Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects successful authentication to administrative identity provider consoles that are flagged by identity-provider risk engines as anomalous (e.g., unfamiliar location, new device, or suspicious sign-in properties). This pattern monitors for potential account takeovers or compromised insider activity targeting critical administrative infrastructure, as observed in attacks utilizing recruited or purchased credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects high-volume data exports or bulk API queries against sensitive Salesforce CRM objects (Accounts, Contacts, Cases, Opportunities) performed by connected applications. This pattern is characteristic of exfiltration efforts where a newly authorized OAuth application is used to quickly extract large quantities of sensitive records.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous engineering account activity associated with supply-chain compromise, specifically identifying the generation of access tokens or retrieval of secrets followed by unauthorized changes to CI/CD pipeline configurations or secret stores in platforms like GitHub, JFrog Artifactory, or BrowserStack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized abuse of the OAuth 2.0 device authorization grant flow in Salesforce environments, commonly used by threat actors like ShinyHunters (UNC6240) to gain programmatic access. Attackers register malicious connected apps to impersonate legitimate tools, then use social engineering (vishing) to trick victims into approving device codes. This rule flags token issuance from non-allowlisted connected apps using the device_code grant type.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects successful authentication to administrative identity provider consoles that are flagged by identity-provider risk engines as anomalous (e.g., unfamiliar location, new device, or suspicious sign-in properties). This pattern monitors for potential account takeovers or compromised insider activity targeting critical administrative infrastructure, as observed in attacks utilizing recruited or purchased credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects high-volume data exports or bulk API queries against sensitive Salesforce CRM objects (Accounts, Contacts, Cases, Opportunities) performed by connected applications. This pattern is characteristic of exfiltration efforts where a newly authorized OAuth application is used to quickly extract large quantities of sensitive records.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects anomalous engineering account activity associated with supply-chain compromise, specifically identifying the generation of access tokens or retrieval of secrets followed by unauthorized changes to CI/CD pipeline configurations or secret stores in platforms like GitHub, JFrog Artifactory, or BrowserStack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects high-volume, unauthenticated or anonymous requests (GetObject, ListObjects, ListObjectsV2) against AWS S3 buckets. This behavior is consistent with mass enumeration or scanning activities often associated with data exfiltration attempts against misconfigured publicly-exposed storage buckets.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects OAuth application consent requests that combine broad API access scopes with persistence-enabling scopes (e.g., offline_access or refresh_token). This pattern is consistent with OAuth consent phishing attacks, where adversaries attempt to gain non-interactive, long-term access to an organization's cloud environment via malicious connected applications.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a burst of file access or download operations from SharePoint or OneDrive by a single user account within a short timeframe. This behavior is indicative of bulk data collection or exfiltration, often associated with post-credential-theft activity where an attacker stage and extract organizational data.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects incoming HTTP requests to a FortiSandbox device that contain suspicious command injection patterns. The rule monitors both the URI and the request body for shell metacharacters such as ';', '|', '`', '$(', or '&&', followed by common binary execution commands (e.g., cat, wget, curl, bash, rm). This behavior is indicative of an exploit attempt targeting CVE-2026-39808.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects high-volume data transfers (exceeding 100MB) from internal sources to known external cloud storage and file-sharing platforms. This behavior is consistent with data staging and exfiltration patterns, often used by threat actors to move collected data to attacker-controlled storage infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects high-privilege account management actions in Entra ID (password resets or MFA modifications) performed by service or admin accounts, which are characteristic of social engineering (vishing) attacks targeting IT helpdesks to gain unauthorized access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects unauthorized attempts to delete or purge critical Salesforce audit logs, including the Setup Audit Trail, Login History, and Event Monitoring log files. This behavior is indicative of anti-forensic activity, often utilized by threat actors such as ShinyHunters to destroy audit evidence following unauthorized access, data export, or credential manipulation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
000
Detects a burst of Kerberos TGS-REQ (Ticket-Granting Service Request) messages using RC4 encryption (etype 0x17) over UDP or TCP port 88. A high volume of these requests from a single source within a short timeframe is indicative of Kerberoasting, a technique where an attacker requests service tickets to perform offline password cracking of service account credentials.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects potential NTLM relay attacks targeting Active Directory Certificate Services (AD CS) web enrollment endpoints, including subsequent certificate requests for sensitive templates. This pattern identifies attackers attempting to relay NTLM authentication to AD CS and potentially requesting certificates for high-privilege templates (e.g., DomainController, SubCA, Machine, or User) to facilitate privilege escalation.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects HTTP GET requests to the URI '/dpixel', which is a known default beacon URI pattern associated with the Brute Ratel C4 command and control framework's 'Badger' implant.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects anomalous MS-DRSR DRSGetNCChanges requests occurring between hosts where the requester is not a recognized Domain Controller. This pattern is commonly used by attackers to perform a DCSync attack, allowing for the replication of sensitive Active Directory data such as user password hashes.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects anomalous network traffic patterns characteristic of the PetitPotam exploit, specifically targeting the MS-EFSRPC interface on Windows SMB pipes. This behavior is used to force a remote system to initiate authentication to a specified target, facilitating NTLM relay attacks.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects NTLM authentication attempts targeting administrative network shares (ADMIN$ or C$) over the SMB protocol. This behavior is a common indicator of lateral movement techniques such as Pass-the-Hash, where an adversary uses captured NTLM hashes to authenticate to remote systems.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000
Detects attempts to access or execute a file named 'cmd.jar' within the Cisco Firepower Management Center (FMC) or Cisco Security Manager (CSM) environment. This filename is associated with web shell activities used for unauthorized command execution on vulnerable Cisco appliances.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000