Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects anomalous, high-velocity authentication activity where a single identity accesses multiple high-value SaaS applications (such as CRM, DevOps, or admin consoles) in a short time frame, correlated with risk signals indicative of token reuse or 'pass-the-cookie' attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects 'Add member to role' operations in Entra ID where high-privileged directory roles are assigned to a user or service principal. This pattern is often a critical indicator of privilege escalation in account compromise scenarios where an attacker attempts to elevate their own or a secondary account's permissions within the tenant.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized access attempts to Chromium-based browser credential storage files, specifically 'Login Data' (SQLite database) and 'Local State' (master key storage), by processes other than standard browsers or known security products. This activity is a common indicator of credential harvesting by information stealers such as LummaC2, Vidar, and RedLine.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the addition of new client secrets or certificates to existing applications or service principals in Azure AD. This activity is a common method for adversaries to establish persistence in a cloud environment by ensuring they maintain MFA-exempt application-level access even if compromised user accounts or session cookies expire.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a sequence of events where a user performs a risky or anomalous login to Azure AD, such as from an anonymous network or an non-compliant device, followed shortly after by the registration of a new MFA method or security information. This behavior is indicative of an attacker who has compromised credentials and is attempting to establish persistence or bypass authentication controls by enrolling their own MFA device.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of anonymous or guest-access sharing links for SharePoint items that are classified as sensitive (having a sensitivity label applied). This activity could indicate potential data exfiltration or unauthorized sharing of protected corporate information.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous, high-volume file download or sync activity by a single user within a 10-minute window in M365 (SharePoint/OneDrive). This behavior is indicative of bulk data exfiltration, potentially occurring after a session hijacking or account takeover, where the attacker leverages legitimate user credentials to access and export sensitive data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects interactive (Logon Type 10) or network (Logon Type 3) authentication to Windows hosts originating from external, non-RFC1918 IP addresses using 'Negotiate' authentication. This pattern is indicative of potential lateral movement from a cloud-connected environment into on-premises infrastructure, specifically where an adversary might be leveraging stolen session artifacts or credentials to bypass standard Kerberos-based domain authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to AWS CloudTrail logging configurations, specifically changes to trails or subscription filters that could be used to suppress, redirect, or disrupt the collection of audit logs, potentially masking malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of an AWS Lambda function that is assigned an excessively privileged execution role (e.g., AdministratorAccess). Attackers often leverage this technique to establish persistence or facilitate privilege escalation by creating backdoored functions that run with broad administrative permissions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the modification or attachment of IAM policies to users or roles that contain wildcard 'Allow' permissions for all actions and resources. This behavior is indicative of privilege escalation where an identity is granted full administrative control over the AWS account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects the initialization of an AWS CloudShell environment or session where Multi-Factor Authentication (MFA) was not explicitly recorded in the event data. Unauthorized access to CloudShell can provide an adversary with a command-line interface to interact with AWS APIs, potentially facilitating further malicious activities.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential privilege escalation where an identity with iam:PassRole permissions deploys or updates compute resources (CloudFormation, EC2, or Lambda) to assume a more privileged IAM role than the user currently holds.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of sts:AssumeRole or sts:GetFederationToken to request temporary security credentials in a different AWS account than the one initiating the request. This can indicate cross-account privilege escalation or lateral movement using identity federation or assumed roles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to AWS S3 bucket Access Control Lists (ACLs) using the 'PutBucketAcl' API call that grant public read or write permissions. This could indicate an attempt to make sensitive data stored in S3 publicly accessible, potentially leading to data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential privilege escalation where an identity with iam:PassRole permissions deploys or updates compute resources (CloudFormation, EC2, or Lambda) to assume a more privileged IAM role than the user currently holds.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of sts:AssumeRole or sts:GetFederationToken to request temporary security credentials in a different AWS account than the one initiating the request. This can indicate cross-account privilege escalation or lateral movement using identity federation or assumed roles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to AWS S3 bucket Access Control Lists (ACLs) using the 'PutBucketAcl' API call that grant public read or write permissions. This could indicate an attempt to make sensitive data stored in S3 publicly accessible, potentially leading to data exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to IAM role trust policies (UpdateAssumeRolePolicy) or the creation of new roles (CreateRole) where the Principal is configured with a wildcard or generic open access. This configuration enables any AWS account to assume the role, representing a significant risk for privilege escalation and persistence establishment by attackers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the mass creation of high-performance compute instances (GPU or high-memory variants) in an AWS environment. By filtering out legitimate service-linked roles associated with auto-scaling, the rule isolates potentially unauthorized manual provisioning, often indicative of cryptojacking or resource hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized attempts to stop, delete, modify, or change event selectors for AWS CloudTrail logs. This activity is indicative of an attacker attempting to disable audit logging to evade detection while performing further malicious actions in the environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000