Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a multi-stage phishing pattern attributed to Star Blizzard (also known as Callisto Group or COLDRIVER). The attack involves an initial email containing no attachments to establish trust or initiate a thread, followed by a subsequent reply-thread email containing both an archive file (ZIP/RAR) and an image file. This technique is designed to bypass email security scanners by hiding the archive password within the image attachment or obscuring the malicious payload context.
Detects potential DNS tunneling or command-and-control (C2) traffic by identifying abnormally long DNS query names, which often indicate encoded data channels, and suspicious usage of TXT or NULL DNS records, which are frequently used by tools like Cobalt Strike, dnscat2, and iodine for C2 communication.
Detects successful RDP (Remote Desktop Protocol) logon events (Event ID 4624, Logon Type 10) where the source IP address is outside the predefined internal network ranges. This behavior is indicative of potential lateral movement, where an attacker attempts to access internal systems from an external, non-corporate source.
Detects HTTP redirect chains originating from common webmail providers to URLs containing suspicious login-related keywords or obfuscated brand look-alike domains, which is indicative of credential harvesting or phishing activity.
Detects Log4Shell (CVE-2021-44228) exploitation attempts by identifying JNDI lookup patterns (e.g., ldap://, rmi://, dns://) and common obfuscation techniques within HTTP headers, user-agents, and query parameters, which could lead to remote code execution.
Detects unauthorized processes requesting memory access to lsass.exe with read permissions commonly associated with credential dumping techniques like Mimikatz. It identifies remote handle requests to lsass.exe, which are frequently used by tools deployed via network services or remote execution methods to extract credentials from memory.
Detects a high volume of failed SSH password authentication attempts from a single source IP address against one or more target hosts within a short time window, which is indicative of an SSH brute-force attack.
Detects Android device management (MDM) components (specifically 'com.corp.mdm') re-launching registration or sticky services upon system events such as boot completion, quick-boot, or package updates. This monitoring is intended to identify persistent components that maintain functionality across device restarts.
Detects unauthorized or suspicious use of USSD codes by the corporate MDM agent to modify call-forwarding settings. This activity is indicative of a compromise where an attacker uses an MDM-controlled device to intercept calls or divert communications.
KQL Query from file: HBO Max PasteSwitch IOC Detected
Detects the addition of new members to a GitHub organization or team outside of standard business hours. This behavior is correlated with potential subsequent grants of repository administrative access or read access to secrets, characteristic of attacker patterns attempting to gain unauthorized access to cloud environments and OAuth tokens via CI/CD pipelines or VCS platforms.
Detects a single Salesforce user or connected-app session performing an anomalous volume of SOQL queries against sensitive objects including Case, Account, Contact, and Opportunity. This behavior is indicative of mass data enumeration and potential exfiltration, as observed in historical incidents where attackers targeted CRM platforms to extract embedded secrets and sensitive record data.
Detects OAuth application consent events in Entra ID where the application display name mimics legitimate services like Salesforce or Data Loader while requesting high-risk API scopes (full_access, offline_access, api). This behavior is characteristic of phishing-driven OAuth grant campaigns, such as those observed by the ShinyHunters group.
Monitors SaaS application integration service accounts (e.g., Salesforce connected apps) by establishing baselines for API call volume and accessed object types. The rule alerts on anomalous spikes in usage or deviations in the scope of accessed data objects, which could indicate the abuse of compromised OAuth tokens following a vendor supply-chain compromise.
Detects anomalous anti-forensic behavior where a Salesforce Bulk API query job is deleted shortly after its creation or completion. This sequence is often associated with efforts to obscure data exfiltration activities by removing the metadata trail of bulk data exports.
Detects anomalous Salesforce API export patterns where a user or connected application maintains a daily record export volume below typical burst thresholds, yet accumulates a high total volume over a rolling 7-day period. This pattern mimics 'low-and-slow' data exfiltration techniques used by actors like ShinyHunters to evade standard volume-based DLP alerts.
Detects the use of native Windows administration utilities (vssadmin, wbadmin, bcdedit, wmic) to delete volume shadow copies, backup catalogs, or disable system recovery configurations. The rule specifically monitors for patterns where these commands are executed across multiple hosts or in rapid succession by the same account, behavior frequently observed during the precursor stages of ransomware deployment, such as the ShinyHunters ShinySp1d3r campaign.
Detects an Android device registration attempt to a known malicious C2 IP address using parameters characteristic of a mobile device management (MDM) implant. The rule looks for a POST request to a specific registration endpoint containing device identifiers like deviceId, manufacturer, model, and osVersion.
Detects Salesforce Experience Cloud guest user sessions performing queries or reads on objects not within the authorized allowlist. This behavior, characterized by an abnormal volume of records retrieved or anomalous query patterns, is consistent with attempts to exploit misconfigured guest profile permissions to access internal sensitive data.
Detects anomalous large-scale data export operations in Google BigQuery (via jobs.insert or jobs.query) performed by identities (service accounts, API keys) not previously observed in the environment. This activity is indicative of credential abuse where stolen third-party analytics or monitoring service tokens are utilized for illicit data exfiltration, a behavior consistent with tactics employed by threat actors such as ShinyHunters.
Detects anomalous large-scale data export operations in Google BigQuery (via jobs.insert or jobs.query) performed by identities (service accounts, API keys) not previously observed in the environment. This activity is indicative of credential abuse where stolen third-party analytics or monitoring service tokens are utilized for illicit data exfiltration, a behavior consistent with tactics employed by threat actors such as ShinyHunters.


