certificates, from distributed attacker-controlled infrastructure.
Detects a potential Business Email Compromise (BEC) persistence chain where a user grants an OAuth application mailbox read/write permissions, followed immediately by the creation of an inbox rule (forwarding, moving, or deleting) targeting messages containing keywords like 'invoice', 'wire', or 'payment'.
Detects a potential Business Email Compromise (BEC) persistence chain where a user grants an OAuth application mailbox read/write permissions, followed immediately by the creation of an inbox rule (forwarding, moving, or deleting) targeting messages containing keywords like 'invoice', 'wire', or 'payment'.
This rule detects administrative changes that weaken cloud identity security, specifically the disabling of Entra ID Security Defaults, per-user MFA enforcement, or tenant-wide authentication-methods policies. These actions remove critical second-factor authentication requirements, significantly increasing the risk of unauthorized access via password-spraying or credential-stuffing attacks.
This rule detects instances where a user successfully activates a privileged role via Privileged Identity Management (PIM) in a cloud environment, despite the activation policy requiring approval. It flags cases where the 'Add member to role completed' event indicates that approval is required, but the 'approvalStatus' is absent, suggesting an attempt to bypass the formal approval workflow.
Detects the reactivation of a service principal by correlating the addition of new credentials followed by a successful login event for the same principal within a 7-day window. This behavior is indicative of potential persistence maintenance or account hijacking, especially when legacy or deprecated accounts are targeted.
Detects the addition of a federated identity credential to an Azure AD / Entra ID application. Adversaries may use this technique to establish persistent, secretless access to an application's service principal by configuring trust with an external OIDC issuer under their control (e.g., a malicious GitHub repository or personal OIDC provider).
Detects administrative actions in Azure that disable or modify diagnostic settings, which stops the flow of logs to services like Azure Sentinel/Log Analytics, or deletes policy assignments. Such actions are often performed by adversaries to blind security operations monitoring prior to lateral movement or further malicious activity.
This rule detects administrative actions in GCP that involve modifying or deleting Cloud Logging sinks, or disabling specific services, with a specific focus on disabling the logging service itself. Adversaries may perform these actions to tamper with audit trails and evade detection of malicious activities.
This rule detects modifications to AWS CloudTrail configurations that reduce logging visibility, such as stopping the logging service, deleting a trail, or updating a trail to include restrictive event selectors (e.g., non-multi-region, read-only events, or excluding management events). These actions are indicative of an attacker attempting to evade detection by limiting the audit trail available to security analysts.
Detects 'ec2:RunInstances' API calls occurring in AWS regions that are not part of the organization's approved allow-list. This behavior can be indicative of malicious infrastructure staging, such as deploying assets for unauthorized cryptomining or establishing pivot points in regions that are infrequently monitored.
Detects 'ec2:RunInstances' API calls occurring in AWS regions that are not part of the organization's approved allow-list. This behavior can be indicative of malicious infrastructure staging, such as deploying assets for unauthorized cryptomining or establishing pivot points in regions that are infrequently monitored.
Detects the initialization of an AWS CloudShell session followed by file transfer operations (PutFile or GetFile). This behavior may indicate an attacker using CloudShell to stage, exfiltrate, or move tools within the cloud environment, potentially bypassing endpoint detection by operating within the cloud service infrastructure.
This rule detects modifications to AWS IAM policies (PutUserPolicy, PutRolePolicy, PutGroupPolicy, AttachUserPolicy, AttachRolePolicy, or CreatePolicyVersion) that result in a policy granting administrative '*' access to both Actions and Resources. This pattern is commonly used by adversaries for persistence and privilege escalation after initial IAM credential compromise.
Detects suspicious modifications to Google Cloud Platform compute instance metadata, specifically the enabling of serial ports or the addition of startup scripts, which can be leveraged to execute arbitrary commands on a virtual machine. This rule also monitors for the initiation of GCP Cloud Shell environments, which may be used as a platform for further administrative activity.
Detects a privilege escalation sequence where a principal uses 'PassRole' to attach an IAM role to a newly created compute resource (Lambda, EC2, or CloudFormation stack), followed shortly by that compute resource performing privileged API calls. This behavior indicates a potential attempt to gain unauthorized elevated permissions by executing actions from an over-privileged service identity.
Detects a privilege escalation sequence where a principal uses 'PassRole' to attach an IAM role to a newly created compute resource (Lambda, EC2, or CloudFormation stack), followed shortly by that compute resource performing privileged API calls. This behavior indicates a potential attempt to gain unauthorized elevated permissions by executing actions from an over-privileged service identity.
Detects the creation of GCP compute instances that are attached to service accounts with broad 'cloud-platform' scope permissions. This activity is monitored to ensure that only authorized automation service accounts (e.g., IaC pipelines) are performing these actions, as creating instances with highly privileged service accounts can be a technique used to escalate privileges or establish persistence.
Detects changes to AWS S3 bucket policies or Access Control Lists (ACLs) that result in the bucket becoming publicly accessible. This is a common indicator of misconfiguration or unauthorized modification potentially leading to unauthorized data exposure.
Detects modifications to application secrets or certificates in Azure that are performed by a user who is not the registered owner of the application, or when a new credential is added to an application that already has credentials configured, potentially indicating persistent access establishment.
