Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
001
Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
Detects a suspected account compromise sequence where an account first authenticates to a Microsoft Teams application from infrastructure associated with TeamFiltration (e.g., specific AWS ranges), followed by a rapid (within 2 minutes) authentication to a VPN or SAML service provider from a different IP address, indicative of an account pivot.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
001
Detects the TeamFiltration/UNK_CondorFiltration spray signature: a large
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
001
Detects the TeamFiltration/UNK_CondorFiltration spray signature: a large
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
101
Detects a suspicious sequence of events where Kubernetes API resources (namespaces, secrets, configmaps, pods, or nodes) are enumerated, followed by a search query against the Slack API, indicative of a potential reconnaissance phase or sandbox escape attempt.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects anomalous POST requests to the RubyGems webhook API endpoint (/api/v1/web_hooks) containing specific indicators ('A000' or 'ZZEND') in the request body, which suggests the misuse of legitimate webhooks for chunked data exfiltration.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
This rule detects network activity associated with the GemStuffer malware, specifically monitoring for DNS queries to known OAST callback domains, HTTP requests to specific C2 paths, and unauthorized data exfiltration attempts to the webhook.site service.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects potential help-desk impersonation or social engineering activity involving account credential or MFA method resets, followed shortly by a sign-in from an unknown device or geography. The rule excludes activity tied to established ticketing systems or standard automated password expiration processes.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects potential help-desk impersonation or social engineering activity involving account credential or MFA method resets, followed shortly by a sign-in from an unknown device or geography. The rule excludes activity tied to established ticketing systems or standard automated password expiration processes.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects potential help-desk impersonation or social engineering activity involving account credential or MFA method resets, followed shortly by a sign-in from an unknown device or geography. The rule excludes activity tied to established ticketing systems or standard automated password expiration processes.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000
Detects anomalous, high-volume file download or export activity originating from a single identity across multiple downstream cloud applications or tenants within a one-hour window. This behavior is indicative of a compromised shared service provider, MSP, or clearinghouse account being leveraged to exfiltrate data from multiple client environments simultaneously. The detection excludes pre-approved service accounts and relies on a dynamic baseline comparison rather than a static threshold.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects anomalous, high-volume file download or export activity originating from a single identity across multiple downstream cloud applications or tenants within a one-hour window. This behavior is indicative of a compromised shared service provider, MSP, or clearinghouse account being leveraged to exfiltrate data from multiple client environments simultaneously. The detection excludes pre-approved service accounts and relies on a dynamic baseline comparison rather than a static threshold.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
6 days ago
000
Detects anomalous, high-volume file download or export activity originating from a single identity across multiple downstream cloud applications or tenants within a one-hour window. This behavior is indicative of a compromised shared service provider, MSP, or clearinghouse account being leveraged to exfiltrate data from multiple client environments simultaneously. The detection excludes pre-approved service accounts and relies on a dynamic baseline comparison rather than a static threshold.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects anomalous, high-volume file download or export activity originating from a single identity across multiple downstream cloud applications or tenants within a one-hour window. This behavior is indicative of a compromised shared service provider, MSP, or clearinghouse account being leveraged to exfiltrate data from multiple client environments simultaneously. The detection excludes pre-approved service accounts and relies on a dynamic baseline comparison rather than a static threshold.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects instances of mshta.exe initiating network connections to cloud storage providers (CloudFront, Cloudflare R2/pages) to retrieve multiple remote files (specifically .js or .txt). This behavior is indicative of an exploit stage where mshta.exe is used as a LOLBAS to fetch orchestrator scripts and gadget payloads for memory-based deserialization attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
This rule detects potential HTML smuggling activity by identifying a browser process writing an executable file named 'config.exe' to the user's Downloads folder without a traditional network download event, followed immediately by Microsoft Defender SmartScreen or Antivirus reporting a warning or scan failure on the file. This behavior is indicative of a payload being reconstructed on the client-side via JavaScript blobs or data URLs, which is a common characteristic of HTML smuggling delivery chains.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
9 days ago
101
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
Defender - KQL
6 days ago
000
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
6 days ago
000
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
avatar
Hunters
6 days ago
000
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
6 days ago
000