Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects usage of legacy and inherently less secure authentication protocols (such as IMAP, POP3, SMTP, or Basic Authentication) within Microsoft Entra ID (Azure AD) sign-in activity. These protocols often bypass modern multi-factor authentication (MFA) requirements and are commonly exploited in credential stuffing and password spraying attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule correlates a risky or compromised sign-in event in Entra ID (Azure AD) with a subsequent OAuth consent grant by the same user within 60 minutes. It specifically looks for grants that request sensitive permissions such as Mail.Read, Mail.ReadWrite, Files.ReadWrite.All, or offline_access, which are commonly associated with consent phishing and persistence tactics.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects non-interactive sign-in events (including refresh-token or PRT-based authentication) where the originating device is not managed by Intune/Jamf, not marked as compliant, and lacks a registered trust type. This behavior is indicative of potential stolen session token replay or unauthorized access using intercepted artifacts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where a user account that has been flagged as risky (e.g., unfamiliar features, impossible travel, or malicious IP activity) performs a modification or registration of multi-factor authentication (MFA) security information within a short timeframe (30 minutes). This behavior is highly indicative of an adversary attempting to establish persistence or bypass authentication controls after a credential compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where a risky Azure AD sign-in (e.g., token replay or confirmed compromise) is closely followed (within 24 hours) by sensitive application or service principal credential modifications by the same user account. This behavior is indicative of potential persistence establishment via account manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects scenarios where an existing SSO or Identity Provider (IdP) session is reused from a device context that differs from the one that originally performed MFA. It identifies this by joining authentication events by SessionId, specifically looking for instances where MFA occurred in one event and a subsequent non-MFA event for the same session has a different User-Agent, DeviceId, JA3 hash, or Operating System build, indicating potential session token theft or reuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation or modification of Exchange mailbox or transport rules that exhibit suspicious characteristics, such as external forwarding, movement to hidden or system folders, automatic deletion/marking as read, or rules containing keywords related to financial fraud. The rule specifically monitors for activities occurring via non-standard or automated clients to increase detection fidelity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects when a user account assigned to a highly privileged directory or cloud role performs the assignment shortly after exhibiting signs of compromise, such as risky sign-ins, anomalous locations, or suspected session token reuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the installation or execution of common Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop, TeamViewer) on Windows endpoints within a 4-hour window of associated cloud identity risk activity (such as risky sign-ins, MFA changes, or privilege grants). It filters out legitimate activity initiated via standard software management pipelines (e.g., SCCM, Intune) to identify potential unauthorized use of remote access software by adversaries following account compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects Microsoft Entra ID (formerly Azure AD) PIM or Just-In-Time role activations that occur without a proper approval workflow, are self-approved, or coincide with identified risky sign-in signals.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a potential post-compromise lateral movement sequence where a host, previously identified as accessing sensitive browser credential files by an unauthorized process, subsequently initiates RDP or WinRM connections to other internal hosts using an account not previously observed performing interactive logons on that source host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where a process that is not a recognized web browser (chrome, msedge, firefox, brave, opera, or explorer) accesses multiple unique browser cookie files. This is a common pattern for credential harvesting malware attempting to steal browser sessions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where a suspicious PowerShell, mshta, or pwsh command, typically involving download or obfuscation patterns, is launched as a child process of Windows Explorer within two minutes of a modification to the Explorer RunMRU registry key. This behavior is indicative of an adversary attempting to achieve execution, often following user interaction or persistence triggers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized access or modification attempts to common web browser credential storage files (such as 'Login Data' or 'key4.db') by processes other than standard, trusted web browsers (e.g., Chrome, Edge, Firefox). This behavior is indicative of credential harvesting, where an adversary attempts to steal saved login information from browser data stores.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects usage of legacy and inherently less secure authentication protocols (such as IMAP, POP3, SMTP, or Basic Authentication) within Microsoft Entra ID (Azure AD) sign-in activity. These protocols often bypass modern multi-factor authentication (MFA) requirements and are commonly exploited in credential stuffing and password spraying attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule correlates a risky or compromised sign-in event in Entra ID (Azure AD) with a subsequent OAuth consent grant by the same user within 60 minutes. It specifically looks for grants that request sensitive permissions such as Mail.Read, Mail.ReadWrite, Files.ReadWrite.All, or offline_access, which are commonly associated with consent phishing and persistence tactics.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects non-interactive sign-in events (including refresh-token or PRT-based authentication) where the originating device is not managed by Intune/Jamf, not marked as compliant, and lacks a registered trust type. This behavior is indicative of potential stolen session token replay or unauthorized access using intercepted artifacts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000