Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects successful authentication attempts using legacy (basic) protocols that do not enforce modern Conditional Access policies (e.g., MFA, device compliance). The rule specifically flags these events if the originating IP address or geographic location is not observed in historical sign-in activity for the specific user, which may indicate account compromise via credential theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects impossible travel sign-in events where a user authenticates from geographically distant locations within a short time window. The rule specifically flags the second, suspicious event as having occurred via a non-interactive session or single-factor authentication, suggesting the use of a replayed or stale session token to bypass MFA.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation or modification of Microsoft 365/Exchange inbox rules that suggest malicious staging or exfiltration activities. This includes rules configured for external email auto-forwarding, automatic deletion of messages, or movement of emails into hidden/system folders (e.g., RSS Subscriptions, Archive) which may be filtered based on sensitive keywords related to financial or credential theft (e.g., invoice, wire, payment).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects successful sign-in events in Entra ID where MFA is marked as satisfied, but no interactive MFA challenge (e.g., Push, FIDO2, SMS) was recorded as completed in the authentication details. This behavior, when correlated with a new IP, device, or user-agent relative to a 30-day baseline, is highly indicative of session token replay or AitM (Adversary-in-the-Middle) attacks attempting to bypass MFA requirements.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects scenarios where a user account grants high-privilege permissions (e.g., mail access or file modification) to an OAuth application within a short time frame (2 hours) following a sign-in event flagged as risky by Entra ID (Azure AD). This pattern is indicative of an adversary abusing OAuth consent flows as a persistence and credential-access mechanism following account compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects a multi-stage attack chain where a device shows signs of credential theft (accessing browser credential stores or cookies) followed closely by a successful cloud authentication from that same user using a device identifier not previously observed in the last 30 days.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects mailbox permission changes (FullAccess, SendAs) or abnormally high volume of mailbox item access events occurring shortly after a risky, non-interactive, or unusual location sign-in. This pattern indicates a potential follow-on activity from a successful session hijacking or token theft attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects mailbox permission changes (FullAccess, SendAs) or abnormally high volume of mailbox item access events occurring shortly after a risky, non-interactive, or unusual location sign-in. This pattern indicates a potential follow-on activity from a successful session hijacking or token theft attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential Adversary-in-the-Middle (AiTM) phishing attacks by identifying a correlation between URL clicks (Safe Links) and subsequent rapid successful sign-ins by the same user. Additionally, the rule flags instances where multiple distinct users authenticate via the same IP address within a one-hour window, identifying potential infrastructure fan-out typical of proxy-based phishing kits.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potentially malicious bulk mailbox exfiltration operations (such as New-MailboxExportRequest, New-ComplianceSearch, or Search-Mailbox) performed by an account within 24 hours of experiencing a high or medium-risk sign-in event, suggesting post-compromise data harvesting.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a user account adding a new client secret or certificate to an Azure AD application/service principal, followed by a sign-in event from that same service principal originating from an IP address not observed in the prior 14 days. This behavior is indicative of potential persistent access creation by an adversary using newly generated credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous reuse of a single session identifier across geographically distinct locations and/or multiple federated SaaS applications within a short time frame. The detection specifically filters for non-interactive sign-in events, which is characteristic of session hijacking and token replay rather than standard user activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the assignment of high-privilege directory roles (e.g., Global Administrator) to a user account, where the initiator's sign-in session is identified as anomalous. Anomalous indicators include non-interactive sign-in, unknown/untrusted device state, elevated risk score, or activity occurring outside of configured business hours.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the assignment of high-privilege directory roles (e.g., Global Administrator) to a user account, where the initiator's sign-in session is identified as anomalous. Anomalous indicators include non-interactive sign-in, unknown/untrusted device state, elevated risk score, or activity occurring outside of configured business hours.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects Entra ID Privileged Identity Management (PIM) role activations that occur with missing or generic justification, correlated with a sign-in session that has been flagged as risky (high/medium risk) or non-interactive. This combination suggests a potential session hijacking scenario where an adversary is attempting to elevate privileges using a compromised, legitimate user session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule monitors for suspicious administrative modifications to identity federation settings within Entra ID (Azure AD) and potential unauthorized alterations to on-premises Active Directory objects related to the 'AZUREADSSOACC' account. These activities are indicative of persistence mechanisms or credential manipulation in hybrid identity environments, potentially used to subvert authentication processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where a suspicious PowerShell, mshta, or pwsh command, typically involving download or obfuscation patterns, is launched as a child process of Windows Explorer within two minutes of a modification to the Explorer RunMRU registry key. This behavior is indicative of an adversary attempting to achieve execution, often following user interaction or persistence triggers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects usage of legacy and inherently less secure authentication protocols (such as IMAP, POP3, SMTP, or Basic Authentication) within Microsoft Entra ID (Azure AD) sign-in activity. These protocols often bypass modern multi-factor authentication (MFA) requirements and are commonly exploited in credential stuffing and password spraying attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule correlates a risky or compromised sign-in event in Entra ID (Azure AD) with a subsequent OAuth consent grant by the same user within 60 minutes. It specifically looks for grants that request sensitive permissions such as Mail.Read, Mail.ReadWrite, Files.ReadWrite.All, or offline_access, which are commonly associated with consent phishing and persistence tactics.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000