Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools (e.g., ScreenConnect, AnyDesk, Atera, Splashtop, NinjaOne, Action1) when the command line includes silent install or installation flags. The detection correlates this activity with recent (within 72 hours) identity-related alerts (e.g., impossible travel, anomalous sign-in, credential compromise) for the same user, suggesting a potential high-risk scenario where an adversary is establishing remote access following a credential compromise.
Detects high-volume file download activity in Office 365/SharePoint/OneDrive audit logs. The rule correlates download spikes with users who have recently triggered security alerts related to session hijacking, token theft, or risky sign-ins, which are indicators of a potential cloud account takeover scenario.
This rule detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying session token or cookie reuse. It monitors for instances where a valid authentication session is established from one IP address and then immediately used again by the same user with the same session ID from a different IP address and potentially a different User-Agent, indicating that an attacker has hijacked and replayed the MFA-satisfied session.
Detects anomalous OAuth 2.0 device authorization grant sign-in activity within Microsoft 365. The rule identifies suspicious token redemption behavior where the initial device code request and the subsequent token redemption occur from disparate IP addresses or utilize different user-agent strings, which is indicative of EvilTokens or similar adversary-in-the-middle (AiTM) device-code phishing frameworks.
Detects unauthorized access to sensitive Chromium-based browser files such as 'Login Data' (password database) or 'Local State' (encryption keys) by processes other than standard web browsers (Chrome, Edge, Brave, Firefox). The rule also elevates risk if the access is followed by the execution of known data-handling tools like sqlite, python, or powershell, which are frequently used by information stealers to parse and exfiltrate browser-stored credentials.
Detects potential infostealer activity where an unsigned or non-system process accesses the Windows DPAPI master key store followed by access to common browser credential and cookie storage files within a 10-minute window. This behavior is indicative of malware attempting to decrypt and exfiltrate saved browser passwords and cookies.
Detects a suspected infostealer activity chain involving the unauthorized access of credential and session cookie files, followed by the archival of these files into a temporary or staging directory, and concluding with an outbound network connection to an uncommon destination from the archiving process.
Detects high-privilege OAuth application consent grants (such as Mail.Read or Files.ReadWrite.All) occurring within four hours of a risky or anomalous user sign-in. This sequence indicates a potential compromise where an attacker uses a compromised account to authorize a malicious OAuth application for persistent access and data exfiltration.
Detects instances where a user account performs non-interactive or legacy authentication (e.g., IMAP, POP3, SMTP, ActiveSync) shortly after an endpoint associated with that same user is flagged for malware or infostealer activity. This pattern is indicative of an adversary using exfiltrated credentials to maintain access to cloud services while bypassing MFA policies.
Detects a sequence of events where a user account triggers a high-risk or anomalous sign-in (e.g., token-replay, AitM, impossible travel), followed within 12 hours by that same user modifying, deleting, or narrowing the scope of Conditional Access or identity security policies. This behavior is indicative of an attacker attempting to establish persistence, strip MFA requirements, or bypass location restrictions after gaining initial cloud account access.
Detects the creation or modification of mailbox inbox rules that configure forwarding or redirection to external addresses, or rules that automatically delete or move messages based on sensitive keyword filters (e.g., 'invoice', 'password'). It specifically looks for indicators of mailbox hiding (hidden rules) which are frequently used by attackers to maintain persistence and conceal activity, particularly following unauthorized access or token theft.
Detects the assignment of a highly privileged administrative or directory role to a user or service principal following a high-risk or anomalous sign-in event. This pattern is indicative of potential session hijacking where an adversary attempts to escalate privileges within a cloud environment after gaining initial access to a compromised account.
Detects bulk mailbox export or content search operations performed by an identity shortly after a high-risk sign-in event. This pattern is indicative of potential account takeover where an adversary attempts to harvest sensitive email data at scale for BEC or extortion.
Detects when a user account that has exhibited anomalous or risky sign-in behavior subsequently grants mailbox delegation, full-access, or Send-As permissions to another user (who is not the mailbox owner). This activity is indicative of a compromised account being used to establish persistence or facilitate email exfiltration and spoofing by expanding access to sensitive mailboxes.
Detects a single user identity authenticating into three or more distinct SaaS applications within a 10-minute window. This behavior is consistent with the replay of a stolen session cookie (Pass-the-Cookie) or the abuse of an active authenticated session to move laterally across a federated SaaS estate.
Detects potential lateral movement by identifying users who have recently had a confirmed infostealer malware infection on a source host and subsequently initiate RDP or WinRM connections from a different host to internal network resources.
Detects an anomalous volume of file access or synchronization activity on cloud document platforms (Microsoft SharePoint, OneDrive, or Google Drive) that occurs following a high-severity risky sign-in event. The rule specifically flags potential exfiltration patterns such as large volumes of data transfer or numerous file accesses, especially if associated with unmanaged devices or connections to known personal/external file-sharing services.
This rule detects anomalous Privileged Identity Management (PIM) or Just-in-Time (JIT) role activation events. It identifies when a user activates a privileged role following suspicious activity such as a risky sign-in, during unusual (off-hours) time windows, or from an unfamiliar source IP address, potentially indicating session hijacking or credential abuse.
Detects non-interactive sign-in events where a refresh token is used to authenticate without satisfying a multi-factor authentication (MFA) requirement. This pattern is indicative of potential token theft and replay attacks, where an adversary uses a stolen refresh token to maintain persistence or access resources without triggering the expected MFA prompt.
Detects unauthorized access by a non-browser process to Chromium-based 'Cookies' SQLite database files, which are used by browsers like Chrome, Edge, and Brave. This behavior is a strong indicator of credential theft or session hijacking, as attackers target these files to extract session cookies and bypass MFA for cloud services.
Detects sign-in events to high-privileged cloud management consoles (e.g., Azure Portal, Microsoft Entra, Intune, Okta, AWS, GCP) originating from sessions with elevated risk or anomalous characteristics. The detection monitors for factors such as the use of anonymized IP addresses, unmanaged devices, sessions marked as 'atRisk' by identity providers, or non-interactive service-based access to management APIs that deviate from standard administrative workflow patterns.
