Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
KQL Query from file: CSuite Campaign - Known Payload File Hash Hunt
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
This rule detects malicious activity associated with the Bazinga macOS backdoor, specifically focusing on the clearing of TCC privacy permissions, the staging of keychain and browser data using 'ditto', and the subsequent exfiltration of this data to a remote host via 'curl'.
Detects anomalous execution of the Microsoft Support Diagnostic Tool (msdt.exe) or its host process (sdiagnhost.exe) when spawned by Microsoft Office applications or when invoked with specific command-line arguments indicative of the CVE-2022-30190 (Follina) exploit.
Detects potential password spraying activity in Azure Active Directory by identifying a single source IP address that authenticates against multiple distinct user accounts within a short time frame. The rule flags instances where there are numerous authentication attempts across many users, characterized by a low per-user failure count followed by at least one successful authentication, which is indicative of a successful password spray attempt.
Detects potential password spraying activity in Azure Active Directory by identifying a single source IP address that authenticates against multiple distinct user accounts within a short time frame. The rule flags instances where there are numerous authentication attempts across many users, characterized by a low per-user failure count followed by at least one successful authentication, which is indicative of a successful password spray attempt.
Detects attempts to exploit CVE-2021-36934 (HiveNightmare/SeriousSAM) by monitoring for unauthorized access to SAM, SYSTEM, or SECURITY hive files within Volume Shadow Copies, or the use of icacls/vssadmin to facilitate this credential access.
This rule monitors for two indicators of potentially malicious WinRM activity: first, the execution of suspicious child processes (e.g., cmd.exe, powershell.exe, rundll32.exe, certutil.exe) originating from the Windows Remote Management host process (wsmprovhost.exe); and second, a 'fan-out' pattern where a single account establishes WinRM/PSRemoting sessions on three or more distinct hosts within a short time window, which is often indicative of automated lateral movement or credential abuse.
Detects the use of MSBuild.exe to compile and execute inline code or tasks. The rule identifies suspicious command-line patterns (such as Task/CodeTaskFactory), execution from non-standard directories (Temp, AppData, Downloads, etc.), and subsequent network or child process activity originating from these MSBuild instances, indicating potential defense evasion or code execution.
This rule detects potentially malicious activity originating from Microsoft Word (WINWORD.EXE). It monitors for two specific patterns: the creation of script files (.bat, .vbs, .cmd) with GUID-based filenames in non-temp directories, and the creation or execution of files matching known malicious hashes associated with the Hookedge malware family.
KQL Query from file: ThreatFox IOC Hunt feed
This rule detects potentially malicious activity involving LNK files being modified, created, or renamed in common locations (Desktop, Quick Launch, Start Menu) correlated with the creation of files ending in '.backup' within 30 minutes. It also independently detects the presence or execution of 'VLCAssistant.exe', which may indicate unauthorized launcher activity or masquerading.
Detects Microsoft Entra ID service principal (app-only) sign-in events where an application accesses a resource or tenant that has not been observed in the previous 30 days. This is often an indicator of cross-tenant impersonation abuse or credential misuse, particularly related to Actor Tokens.
This rule detects inbound emails where the sender domain matches the recipient domain (internal-looking), but the message authentication (SPF/DKIM/DMARC as indicated by CompAuth status) failed or was not performed. This is indicative of abuse of Exchange Online 'Direct Send' or similar unauthenticated relay methods to spoof internal identities.
This rule detects large-scale, non-interactive password-spraying campaigns targeting Microsoft Entra ID (Azure AD) accounts. It specifically identifies anomalous login behavior originating from Azure CLI or similar non-interactive clients, where a single source IP attempts to authenticate against a large number of distinct user accounts with a low number of failures per user within a short timeframe, characteristic of 'low-and-slow' password spraying.
Detects anomalous, high-frequency, multi-channel probing of AI agent input surfaces. The rule identifies external actors sending instruction-injection style keywords across different communication channels (e.g., email, Teams, calendar) within a short window, which may indicate an attempt to identify and manipulate an organization's autonomous agents. Covers T1595.002
Detects anomalous, high-frequency, multi-channel probing of AI agent input surfaces. The rule identifies external actors sending instruction-injection style keywords across different communication channels (e.g., email, Teams, calendar) within a short window, which may indicate an attempt to identify and manipulate an organization's autonomous agents. Covers T1595.002
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
Detects anomalous multi-agent chaining where one AI-enabled agent instance initiates a connection to an AI API and subsequently hands off information to a second, distinct agent instance, which then performs an suspicious downstream action such as spawning a shell or initiating an unauthorized external network connection. This behavior is intended to identify potential abuse of AI-coding assistant tools for automated execution chains.
Detects potential AI-targeted cloaking, a technique where a web server serves different content to AI crawlers versus human users, identified by comparing HTTP response sizes or hashes across session logs. The rule uses Microsoft Sentinel's ASIM Web Session schema to correlate web requests, identifying discrepancies that suggest malicious or evasive intent. Covers T1036 & T1027

