Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects successful authentication attempts using legacy (basic) protocols that do not enforce modern Conditional Access policies (e.g., MFA, device compliance). The rule specifically flags these events if the originating IP address or geographic location is not observed in historical sign-in activity for the specific user, which may indicate account compromise via credential theft.
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
Detects impossible travel sign-in events where a user authenticates from geographically distant locations within a short time window. The rule specifically flags the second, suspicious event as having occurred via a non-interactive session or single-factor authentication, suggesting the use of a replayed or stale session token to bypass MFA.
Detects the creation or modification of Microsoft 365/Exchange inbox rules that suggest malicious staging or exfiltration activities. This includes rules configured for external email auto-forwarding, automatic deletion of messages, or movement of emails into hidden/system folders (e.g., RSS Subscriptions, Archive) which may be filtered based on sensitive keywords related to financial or credential theft (e.g., invoice, wire, payment).
Detects successful sign-in events in Entra ID where MFA is marked as satisfied, but no interactive MFA challenge (e.g., Push, FIDO2, SMS) was recorded as completed in the authentication details. This behavior, when correlated with a new IP, device, or user-agent relative to a 30-day baseline, is highly indicative of session token replay or AitM (Adversary-in-the-Middle) attacks attempting to bypass MFA requirements.
This rule detects scenarios where a user account grants high-privilege permissions (e.g., mail access or file modification) to an OAuth application within a short time frame (2 hours) following a sign-in event flagged as risky by Entra ID (Azure AD). This pattern is indicative of an adversary abusing OAuth consent flows as a persistence and credential-access mechanism following account compromise.
This rule detects a multi-stage attack chain where a device shows signs of credential theft (accessing browser credential stores or cookies) followed closely by a successful cloud authentication from that same user using a device identifier not previously observed in the last 30 days.
Detects mailbox permission changes (FullAccess, SendAs) or abnormally high volume of mailbox item access events occurring shortly after a risky, non-interactive, or unusual location sign-in. This pattern indicates a potential follow-on activity from a successful session hijacking or token theft attack.
Detects mailbox permission changes (FullAccess, SendAs) or abnormally high volume of mailbox item access events occurring shortly after a risky, non-interactive, or unusual location sign-in. This pattern indicates a potential follow-on activity from a successful session hijacking or token theft attack.
Detects potential Adversary-in-the-Middle (AiTM) phishing attacks by identifying a correlation between URL clicks (Safe Links) and subsequent rapid successful sign-ins by the same user. Additionally, the rule flags instances where multiple distinct users authenticate via the same IP address within a one-hour window, identifying potential infrastructure fan-out typical of proxy-based phishing kits.
This rule detects potentially malicious bulk mailbox exfiltration operations (such as New-MailboxExportRequest, New-ComplianceSearch, or Search-Mailbox) performed by an account within 24 hours of experiencing a high or medium-risk sign-in event, suggesting post-compromise data harvesting.
Detects a user account adding a new client secret or certificate to an Azure AD application/service principal, followed by a sign-in event from that same service principal originating from an IP address not observed in the prior 14 days. This behavior is indicative of potential persistent access creation by an adversary using newly generated credentials.
Detects anomalous reuse of a single session identifier across geographically distinct locations and/or multiple federated SaaS applications within a short time frame. The detection specifically filters for non-interactive sign-in events, which is characteristic of session hijacking and token replay rather than standard user activity.
Detects the assignment of high-privilege directory roles (e.g., Global Administrator) to a user account, where the initiator's sign-in session is identified as anomalous. Anomalous indicators include non-interactive sign-in, unknown/untrusted device state, elevated risk score, or activity occurring outside of configured business hours.
Detects the assignment of high-privilege directory roles (e.g., Global Administrator) to a user account, where the initiator's sign-in session is identified as anomalous. Anomalous indicators include non-interactive sign-in, unknown/untrusted device state, elevated risk score, or activity occurring outside of configured business hours.
This rule detects Entra ID Privileged Identity Management (PIM) role activations that occur with missing or generic justification, correlated with a sign-in session that has been flagged as risky (high/medium risk) or non-interactive. This combination suggests a potential session hijacking scenario where an adversary is attempting to elevate privileges using a compromised, legitimate user session.
This rule monitors for suspicious administrative modifications to identity federation settings within Entra ID (Azure AD) and potential unauthorized alterations to on-premises Active Directory objects related to the 'AZUREADSSOACC' account. These activities are indicative of persistence mechanisms or credential manipulation in hybrid identity environments, potentially used to subvert authentication processes.
Detects instances where a suspicious PowerShell, mshta, or pwsh command, typically involving download or obfuscation patterns, is launched as a child process of Windows Explorer within two minutes of a modification to the Explorer RunMRU registry key. This behavior is indicative of an adversary attempting to achieve execution, often following user interaction or persistence triggers.
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
Detects usage of legacy and inherently less secure authentication protocols (such as IMAP, POP3, SMTP, or Basic Authentication) within Microsoft Entra ID (Azure AD) sign-in activity. These protocols often bypass modern multi-factor authentication (MFA) requirements and are commonly exploited in credential stuffing and password spraying attacks.
This rule correlates a risky or compromised sign-in event in Entra ID (Azure AD) with a subsequent OAuth consent grant by the same user within 60 minutes. It specifically looks for grants that request sensitive permissions such as Mail.Read, Mail.ReadWrite, Files.ReadWrite.All, or offline_access, which are commonly associated with consent phishing and persistence tactics.
