Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the use of AWS CloudShell to execute commands that download or install external files (e.g., using curl, wget, pip, or git), excluding those originating from known approved sources such as AWS-owned domains or standard package registries. This behavior may indicate an adversary attempting to download offensive tooling or backdoors into the cloud environment.
Detects 'PutBucketPolicy' API calls in AWS CloudTrail where the policy is modified to grant 'Allow' access to a wildcard ('*') or anonymous principal, without including restrictive conditional requirements such as VPC endpoints or organizational ID constraints. This behavior is a common precursor to data exfiltration from misconfigured S3 buckets.
Detects modifications to AWS EC2 snapshot or AMI attributes that grant cross-account permissions, including making them publicly accessible. This activity may indicate an attempt to exfiltrate volume data, such as credentials, configuration, or database contents, to an external AWS account.
Detects 'CreateAccessKey' API calls in AWS CloudTrail where the principal making the request is different from the target IAM user. This pattern is commonly associated with persistence mechanisms where an attacker creates additional access keys on legitimate administrator accounts to maintain stealthy access.
Detects unauthorized attempts to disable, suppress, or modify security monitoring services in AWS, including GuardDuty, Security Hub, and AWS Config. This rule monitors for API calls that effectively reduce cloud visibility or detection capabilities, explicitly excluding actions performed by authorized security-engineering roles.
Detects the creation of recurring EventBridge rules or EventBridge Scheduler schedules configured with cron or rate expressions that trigger Lambda functions or SSM automation documents. This activity is a common method for cloud-native persistence, allowing for durable, recurring execution of malicious code that persists across credential rotations or resource deletions, provided the actor is not a recognized platform-engineering entity.
Detects potential persistence mechanisms in AWS by monitoring the creation of new IAM users or roles, the issuance of long-lived credentials (access keys or login profiles), or the creation of roles with permissive cross-account trust policies. This rule specifically excludes known legitimate automation roles to reduce noise.
Detects a rapid burst of read-only IAM and STS API enumeration calls originating from a single source IP address within a one-minute window. This behavior is indicative of automated reconnaissance tools (e.g., enumerate-iam, Pacu) used in the early stages of a cloud attack to identify permissions and potential targets for privilege escalation.
Detects AWS CloudTrail events where an actor performs identity or session token manipulation, specifically through the use of sts:GetFederationToken or sts:AssumeRole, or by modifying MFA configurations such as DeactivateMFADevice or CreateVirtualMFADevice on privileged accounts. This activity may indicate an attempt to gain persistent access, bypass security controls, or masquerade as a legitimate principal.
Detects the modification of EBS snapshot or AMI attributes to add createVolumePermission or launchPermission, which enables sharing the resource with an external AWS account. This action is a common precursor to cross-account data exfiltration or extortion via snapshot/AMI hijacking.
This rule detects typical behavior associated with infostealers targeting browser data, specifically the creation of compressed archives (.zip, .rar) in temporary directories (Temp or AppData) and the subsequent exfiltration of data via known webhook services (e.g., Discord, Telegram, Pastebin) or direct IP connections. It filters out common signed backup and synchronization software to minimize noise.
Detects the ClickFix/fake-CAPTCHA initial access pattern where users are socially engineered into copying and pasting malicious commands into the Windows Run dialog or a browser-spawned shell. The rule matches on process creation events involving mshta.exe, powershell.exe, or wscript.exe initiated by explorer.exe or common shell-related processes, filtering out known administrative and deployment software.
Detects the use of administrative utilities (psexec.exe, wmic.exe, powershell.exe, cmd.exe) initiating network connections over common remote management ports (135, 139, 445, 3389, 5985, 5986) to internal destinations. This behavior is indicative of lateral movement activity, particularly when initiated from a host that has recently engaged in credential harvesting or infostealer-related activity. The rule excludes common, expected sources to minimize noise.
Detects anomalous authentication patterns where a user account accesses a large number of distinct SaaS/SSO resources within a short time frame from devices or IP addresses not previously associated with the user's historical baseline. This behavior is indicative of a stolen session cookie being replayed by an adversary to perform rapid lateral movement across the victim's cloud footprint.
Detects high-volume mailbox item access (MailItemsAccessed) within 15-minute intervals, correlated with risky Entra ID sign-in events within a 60-minute window. This behavior is indicative of automated mail reconnaissance or data exfiltration following potential cloud account compromise.
Detects the granting of high-risk OAuth application scopes (e.g., Mail.Read, offline_access) within two hours of a risky sign-in event for the same user. This pattern is indicative of attackers establishing persistence and maintaining access to sensitive data (such as emails or files) even after potential credential resets.
Detects non-interactive sign-in events in Entra ID that occur without a preceding interactive sign-in session on the same device that successfully satisfied a multi-factor authentication (MFA) challenge. This behavior is indicative of token replay attacks or session hijacking where an adversary attempts to use harvested session cookies or tokens to access resources.
Detects MFA or security information registration, updates, or deletions within Entra ID AuditLogs that occur within two hours of a sign-in event flagged as risky, impossible travel, or involving a new device. This sequence is a common indicator of post-compromise identity persistence.
Detects the addition of a new client secret or certificate to an application or service principal by a user account. This activity is correlated with recent high-risk or suspicious sign-in events. Adversaries often perform this action following account takeover to establish durable, MFA-immune persistence in the cloud tenant.
Detects a suspicious sequence of events where a user performs a device-code authentication flow from a previously unseen application, followed within a two-hour window by sensitive account activities such as OAuth application consent/registration or mailbox-related administrative operations. This behavior is characteristic of passkey-phishing campaigns designed to steal access tokens and achieve persistence or data access via malicious OAuth applications.
Detects the assignment of high-privilege Entra ID directory roles (e.g., Global Administrator) to identities that either have a recent risky sign-in history or were created within the last 48 hours. This pattern is indicative of privilege escalation following account compromise or the creation of backdoored accounts by an attacker. Assignments including change management tracking tags are excluded to reduce noise.
