Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects OAuth application consent grant events where an application name matches common 'Data Loader' naming conventions and requests high-privilege scopes (read/write/full/api). This pattern is consistent with consent phishing campaigns used by threat actors to gain persistent access to SaaS environments like M365 or Salesforce.
Detects the execution of TruffleHog, an automated secret-scanning CLI tool, often utilized by threat actors to harvest sensitive credentials from local filesystems, repositories, environment variables, or CI/CD configuration files following unauthorized access.
Detects high-volume, anomalous data read operations performed by the Gainsight integration service account within Salesforce, which may indicate unauthorized use of the integration token for data exfiltration.
Detects anomalous, high-volume data access patterns within Salesforce, specifically monitoring for bulk API or SOQL query requests by a single user or application. This behavior is indicative of mass data exfiltration from a CRM instance, a tactic observed in extortion-themed campaigns such as those associated with the ShinyHunters group.
Detects the execution of the GigaWiper malware or the use of common system commands associated with destructive data activities, such as recursive file removal, disk formatting, or secure data overwriting, often used by threat actors for extortion.
Detects high-frequency HTTP requests targeting Salesforce Aura endpoints associated with structural introspection, such as retrieving component definitions or field metadata. This behavior is consistent with the use of the AuraInspector reconnaissance tool to map the internal structure of a Salesforce application.
Detects unauthorized access to CRM platforms (Salesforce) using Salesloft or Drift OAuth tokens, where the source IP address does not match the known legitimate service provider IP ranges. This behavior is indicative of potential token theft or misuse, particularly relevant to supply-chain campaign activities.
Detects authentication to Snowflake instances where Multi-Factor Authentication (MFA) is absent and the account authenticates from multiple distinct source IP addresses within a 14-day window. This behavior is indicative of potential account takeover using compromised non-MFA credentials, a pattern consistent with activities attributed to threat actors like ShinyHunters/UNC5537.
Detects high-volume database or CRM read activity performed by a user, followed by significant outbound network traffic to known public cloud storage, file-sharing, or messaging services. This pattern is consistent with data staging and exfiltration behaviors often attributed to the ShinyHunters threat actor group.
Detects a pattern associated with ShinyHunters/UNC6040, where a user authorizes a new or rarely-used OAuth connected application shortly after performing a help-desk initiated password reset or MFA re-enrollment, originating from a different geographic location.
Detects successful OAuth token grant events for specific third-party SaaS integrations (Salesloft, Drift, Gainsight) where requested scopes include broad permissions such as 'api', 'refresh_token', or 'full'. This pattern is indicative of potential consent phishing or the abuse of a compromised OAuth application to maintain persistent, high-privileged access to SaaS resources.
Detects unauthenticated guest users abusing the Salesforce Experience Cloud Aura endpoint (/s/sfsites/aura) to perform high-volume metadata and schema enumeration. This activity typically involves tools like AuraInspector to harvest CRM data by repeatedly invoking Aura actions such as describeSObjects, getSObjectMetadata, ObjectInfoController, or RecordUiController.
Detects anomalous AWS IAM and Secrets Manager API activity indicative of credential abuse following suspected exposure. The rule identifies suspicious patterns such as unauthorized enumeration of access keys, secret retrieval, and creation of new keys by non-service principals, reflecting activity associated with ShinyHunters-style operations where compromised credentials are abused.
Detects successful authentication to administrative identity provider consoles that are flagged by identity-provider risk engines as anomalous (e.g., unfamiliar location, new device, or suspicious sign-in properties). This pattern monitors for potential account takeovers or compromised insider activity targeting critical administrative infrastructure, as observed in attacks utilizing recruited or purchased credentials.
Detects high-volume data exports or bulk API queries against sensitive Salesforce CRM objects (Accounts, Contacts, Cases, Opportunities) performed by connected applications. This pattern is characteristic of exfiltration efforts where a newly authorized OAuth application is used to quickly extract large quantities of sensitive records.
Detects anomalous engineering account activity associated with supply-chain compromise, specifically identifying the generation of access tokens or retrieval of secrets followed by unauthorized changes to CI/CD pipeline configurations or secret stores in platforms like GitHub, JFrog Artifactory, or BrowserStack.
Detects unauthorized abuse of the OAuth 2.0 device authorization grant flow in Salesforce environments, commonly used by threat actors like ShinyHunters (UNC6240) to gain programmatic access. Attackers register malicious connected apps to impersonate legitimate tools, then use social engineering (vishing) to trick victims into approving device codes. This rule flags token issuance from non-allowlisted connected apps using the device_code grant type.
Detects successful authentication to administrative identity provider consoles that are flagged by identity-provider risk engines as anomalous (e.g., unfamiliar location, new device, or suspicious sign-in properties). This pattern monitors for potential account takeovers or compromised insider activity targeting critical administrative infrastructure, as observed in attacks utilizing recruited or purchased credentials.
Detects high-volume data exports or bulk API queries against sensitive Salesforce CRM objects (Accounts, Contacts, Cases, Opportunities) performed by connected applications. This pattern is characteristic of exfiltration efforts where a newly authorized OAuth application is used to quickly extract large quantities of sensitive records.
Detects anomalous engineering account activity associated with supply-chain compromise, specifically identifying the generation of access tokens or retrieval of secrets followed by unauthorized changes to CI/CD pipeline configurations or secret stores in platforms like GitHub, JFrog Artifactory, or BrowserStack.
Detects high-volume, unauthenticated or anonymous requests (GetObject, ListObjects, ListObjectsV2) against AWS S3 buckets. This behavior is consistent with mass enumeration or scanning activities often associated with data exfiltration attempts against misconfigured publicly-exposed storage buckets.
