Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools (e.g., ScreenConnect, AnyDesk, Atera, Splashtop, NinjaOne, Action1) when the command line includes silent install or installation flags. The detection correlates this activity with recent (within 72 hours) identity-related alerts (e.g., impossible travel, anomalous sign-in, credential compromise) for the same user, suggesting a potential high-risk scenario where an adversary is establishing remote access following a credential compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects high-volume file download activity in Office 365/SharePoint/OneDrive audit logs. The rule correlates download spikes with users who have recently triggered security alerts related to session hijacking, token theft, or risky sign-ins, which are indicators of a potential cloud account takeover scenario.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying session token or cookie reuse. It monitors for instances where a valid authentication session is established from one IP address and then immediately used again by the same user with the same session ID from a different IP address and potentially a different User-Agent, indicating that an attacker has hijacked and replayed the MFA-satisfied session.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous OAuth 2.0 device authorization grant sign-in activity within Microsoft 365. The rule identifies suspicious token redemption behavior where the initial device code request and the subsequent token redemption occur from disparate IP addresses or utilize different user-agent strings, which is indicative of EvilTokens or similar adversary-in-the-middle (AiTM) device-code phishing frameworks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized access to sensitive Chromium-based browser files such as 'Login Data' (password database) or 'Local State' (encryption keys) by processes other than standard web browsers (Chrome, Edge, Brave, Firefox). The rule also elevates risk if the access is followed by the execution of known data-handling tools like sqlite, python, or powershell, which are frequently used by information stealers to parse and exfiltrate browser-stored credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential infostealer activity where an unsigned or non-system process accesses the Windows DPAPI master key store followed by access to common browser credential and cookie storage files within a 10-minute window. This behavior is indicative of malware attempting to decrypt and exfiltrate saved browser passwords and cookies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a suspected infostealer activity chain involving the unauthorized access of credential and session cookie files, followed by the archival of these files into a temporary or staging directory, and concluding with an outbound network connection to an uncommon destination from the archiving process.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects high-privilege OAuth application consent grants (such as Mail.Read or Files.ReadWrite.All) occurring within four hours of a risky or anomalous user sign-in. This sequence indicates a potential compromise where an attacker uses a compromised account to authorize a malicious OAuth application for persistent access and data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects instances where a user account performs non-interactive or legacy authentication (e.g., IMAP, POP3, SMTP, ActiveSync) shortly after an endpoint associated with that same user is flagged for malware or infostealer activity. This pattern is indicative of an adversary using exfiltrated credentials to maintain access to cloud services while bypassing MFA policies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a sequence of events where a user account triggers a high-risk or anomalous sign-in (e.g., token-replay, AitM, impossible travel), followed within 12 hours by that same user modifying, deleting, or narrowing the scope of Conditional Access or identity security policies. This behavior is indicative of an attacker attempting to establish persistence, strip MFA requirements, or bypass location restrictions after gaining initial cloud account access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation or modification of mailbox inbox rules that configure forwarding or redirection to external addresses, or rules that automatically delete or move messages based on sensitive keyword filters (e.g., 'invoice', 'password'). It specifically looks for indicators of mailbox hiding (hidden rules) which are frequently used by attackers to maintain persistence and conceal activity, particularly following unauthorized access or token theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the assignment of a highly privileged administrative or directory role to a user or service principal following a high-risk or anomalous sign-in event. This pattern is indicative of potential session hijacking where an adversary attempts to escalate privileges within a cloud environment after gaining initial access to a compromised account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects bulk mailbox export or content search operations performed by an identity shortly after a high-risk sign-in event. This pattern is indicative of potential account takeover where an adversary attempts to harvest sensitive email data at scale for BEC or extortion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects when a user account that has exhibited anomalous or risky sign-in behavior subsequently grants mailbox delegation, full-access, or Send-As permissions to another user (who is not the mailbox owner). This activity is indicative of a compromised account being used to establish persistence or facilitate email exfiltration and spoofing by expanding access to sensitive mailboxes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a single user identity authenticating into three or more distinct SaaS applications within a 10-minute window. This behavior is consistent with the replay of a stolen session cookie (Pass-the-Cookie) or the abuse of an active authenticated session to move laterally across a federated SaaS estate.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential lateral movement by identifying users who have recently had a confirmed infostealer malware infection on a source host and subsequently initiate RDP or WinRM connections from a different host to internal network resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects an anomalous volume of file access or synchronization activity on cloud document platforms (Microsoft SharePoint, OneDrive, or Google Drive) that occurs following a high-severity risky sign-in event. The rule specifically flags potential exfiltration patterns such as large volumes of data transfer or numerous file accesses, especially if associated with unmanaged devices or connections to known personal/external file-sharing services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects anomalous Privileged Identity Management (PIM) or Just-in-Time (JIT) role activation events. It identifies when a user activates a privileged role following suspicious activity such as a risky sign-in, during unusual (off-hours) time windows, or from an unfamiliar source IP address, potentially indicating session hijacking or credential abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects non-interactive sign-in events where a refresh token is used to authenticate without satisfying a multi-factor authentication (MFA) requirement. This pattern is indicative of potential token theft and replay attacks, where an adversary uses a stolen refresh token to maintain persistence or access resources without triggering the expected MFA prompt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized access by a non-browser process to Chromium-based 'Cookies' SQLite database files, which are used by browsers like Chrome, Edge, and Brave. This behavior is a strong indicator of credential theft or session hijacking, as attackers target these files to extract session cookies and bypass MFA for cloud services.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects sign-in events to high-privileged cloud management consoles (e.g., Azure Portal, Microsoft Entra, Intune, Okta, AWS, GCP) originating from sessions with elevated risk or anomalous characteristics. The detection monitors for factors such as the use of anonymized IP addresses, unmanaged devices, sessions marked as 'atRisk' by identity providers, or non-interactive service-based access to management APIs that deviate from standard administrative workflow patterns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000