Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the addition of a federated identity credential to an Azure AD / Entra ID application. Adversaries may use this technique to establish persistent, secretless access to an application's service principal by configuring trust with an external OIDC issuer under their control (e.g., a malicious GitHub repository or personal OIDC provider).
Detects potential abuse of Azure Cloud Shell backing storage (acsCloudShell) to stage or persist malicious scripts following an Azure AD session compromise. Adversaries may use this storage to blend in with legitimate engineering operations while maintaining persistent access to their tooling.
Detects administrative actions in Azure that disable or modify diagnostic settings, which stops the flow of logs to services like Azure Sentinel/Log Analytics, or deletes policy assignments. Such actions are often performed by adversaries to blind security operations monitoring prior to lateral movement or further malicious activity.
This rule detects administrative actions in GCP that involve modifying or deleting Cloud Logging sinks, or disabling specific services, with a specific focus on disabling the logging service itself. Adversaries may perform these actions to tamper with audit trails and evade detection of malicious activities.
This rule detects modifications to AWS CloudTrail configurations that reduce logging visibility, such as stopping the logging service, deleting a trail, or updating a trail to include restrictive event selectors (e.g., non-multi-region, read-only events, or excluding management events). These actions are indicative of an attacker attempting to evade detection by limiting the audit trail available to security analysts.
Detects 'ec2:RunInstances' API calls occurring in AWS regions that are not part of the organization's approved allow-list. This behavior can be indicative of malicious infrastructure staging, such as deploying assets for unauthorized cryptomining or establishing pivot points in regions that are infrequently monitored.
Detects the initialization of an AWS CloudShell session followed by file transfer operations (PutFile or GetFile). This behavior may indicate an attacker using CloudShell to stage, exfiltrate, or move tools within the cloud environment, potentially bypassing endpoint detection by operating within the cloud service infrastructure.
This rule detects modifications to AWS IAM policies (PutUserPolicy, PutRolePolicy, PutGroupPolicy, AttachUserPolicy, AttachRolePolicy, or CreatePolicyVersion) that result in a policy granting administrative '*' access to both Actions and Resources. This pattern is commonly used by adversaries for persistence and privilege escalation after initial IAM credential compromise.
Detects suspicious modifications to Google Cloud Platform compute instance metadata, specifically the enabling of serial ports or the addition of startup scripts, which can be leveraged to execute arbitrary commands on a virtual machine. This rule also monitors for the initiation of GCP Cloud Shell environments, which may be used as a platform for further administrative activity.
Detects a privilege escalation sequence where a principal uses 'PassRole' to attach an IAM role to a newly created compute resource (Lambda, EC2, or CloudFormation stack), followed shortly by that compute resource performing privileged API calls. This behavior indicates a potential attempt to gain unauthorized elevated permissions by executing actions from an over-privileged service identity.
Detects the creation of GCP compute instances that are attached to service accounts with broad 'cloud-platform' scope permissions. This activity is monitored to ensure that only authorized automation service accounts (e.g., IaC pipelines) are performing these actions, as creating instances with highly privileged service accounts can be a technique used to escalate privileges or establish persistence.
Detects changes to AWS S3 bucket policies or Access Control Lists (ACLs) that result in the bucket becoming publicly accessible. This is a common indicator of misconfiguration or unauthorized modification potentially leading to unauthorized data exposure.
Detects modifications to application secrets or certificates in Azure that are performed by a user who is not the registered owner of the application, or when a new credential is added to an application that already has credentials configured, potentially indicating persistent access establishment.
Detects modifications to Google Cloud Storage bucket IAM policies that grant access to 'allUsers' or 'allAuthenticatedUsers'. This activity indicates a potential misconfiguration or an attempt by an attacker to stage or exfiltrate data by making bucket contents publicly accessible.
Detects the modification of an Azure Storage account configuration to enable public access (allowBlobPublicAccess: true). This activity is often associated with attackers attempting to facilitate anonymous data exfiltration by enabling public access to blobs and subsequently reading them.
Detects the creation of new AWS IAM access keys where the actor initiating the request is distinct from the target user associated with the key. This behavior often indicates an adversary attempting to establish persistent access to a compromised account by creating additional, long-lived credentials.
Detects suspicious modifications to AWS Organization structure, specifically the moving of accounts out of protected organizational units (e.g., security, quarantine, guardrail), accounts leaving the organization, or the detachment of policies, which may indicate an attempt to evade security controls or organizational guardrails.
Detects modifications or deletions of Azure AD Conditional Access policies that weaken security, such as disabling policies, removing MFA requirements, or adding user/group/application exclusions. This behavior can be indicative of an attacker attempting to bypass authentication controls.
This rule detects the creation of new, potentially long-lived service account keys for GCP service accounts that possess highly privileged roles, such as Project Owner, Project Editor, or broad custom roles. The creation of such keys for privileged accounts can be a technique used by adversaries to establish persistent, stealthy access within a GCP environment.
This rule detects modifications to AWS EC2 Snapshot or AMI (Image) attributes that result in the resource becoming publicly accessible ('all') or shared with an unapproved AWS account ID. Such activities are often precursors to data exfiltration or unauthorized access to sensitive disk images.
Detects instances where an IAM user or role attempts to assume a role in a different AWS account (Cross-Account) without providing a valid ExternalID. This often indicates unauthorized attempts to access or abuse cross-account trust relationships, which is a common technique for lateral movement or privilege escalation in cloud environments.
