Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects DLL side-loading where a known legitimate signed executable, often associated with security utilities, loads a DLL from a non-standard, user-writable directory (such as Temp, AppData, or ProgramData). This behavior is characteristic of APT10's (Stone Panda/Cicada) historical tradecraft in MSP environments to execute modular PlugX RAT payloads.
Detects lateral movement via PsExec (PSEXESVC) followed by mass file encryption/rename activities and the creation of ransom note files, characteristic of Wizard Spider's deployment of Conti ransomware.
Detects network indicators associated with the Exvicy/ErrTraffic 'ClickFix' campaign. The rule identifies the retrieval of malicious HTML lure templates from compromised WordPress sites and subsequent telemetry/registration calls to an attacker-controlled 'api.php' script, which are precursors to the fake Cloudflare Turnstile 'Win+R' execution sequence.
Detects the execution of script interpreters (powershell, cmd, mshta, etc.) spawned directly by explorer.exe via the Run dialog, commonly associated with 'ClickFix' social engineering attacks where users are prompted to copy and paste malicious commands to bypass security mechanisms.
Detects instances where a user account registers a new Multi-Factor Authentication (MFA) method (such as TOTP or Authenticator app) shortly (within 30 minutes) after a high-risk or potentially anomalous sign-in event. This pattern is commonly associated with adversary-in-the-middle (AiTM) phishing attacks where an attacker captures an authenticated session and uses it to enroll a secondary, attacker-controlled MFA device for persistent account access.
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
Detects successful authentication events for accounts that have been dormant for at least 90 days, correlated with suspicious activity markers such as recent failed sign-in attempts, access from an unfamiliar geographic location or ASN, or a complete absence of historical sign-in activity.
Detects successful authentication events for accounts that have been dormant for at least 90 days, correlated with suspicious activity markers such as recent failed sign-in attempts, access from an unfamiliar geographic location or ASN, or a complete absence of historical sign-in activity.
Detects patterns associated with the TeamFiltration backdoor module, specifically unauthorized OneDrive/SharePoint file modifications occurring shortly after an authentication from a previously unseen device/IP. The rule flags file changes (modifications, deletions, or renames) involving potential executable or script extensions, or those performed by the OneDrive SyncEngine app from a new source.
Detects high-volume account enumeration activity associated with the TeamFiltration tool, characterized by the use of legacy Microsoft Teams desktop client User-Agent strings (specific versions of Teams, Electron, and Chrome) within a short time window.
Detects high-volume account enumeration activity associated with the TeamFiltration tool, characterized by the use of legacy Microsoft Teams desktop client User-Agent strings (specific versions of Teams, Electron, and Chrome) within a short time window.
Detects high-volume account enumeration activity associated with the TeamFiltration tool, characterized by the use of legacy Microsoft Teams desktop client User-Agent strings (specific versions of Teams, Electron, and Chrome) within a short time window.
Detects the 'auto-exfil' pattern associated with the TeamFiltration tool. The rule identifies a sequence of SharePoint Online file access immediately followed by a Microsoft Graph token request from the SharePoint Online Web Client Extensibility app. To reduce noise, it mandates a very short time delta between events (<= 60 seconds) combined with either the use of an IP address/ASN not previously seen for the account in the last 14 days, or a preceding failed sign-in attempt for the account.
Detects the 'auto-exfil' pattern associated with the TeamFiltration tool. The rule identifies a sequence of SharePoint Online file access immediately followed by a Microsoft Graph token request from the SharePoint Online Web Client Extensibility app. To reduce noise, it mandates a very short time delta between events (<= 60 seconds) combined with either the use of an IP address/ASN not previously seen for the account in the last 14 days, or a preceding failed sign-in attempt for the account.
Detects the 'auto-exfil' pattern associated with the TeamFiltration tool. The rule identifies a sequence of SharePoint Online file access immediately followed by a Microsoft Graph token request from the SharePoint Online Web Client Extensibility app. To reduce noise, it mandates a very short time delta between events (<= 60 seconds) combined with either the use of an IP address/ASN not previously seen for the account in the last 14 days, or a preceding failed sign-in attempt for the account.
Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
Detects the TeamFiltration/UNK_CondorFiltration spray signature: a large
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.


