Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects changes to AWS S3 bucket policies or Access Control Lists (ACLs) that result in the bucket becoming publicly accessible. This is a common indicator of misconfiguration or unauthorized modification potentially leading to unauthorized data exposure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to application secrets or certificates in Azure that are performed by a user who is not the registered owner of the application, or when a new credential is added to an application that already has credentials configured, potentially indicating persistent access establishment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to Google Cloud Storage bucket IAM policies that grant access to 'allUsers' or 'allAuthenticatedUsers'. This activity indicates a potential misconfiguration or an attempt by an attacker to stage or exfiltrate data by making bucket contents publicly accessible.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of new AWS IAM access keys where the actor initiating the request is distinct from the target user associated with the key. This behavior often indicates an adversary attempting to establish persistent access to a compromised account by creating additional, long-lived credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects suspicious modifications to AWS Organization structure, specifically the moving of accounts out of protected organizational units (e.g., security, quarantine, guardrail), accounts leaving the organization, or the detachment of policies, which may indicate an attempt to evade security controls or organizational guardrails.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications or deletions of Azure AD Conditional Access policies that weaken security, such as disabling policies, removing MFA requirements, or adding user/group/application exclusions. This behavior can be indicative of an attacker attempting to bypass authentication controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the creation of new, potentially long-lived service account keys for GCP service accounts that possess highly privileged roles, such as Project Owner, Project Editor, or broad custom roles. The creation of such keys for privileged accounts can be a technique used by adversaries to establish persistent, stealthy access within a GCP environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects modifications to AWS EC2 Snapshot or AMI (Image) attributes that result in the resource becoming publicly accessible ('all') or shared with an unapproved AWS account ID. Such activities are often precursors to data exfiltration or unauthorized access to sensitive disk images.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects a correlation between a successful non-interactive authentication event (e.g., token-based sign-in) and a subsequent device registration event performed by the same user identity within a short time window. This sequence is a known pattern for attackers seeking to register an adversary-controlled device against a compromised account to establish durable persistence and potentially bypass conditional access policies (PRT persistence).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects successful authentication attempts using legacy (basic) protocols that do not enforce modern Conditional Access policies (e.g., MFA, device compliance). The rule specifically flags these events if the originating IP address or geographic location is not observed in historical sign-in activity for the specific user, which may indicate account compromise via credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects successful authentication attempts using legacy (basic) protocols that do not enforce modern Conditional Access policies (e.g., MFA, device compliance). The rule specifically flags these events if the originating IP address or geographic location is not observed in historical sign-in activity for the specific user, which may indicate account compromise via credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects impossible travel sign-in events where a user authenticates from geographically distant locations within a short time window. The rule specifically flags the second, suspicious event as having occurred via a non-interactive session or single-factor authentication, suggesting the use of a replayed or stale session token to bypass MFA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects impossible travel sign-in events where a user authenticates from geographically distant locations within a short time window. The rule specifically flags the second, suspicious event as having occurred via a non-interactive session or single-factor authentication, suggesting the use of a replayed or stale session token to bypass MFA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects successful sign-in events in Entra ID where MFA is marked as satisfied, but no interactive MFA challenge (e.g., Push, FIDO2, SMS) was recorded as completed in the authentication details. This behavior, when correlated with a new IP, device, or user-agent relative to a 30-day baseline, is highly indicative of session token replay or AitM (Adversary-in-the-Middle) attacks attempting to bypass MFA requirements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a potential Business Email Compromise (BEC) persistence chain where a user grants an OAuth application mailbox read/write permissions, followed immediately by the creation of an inbox rule (forwarding, moving, or deleting) targeting messages containing keywords like 'invoice', 'wire', or 'payment'.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects administrative changes that weaken cloud identity security, specifically the disabling of Entra ID Security Defaults, per-user MFA enforcement, or tenant-wide authentication-methods policies. These actions remove critical second-factor authentication requirements, significantly increasing the risk of unauthorized access via password-spraying or credential-stuffing attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects instances where a user successfully activates a privileged role via Privileged Identity Management (PIM) in a cloud environment, despite the activation policy requiring approval. It flags cases where the 'Add member to role completed' event indicates that approval is required, but the 'approvalStatus' is absent, suggesting an attempt to bypass the formal approval workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the reactivation of a service principal by correlating the addition of new credentials followed by a successful login event for the same principal within a 7-day window. This behavior is indicative of potential persistence maintenance or account hijacking, especially when legacy or deprecated accounts are targeted.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000