Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous, high-velocity authentication activity where a single identity accesses multiple high-value SaaS applications (such as CRM, DevOps, or admin consoles) in a short time frame, correlated with risk signals indicative of token reuse or 'pass-the-cookie' attacks.
Detects 'Add member to role' operations in Entra ID where high-privileged directory roles are assigned to a user or service principal. This pattern is often a critical indicator of privilege escalation in account compromise scenarios where an attacker attempts to elevate their own or a secondary account's permissions within the tenant.
Detects unauthorized access attempts to Chromium-based browser credential storage files, specifically 'Login Data' (SQLite database) and 'Local State' (master key storage), by processes other than standard browsers or known security products. This activity is a common indicator of credential harvesting by information stealers such as LummaC2, Vidar, and RedLine.
Detects the addition of new client secrets or certificates to existing applications or service principals in Azure AD. This activity is a common method for adversaries to establish persistence in a cloud environment by ensuring they maintain MFA-exempt application-level access even if compromised user accounts or session cookies expire.
Detects a sequence of events where a user performs a risky or anomalous login to Azure AD, such as from an anonymous network or an non-compliant device, followed shortly after by the registration of a new MFA method or security information. This behavior is indicative of an attacker who has compromised credentials and is attempting to establish persistence or bypass authentication controls by enrolling their own MFA device.
Detects the creation of anonymous or guest-access sharing links for SharePoint items that are classified as sensitive (having a sensitivity label applied). This activity could indicate potential data exfiltration or unauthorized sharing of protected corporate information.
Detects anomalous, high-volume file download or sync activity by a single user within a 10-minute window in M365 (SharePoint/OneDrive). This behavior is indicative of bulk data exfiltration, potentially occurring after a session hijacking or account takeover, where the attacker leverages legitimate user credentials to access and export sensitive data.
Detects interactive (Logon Type 10) or network (Logon Type 3) authentication to Windows hosts originating from external, non-RFC1918 IP addresses using 'Negotiate' authentication. This pattern is indicative of potential lateral movement from a cloud-connected environment into on-premises infrastructure, specifically where an adversary might be leveraging stolen session artifacts or credentials to bypass standard Kerberos-based domain authentication.
Detects modifications to AWS CloudTrail logging configurations, specifically changes to trails or subscription filters that could be used to suppress, redirect, or disrupt the collection of audit logs, potentially masking malicious activity.
Detects the creation of an AWS Lambda function that is assigned an excessively privileged execution role (e.g., AdministratorAccess). Attackers often leverage this technique to establish persistence or facilitate privilege escalation by creating backdoored functions that run with broad administrative permissions.
Detects the modification or attachment of IAM policies to users or roles that contain wildcard 'Allow' permissions for all actions and resources. This behavior is indicative of privilege escalation where an identity is granted full administrative control over the AWS account.
This rule detects the initialization of an AWS CloudShell environment or session where Multi-Factor Authentication (MFA) was not explicitly recorded in the event data. Unauthorized access to CloudShell can provide an adversary with a command-line interface to interact with AWS APIs, potentially facilitating further malicious activities.
Detects potential privilege escalation where an identity with iam:PassRole permissions deploys or updates compute resources (CloudFormation, EC2, or Lambda) to assume a more privileged IAM role than the user currently holds.
Detects the use of sts:AssumeRole or sts:GetFederationToken to request temporary security credentials in a different AWS account than the one initiating the request. This can indicate cross-account privilege escalation or lateral movement using identity federation or assumed roles.
Detects modifications to AWS S3 bucket Access Control Lists (ACLs) using the 'PutBucketAcl' API call that grant public read or write permissions. This could indicate an attempt to make sensitive data stored in S3 publicly accessible, potentially leading to data exfiltration.
Detects potential privilege escalation where an identity with iam:PassRole permissions deploys or updates compute resources (CloudFormation, EC2, or Lambda) to assume a more privileged IAM role than the user currently holds.
Detects the use of sts:AssumeRole or sts:GetFederationToken to request temporary security credentials in a different AWS account than the one initiating the request. This can indicate cross-account privilege escalation or lateral movement using identity federation or assumed roles.
Detects modifications to AWS S3 bucket Access Control Lists (ACLs) using the 'PutBucketAcl' API call that grant public read or write permissions. This could indicate an attempt to make sensitive data stored in S3 publicly accessible, potentially leading to data exfiltration.
Detects modifications to IAM role trust policies (UpdateAssumeRolePolicy) or the creation of new roles (CreateRole) where the Principal is configured with a wildcard or generic open access. This configuration enables any AWS account to assume the role, representing a significant risk for privilege escalation and persistence establishment by attackers.
Detects the mass creation of high-performance compute instances (GPU or high-memory variants) in an AWS environment. By filtering out legitimate service-linked roles associated with auto-scaling, the rule isolates potentially unauthorized manual provisioning, often indicative of cryptojacking or resource hijacking.
Detects unauthorized attempts to stop, delete, modify, or change event selectors for AWS CloudTrail logs. This activity is indicative of an attacker attempting to disable audit logging to evade detection while performing further malicious actions in the environment.
