Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects the use of AWS CloudShell to execute commands that download or install external files (e.g., using curl, wget, pip, or git), excluding those originating from known approved sources such as AWS-owned domains or standard package registries. This behavior may indicate an adversary attempting to download offensive tooling or backdoors into the cloud environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects 'PutBucketPolicy' API calls in AWS CloudTrail where the policy is modified to grant 'Allow' access to a wildcard ('*') or anonymous principal, without including restrictive conditional requirements such as VPC endpoints or organizational ID constraints. This behavior is a common precursor to data exfiltration from misconfigured S3 buckets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects modifications to AWS EC2 snapshot or AMI attributes that grant cross-account permissions, including making them publicly accessible. This activity may indicate an attempt to exfiltrate volume data, such as credentials, configuration, or database contents, to an external AWS account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects 'CreateAccessKey' API calls in AWS CloudTrail where the principal making the request is different from the target IAM user. This pattern is commonly associated with persistence mechanisms where an attacker creates additional access keys on legitimate administrator accounts to maintain stealthy access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects unauthorized attempts to disable, suppress, or modify security monitoring services in AWS, including GuardDuty, Security Hub, and AWS Config. This rule monitors for API calls that effectively reduce cloud visibility or detection capabilities, explicitly excluding actions performed by authorized security-engineering roles.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the creation of recurring EventBridge rules or EventBridge Scheduler schedules configured with cron or rate expressions that trigger Lambda functions or SSM automation documents. This activity is a common method for cloud-native persistence, allowing for durable, recurring execution of malicious code that persists across credential rotations or resource deletions, provided the actor is not a recognized platform-engineering entity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects potential persistence mechanisms in AWS by monitoring the creation of new IAM users or roles, the issuance of long-lived credentials (access keys or login profiles), or the creation of roles with permissive cross-account trust policies. This rule specifically excludes known legitimate automation roles to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a rapid burst of read-only IAM and STS API enumeration calls originating from a single source IP address within a one-minute window. This behavior is indicative of automated reconnaissance tools (e.g., enumerate-iam, Pacu) used in the early stages of a cloud attack to identify permissions and potential targets for privilege escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects AWS CloudTrail events where an actor performs identity or session token manipulation, specifically through the use of sts:GetFederationToken or sts:AssumeRole, or by modifying MFA configurations such as DeactivateMFADevice or CreateVirtualMFADevice on privileged accounts. This activity may indicate an attempt to gain persistent access, bypass security controls, or masquerade as a legitimate principal.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the modification of EBS snapshot or AMI attributes to add createVolumePermission or launchPermission, which enables sharing the resource with an external AWS account. This action is a common precursor to cross-account data exfiltration or extortion via snapshot/AMI hijacking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
This rule detects typical behavior associated with infostealers targeting browser data, specifically the creation of compressed archives (.zip, .rar) in temporary directories (Temp or AppData) and the subsequent exfiltration of data via known webhook services (e.g., Discord, Telegram, Pastebin) or direct IP connections. It filters out common signed backup and synchronization software to minimize noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the ClickFix/fake-CAPTCHA initial access pattern where users are socially engineered into copying and pasting malicious commands into the Windows Run dialog or a browser-spawned shell. The rule matches on process creation events involving mshta.exe, powershell.exe, or wscript.exe initiated by explorer.exe or common shell-related processes, filtering out known administrative and deployment software.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the use of administrative utilities (psexec.exe, wmic.exe, powershell.exe, cmd.exe) initiating network connections over common remote management ports (135, 139, 445, 3389, 5985, 5986) to internal destinations. This behavior is indicative of lateral movement activity, particularly when initiated from a host that has recently engaged in credential harvesting or infostealer-related activity. The rule excludes common, expected sources to minimize noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects anomalous authentication patterns where a user account accesses a large number of distinct SaaS/SSO resources within a short time frame from devices or IP addresses not previously associated with the user's historical baseline. This behavior is indicative of a stolen session cookie being replayed by an adversary to perform rapid lateral movement across the victim's cloud footprint.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects high-volume mailbox item access (MailItemsAccessed) within 15-minute intervals, correlated with risky Entra ID sign-in events within a 60-minute window. This behavior is indicative of automated mail reconnaissance or data exfiltration following potential cloud account compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the granting of high-risk OAuth application scopes (e.g., Mail.Read, offline_access) within two hours of a risky sign-in event for the same user. This pattern is indicative of attackers establishing persistence and maintaining access to sensitive data (such as emails or files) even after potential credential resets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects non-interactive sign-in events in Entra ID that occur without a preceding interactive sign-in session on the same device that successfully satisfied a multi-factor authentication (MFA) challenge. This behavior is indicative of token replay attacks or session hijacking where an adversary attempts to use harvested session cookies or tokens to access resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects MFA or security information registration, updates, or deletions within Entra ID AuditLogs that occur within two hours of a sign-in event flagged as risky, impossible travel, or involving a new device. This sequence is a common indicator of post-compromise identity persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the addition of a new client secret or certificate to an application or service principal by a user account. This activity is correlated with recent high-risk or suspicious sign-in events. Adversaries often perform this action following account takeover to establish durable, MFA-immune persistence in the cloud tenant.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects a suspicious sequence of events where a user performs a device-code authentication flow from a previously unseen application, followed within a two-hour window by sensitive account activities such as OAuth application consent/registration or mailbox-related administrative operations. This behavior is characteristic of passkey-phishing campaigns designed to steal access tokens and achieve persistence or data access via malicious OAuth applications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000
Detects the assignment of high-privilege Entra ID directory roles (e.g., Global Administrator) to identities that either have a recent risky sign-in history or were created within the last 48 hours. This pattern is indicative of privilege escalation following account compromise or the creation of backdoored accounts by an attacker. Assignments including change management tracking tags are excluded to reduce noise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
5 days ago
000