Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects successful authentication to administrative identity provider consoles that are flagged by identity-provider risk engines as anomalous (e.g., unfamiliar location, new device, or suspicious sign-in properties). This pattern monitors for potential account takeovers or compromised insider activity targeting critical administrative infrastructure, as observed in attacks utilizing recruited or purchased credentials.
Detects high-volume data exports or bulk API queries against sensitive Salesforce CRM objects (Accounts, Contacts, Cases, Opportunities) performed by connected applications. This pattern is characteristic of exfiltration efforts where a newly authorized OAuth application is used to quickly extract large quantities of sensitive records.
Detects anomalous engineering account activity associated with supply-chain compromise, specifically identifying the generation of access tokens or retrieval of secrets followed by unauthorized changes to CI/CD pipeline configurations or secret stores in platforms like GitHub, JFrog Artifactory, or BrowserStack.
Detects unauthorized abuse of the OAuth 2.0 device authorization grant flow in Salesforce environments, commonly used by threat actors like ShinyHunters (UNC6240) to gain programmatic access. Attackers register malicious connected apps to impersonate legitimate tools, then use social engineering (vishing) to trick victims into approving device codes. This rule flags token issuance from non-allowlisted connected apps using the device_code grant type.
Detects successful authentication to administrative identity provider consoles that are flagged by identity-provider risk engines as anomalous (e.g., unfamiliar location, new device, or suspicious sign-in properties). This pattern monitors for potential account takeovers or compromised insider activity targeting critical administrative infrastructure, as observed in attacks utilizing recruited or purchased credentials.
Detects high-volume data exports or bulk API queries against sensitive Salesforce CRM objects (Accounts, Contacts, Cases, Opportunities) performed by connected applications. This pattern is characteristic of exfiltration efforts where a newly authorized OAuth application is used to quickly extract large quantities of sensitive records.
Detects anomalous engineering account activity associated with supply-chain compromise, specifically identifying the generation of access tokens or retrieval of secrets followed by unauthorized changes to CI/CD pipeline configurations or secret stores in platforms like GitHub, JFrog Artifactory, or BrowserStack.
Detects high-volume, unauthenticated or anonymous requests (GetObject, ListObjects, ListObjectsV2) against AWS S3 buckets. This behavior is consistent with mass enumeration or scanning activities often associated with data exfiltration attempts against misconfigured publicly-exposed storage buckets.
Detects OAuth application consent requests that combine broad API access scopes with persistence-enabling scopes (e.g., offline_access or refresh_token). This pattern is consistent with OAuth consent phishing attacks, where adversaries attempt to gain non-interactive, long-term access to an organization's cloud environment via malicious connected applications.
Detects a burst of file access or download operations from SharePoint or OneDrive by a single user account within a short timeframe. This behavior is indicative of bulk data collection or exfiltration, often associated with post-credential-theft activity where an attacker stage and extract organizational data.
Detects incoming HTTP requests to a FortiSandbox device that contain suspicious command injection patterns. The rule monitors both the URI and the request body for shell metacharacters such as ';', '|', '`', '$(', or '&&', followed by common binary execution commands (e.g., cat, wget, curl, bash, rm). This behavior is indicative of an exploit attempt targeting CVE-2026-39808.
Detects high-volume data transfers (exceeding 100MB) from internal sources to known external cloud storage and file-sharing platforms. This behavior is consistent with data staging and exfiltration patterns, often used by threat actors to move collected data to attacker-controlled storage infrastructure.
Detects high-privilege account management actions in Entra ID (password resets or MFA modifications) performed by service or admin accounts, which are characteristic of social engineering (vishing) attacks targeting IT helpdesks to gain unauthorized access.
Detects unauthorized attempts to delete or purge critical Salesforce audit logs, including the Setup Audit Trail, Login History, and Event Monitoring log files. This behavior is indicative of anti-forensic activity, often utilized by threat actors such as ShinyHunters to destroy audit evidence following unauthorized access, data export, or credential manipulation.
Detects a burst of Kerberos TGS-REQ (Ticket-Granting Service Request) messages using RC4 encryption (etype 0x17) over UDP or TCP port 88. A high volume of these requests from a single source within a short timeframe is indicative of Kerberoasting, a technique where an attacker requests service tickets to perform offline password cracking of service account credentials.
Detects potential NTLM relay attacks targeting Active Directory Certificate Services (AD CS) web enrollment endpoints, including subsequent certificate requests for sensitive templates. This pattern identifies attackers attempting to relay NTLM authentication to AD CS and potentially requesting certificates for high-privilege templates (e.g., DomainController, SubCA, Machine, or User) to facilitate privilege escalation.
Detects HTTP GET requests to the URI '/dpixel', which is a known default beacon URI pattern associated with the Brute Ratel C4 command and control framework's 'Badger' implant.
Detects anomalous MS-DRSR DRSGetNCChanges requests occurring between hosts where the requester is not a recognized Domain Controller. This pattern is commonly used by attackers to perform a DCSync attack, allowing for the replication of sensitive Active Directory data such as user password hashes.
Detects anomalous network traffic patterns characteristic of the PetitPotam exploit, specifically targeting the MS-EFSRPC interface on Windows SMB pipes. This behavior is used to force a remote system to initiate authentication to a specified target, facilitating NTLM relay attacks.
Detects NTLM authentication attempts targeting administrative network shares (ADMIN$ or C$) over the SMB protocol. This behavior is a common indicator of lateral movement techniques such as Pass-the-Hash, where an adversary uses captured NTLM hashes to authenticate to remote systems.
Detects attempts to access or execute a file named 'cmd.jar' within the Cisco Firepower Management Center (FMC) or Cisco Security Manager (CSM) environment. This filename is associated with web shell activities used for unauthorized command execution on vulnerable Cisco appliances.

