Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where a user account that has been flagged as risky (e.g., unfamiliar features, impossible travel, or malicious IP activity) performs a modification or registration of multi-factor authentication (MFA) security information within a short timeframe (30 minutes). This behavior is highly indicative of an adversary attempting to establish persistence or bypass authentication controls after a credential compromise.
This rule detects potential account compromise by identifying 'impossible travel' scenarios where successful logins for the same user occur from different geolocations within a short timeframe (less than 1 hour), specifically when at least one authentication event uses a refresh or session token rather than interactive MFA. It correlates these suspicious logins with previous endpoint infostealer detections on the same device within the last 72 hours, indicating that the token may have been stolen by malware.
Detects anomalous authentication behavior where a single session identifier is used to access three or more distinct SaaS applications within a one-hour window. This behavior often indicates the unauthorized use of a stolen session cookie or OAuth token (Pass-the-Cookie) across multiple SSO-integrated platforms.
Detects instances where a risky Azure AD sign-in (e.g., token replay or confirmed compromise) is closely followed (within 24 hours) by sensitive application or service principal credential modifications by the same user account. This behavior is indicative of potential persistence establishment via account manipulation.
This rule detects scenarios where an existing SSO or Identity Provider (IdP) session is reused from a device context that differs from the one that originally performed MFA. It identifies this by joining authentication events by SessionId, specifically looking for instances where MFA occurred in one event and a subsequent non-MFA event for the same session has a different User-Agent, DeviceId, JA3 hash, or Operating System build, indicating potential session token theft or reuse.
Detects the creation or modification of Exchange mailbox or transport rules that exhibit suspicious characteristics, such as external forwarding, movement to hidden or system folders, automatic deletion/marking as read, or rules containing keywords related to financial fraud. The rule specifically monitors for activities occurring via non-standard or automated clients to increase detection fidelity.
Detects when a user account assigned to a highly privileged directory or cloud role performs the assignment shortly after exhibiting signs of compromise, such as risky sign-ins, anomalous locations, or suspected session token reuse.
This rule detects the installation or execution of common Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop, TeamViewer) on Windows endpoints within a 4-hour window of associated cloud identity risk activity (such as risky sign-ins, MFA changes, or privilege grants). It filters out legitimate activity initiated via standard software management pipelines (e.g., SCCM, Intune) to identify potential unauthorized use of remote access software by adversaries following account compromise.
Detects Microsoft Entra ID (formerly Azure AD) PIM or Just-In-Time role activations that occur without a proper approval workflow, are self-approved, or coincide with identified risky sign-in signals.
This rule detects potentially compromised accounts by correlating suspicious authentication activity (such as risky sign-ins, impossible travel, or malicious OAuth/Mail-rule configurations) with a subsequent spike in SharePoint or OneDrive file access, downloads, or external link sharing within a one-hour window. This behavior is indicative of an adversary performing cloud-based data exfiltration after gaining unauthorized access to an account.
Detects the creation of a 'manifest.json' file within directory paths containing 'extensions' by a process other than standard web browsers. This behavior is indicative of unauthorized manual installation or modification of browser extensions, which may be used for persistence or to facilitate credential/session theft.
Detects instances where a user account identified as high or medium risk, or marked as 'at risk' by Azure AD Identity Protection, performs an OAuth application consent action within one hour of the risky sign-in event. This correlation targets potential illicit application consent attacks where a compromised account is used to grant permissions to a malicious application.
Detects successful user authentication to Microsoft Entra ID or Exchange Online using legacy authentication protocols (e.g., IMAP, POP3, SMTP AUTH, Exchange ActiveSync) that bypass modern MFA enforcement. The rule specifically alerts when these legacy sign-ins originate from a source IP address not previously associated with that specific user account, indicating potential credential abuse.
Detects the creation or modification of Exchange inbox rules that involve suspicious actions, such as forwarding or redirecting emails to external domains, deleting messages, or marking messages as read. These actions are common indicators of persistent access or data exfiltration attempts following a mailbox compromise.
This rule correlates endpoint-based alerts related to credential theft or infostealer malware with subsequent successful cloud identity authentication events. It identifies situations where a user, who has recently triggered a credential theft alert on an endpoint, logs into a cloud environment from a country or IP address that has not been historically associated with that user within a 24-hour window.
Detects mailbox configuration changes in Exchange Online where email forwarding (ForwardingSmtpAddress, ForwardingAddress, or DeliverToMailboxAndForward) is enabled to an external, non-tenant domain. This technique is commonly used for persistence and data exfiltration following account compromise, allowing attackers to redirect incoming communications to an external mailbox even after the original account credentials have been reset.
Detects the addition of new credentials (certificates, secrets, or keys) to Azure AD Service Principals or Applications, occurring outside of standard business hours (6 AM to 8 PM). This pattern is often indicative of an adversary establishing or maintaining persistent access to an enterprise cloud environment.
Detects the addition of new credentials (certificates, secrets, or keys) to Azure AD Service Principals or Applications, occurring outside of standard business hours (6 AM to 8 PM). This pattern is often indicative of an adversary establishing or maintaining persistent access to an enterprise cloud environment.
This rule detects when a user is assigned a highly privileged role in Azure AD (e.g., Global Administrator, Security Administrator) shortly after that user has performed a sign-in event flagged as risky. This behavior is a strong indicator of account takeover or malicious privilege escalation within the cloud environment.
Correlates a successful OAuth device-code sign-in with a subsequent Device Registration Service event for the same user within 30 minutes, excluding known legitimate device-code applications (Azure CLI, Azure PowerShell, Visual Studio, VS Code) and requiring both events to have succeeded. The registration match is scoped strictly to the Device Registration Service resource (not the broader Microsoft Authentication Broker app, which fires on routine token refresh/broker activity unrelated to registering a new device). The correlation is further restricted to cases where the device-registration event originates from a different IP address or city than the original device-code sign-in -- the pattern expected when an attacker uses a stolen token to register their own device and mint a Primary Refresh Token, versus a legitimate user completing device enrollment from their own network shortly after a CLI/developer login.
This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools (e.g., ScreenConnect, AnyDesk, Atera, Splashtop, NinjaOne, Action1) when the command line includes silent install or installation flags. The detection correlates this activity with recent (within 72 hours) identity-related alerts (e.g., impossible travel, anomalous sign-in, credential compromise) for the same user, suggesting a potential high-risk scenario where an adversary is establishing remote access following a credential compromise.

