Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous Entra ID sign-in patterns indicating potential session hijacking or stolen session cookie replay. The rule identifies pairs of successful sign-ins where the geographic distance and time elapsed suggest impossible travel, or where the device/browser context changes without a fresh MFA challenge, suggesting the bypass of authentication requirements via persistent session tokens.
Detects instances where a user performs high-risk sign-in activities (such as impossible travel or triggered risk events) followed by the registration of new security information, MFA methods, or rogue OAuth devices within a 30-minute window. This behavior is indicative of an attacker establishing persistence on a compromised account by bypassing or hardening MFA requirements.
Detects activity indicative of the 'ClickFix' social engineering technique, where users are tricked into manually executing obfuscated commands (often from fake CAPTCHA or error prompts) via the Windows Run dialog or command-line interfaces. The rule correlates suspicious process execution (e.g., mshta, powershell, certutil, curl) originating from explorer.exe with the detection of common encoded/obfuscated command line patterns, or interactions with the Windows RunMRU registry key, which logs commands typed into the Run dialog.
Detects a multi-stage activity chain indicative of infostealer malware, including reading the browser 'Local State' file (containing the master key), accessing a browser process (likely for memory dumping or token extraction), and initiating an immediate outbound network connection to an external destination.
Detects unauthorized access to common browser credential storage files (Login Data, Cookies, Web Data, Local State) by processes other than standard web browsers. This rule identifies potentially malicious activity by filtering for rare or unsigned binaries executing from common staging directories (Temp, Downloads) or accessing browser files shortly after the process launch, which is a common behavior pattern for info-stealer malware.
Detects successful authentication attempts using legacy protocols or non-interactive refresh tokens for user accounts previously flagged within a 14-day window as being involved in infostealer or credential exposure events.
Detects attempts to enumerate or access Windows Credential Manager and vault files, often used by adversaries to extract cached credentials. The rule monitors for execution of vaultcmd.exe, invocation of keymgr.dll via rundll32.exe, and unauthorized access to credential storage paths in AppData by non-system processes.
This rule detects potential session hijacking by monitoring for the reuse of session or refresh tokens from unrecognized devices, browsers, or user agents, particularly when such activity occurs without an interactive MFA challenge. This behavior is indicative of an attacker attempting to use stolen session cookies or tokens to access cloud resources.
Detects processes that access multiple categories of sensitive data (browser autofill, cryptocurrency wallets, password manager exports, or system fingerprinting files) within a short time window. This behavior is highly indicative of modular infostealers or data-collection malware conducting 'stacking access' to stage sensitive information for exfiltration.
This rule detects network connections initiated by unsigned executables that were recently created (within one hour) in common staging directories such as AppData, Temp, or ProgramData. It specifically targets beacons to the Telegram Bot API or Discord webhooks, which are common patterns for command-and-control (C2) communication used by malware such as the Amadey bot.
This rule detects potentially malicious OAuth application consent grants where a user authorizes an application with high-privilege scopes (such as mail or directory access). The detection flags consent grants for applications that are either unverified by the publisher or newly created within the last 30 days, and correlates these events with suspicious sign-in activity (high/medium risk or failures) for the same user within a two-hour window.
Detects the creation or modification of inbox rules in Office 365 that exhibit suspicious characteristics, such as external forwarding, automatic deletion/moving of sensitive emails (e.g., security alerts, junk), or rules containing keywords related to fraud. The rule optionally correlates this activity with recent anomalous sign-in attempts by the same user to identify potential account compromise.
Detects potential reconnaissance or data collection activity within Office 365 Exchange mailboxes. The rule monitors for mailbox access operations (MailItemsAccessed, SearchQueryInitiated, FolderBind, or MessageBind) originating from new or uncommon application IDs, IP addresses, or ASNs for a specific user, or indicates bulk folder enumeration behavior in a short timeframe, which may suggest session token reuse or unauthorized mailbox access.
Detects an anomalous volume of file downloads from cloud storage platforms (SharePoint, OneDrive, Google Drive, Box) occurring within two hours of a high or medium risk sign-in event, including impossible travel or token replay scenarios. This pattern is indicative of potential data exfiltration by an actor using compromised credentials.
Detects potential lateral movement by users who have recently been flagged for credential theft or infostealer activity. The rule correlates initial security alerts with subsequent Windows logon events (RDP, network/WinRM) or SMB share access, identifying users connecting to multiple distinct destinations within a 48-hour window.
Detects a hybrid identity attack sequence where an anomalous or high-risk cloud sign-in (e.g., AD FS, Azure AD Connect) is followed within 24 hours by suspicious on-premise Active Directory activity, specifically DCSync replication requests or Kerberoasting (high volume of TGS requests). This pattern is indicative of an attacker leveraging stolen cloud session tokens to pivot into on-premise infrastructure.
Detects the assignment of high-privilege roles to cloud user accounts in Entra ID, AWS, or GCP when that assignment is preceded by anomalous sign-in behavior (high-risk or failed authentication) within 24 hours, or when the account appears to be dormant (no activity in 90+ days) prior to the privilege assignment.
Detects mass device management actions (e.g., remote wipe, retire, or delete) performed via the Microsoft Intune console by a user who has simultaneously exhibited risky sign-in behavior, potentially indicating a compromised administrative account.
Detects the mounting of VHDX files via disk imaging tools or PowerShell, followed shortly (within 15 minutes) by the execution of a shell process with hidden window flags. This behavioral pattern is associated with the delivery of malicious payloads, such as those observed in Star Blizzard's RedFlick delivery chain for CosmicPulse.
Detects the creation of specific decoy scheduled tasks ('Internet Quality Test Connection', 'Network Configuration Manager', 'System Health Monitor') identified as part of the Star Blizzard actor's CosmicPulse delivery mechanism. The rule monitors for the creation of these tasks via schtasks.exe or system events, specifically when the task configuration references execution via rundll32.exe, regsvr32.exe, control.exe, or remote/UNC-based payloads.
Detects the execution of a Control Panel (.cpl) item using control.exe or rundll32.exe. The rule specifically looks for CPL files that were recently written to suspicious directories (Temp, AppData, Downloads) and correlates this execution with subsequent suspicious behaviors, such as spawning Python processes, outbound network connections, or registry modifications consistent with key storage or payload persistence.

