Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects multiple reconnaissance commands executed by PowerShell processes running as the SYSTEM account. This behavior is indicative of an attacker attempting to enumerate domain trusts, group memberships, or user sessions on a host to facilitate lateral movement or privilege escalation.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
This rule detects potential ClickFix/InstallFix attacks where a user is socially engineered to copy and paste a malicious command from a website that mimics a legitimate developer tool installation (e.g., Claude Code, NotebookLM). The detection flags the use of common download-and-execute cmdlets (e.g., irm, iwr, iex) within common Windows shell interpreters while excluding known legitimate vendor install domains.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects a sequence of potentially malicious local command execution (via PowerShell, cmd, or mshta) that mirrors the 'ClickFix' social engineering pattern, followed by an OAuth application consent grant or device-code authorization by the same user within a short timeframe. This behavior is indicative of an adversary attempting to bypass MFA by tricking a user into authorizing a malicious application after establishing local execution on their endpoint.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the simultaneous activation of three or more distinct browser profiles on the same device within a one-hour window. This behavior is used as a proxy for browser session hijacking or 'browser sync' attacks, where an adversary bridges a compromised personal identity into a managed corporate browser environment.
Detects the execution of 'LevelInstaller.exe' with specific installation arguments ('--action install --force --key') in conjunction with the presence of the 'level.exe' binary in its designated Program Files directory. The rule optionally identifies related scheduled task creation for 'Level Watchdog' and network activity associated with the 'level.io' domain or specific IP address.
This rule detects potentially malicious usage of msiexec.exe where the command line contains obfuscation techniques such as excessive spacing, Unicode character substitution, or suspicious case variations. It specifically looks for activity initiated by common shell processes like explorer.exe or cmd.exe that involves the /package argument or URL-based loading, which is a common indicator of MSI-based payload delivery.
Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.
Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.
Detects potential session hijacking where an Entra ID session is reused by a non-managed/non-compliant device from a different IP and country shortly after an initial authentication from a managed device. This pattern is consistent with infostealer malware stealing session tokens and replaying them on attacker-controlled infrastructure to bypass MFA.
Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.
Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.
Detects anomalous device-authorization-grant (RFC 8628) activity indicative of device-code phishing attacks (e.g., Tycoon2FA). The rule identifies user accounts exhibiting a rapid succession of 'authorization_pending' (70016) status polling attempts followed by a successful token issuance (0), constrained to a short time window and excluding known first-party Microsoft CLI/dev-tool applications.

