Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects Azure AD user sign-ins from multiple distinct IP addresses or countries within a 1-hour window. This is a common heuristic used to identify potentially compromised credentials or impossible travel scenarios, where a single user account authenticates from geographically distant or disparate network locations in an unrealistic timeframe.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
15 days ago
104
Detects potential OAuth device code phishing attempts by identifying sign-ins via the device code flow using applications not previously used by the specific user, especially when occurring in a burst pattern across multiple users.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
101
Detects a suspicious execution chain where a browser process makes a network connection, followed shortly by a direct execution of command-line tools (powershell.exe, mshta.exe, or cmd.exe) from the Windows explorer.exe process (e.g., via the Run dialog). This behavior is characteristic of 'ClickFix' social engineering attacks where users are tricked into copying and pasting malicious commands from a web page directly into their local environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
201
This rule detects potential social engineering attacks where an external or federated user impersonates an IT or helpdesk entity within Microsoft Teams (via chats, messages, or calls) followed shortly by an MFA registration or password reset event for the targeted user. This sequence is indicative of a vishing or phishing attack aimed at account takeover.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
501
Detects instances where a user account modifies security information, registers a new MFA method, or resets a password shortly after a successful sign-in from a country not observed for that user within the previous 30 days. This pattern is indicative of potential account takeover where an adversary adds persistence or MFA bypass methods to a newly compromised account.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects MFA fatigue or push-bombing attacks where a user account experiences an abnormally high volume of MFA request denials in a short duration (10 minutes), followed by a successful authentication event. The rule specifically looks for evidence where the successful authentication potentially originates from a different IP address than the failed attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects phishing emails containing suspicious URLs pointing to PaaS platforms (Azure Static Web Apps, Cloudflare, Firebase) that exhibit credential harvesting characteristics (branded keywords or base64 patterns). The rule correlates these emails with subsequent clicks and a successful M365 sign-in by the same user within 30 minutes of the click, indicating a probable successful credential compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects inbound .ics calendar invite attachments that contain URLs, originating from sender domains not previously seen within the organization over the last 90 days, and distributed to 10 or more recipients. This pattern is indicative of a mass-distributed phishing campaign using calendar invites as a lure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule detects mass phishing campaigns by identifying HTML/HTM email attachments that contain embedded URLs. It monitors for a pattern where the same sender distributes these attachments to multiple recipients, a common behavior for HTML smuggling delivery vectors where malicious payloads are constructed client-side to bypass static email gateway inspection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects newly consented OAuth applications that immediately perform mass access or exfiltration of mail and file data across multiple mailboxes or drives within a short period, potentially indicating an attacker utilizing a malicious OAuth application.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
301
Detects inbound emails where the sender domain or embedded URLs use Punycode (xn--) or homoglyph-based lookalikes of trusted brand domains (e.g., Microsoft, Google, DocuSign). The rule further prioritizes alerts where the email subject contains urgency-based social engineering language typically used in credential harvesting campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects potential Business Email Compromise (BEC) by monitoring inbound email threads for unexpected changes in the sender domain during ongoing conversations. This rule flags replies that contain payment-related keywords (e.g., IBAN, SWIFT, bank details) where the sender domain has not been observed in the previous 30 days of the thread's history.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects potential Business Email Compromise (BEC) fraud involving AI voice-cloning. The rule correlates external or unrecognized Microsoft Teams activity (calls/chats) directed at finance users with high-value financial transactions or vendor bank detail updates occurring on the same day, specifically when these transactions lack evidence of legitimate out-of-band or second-approver verification.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the use of the 'finger.exe' utility in a suspicious manner, indicative of payload staging in a 'ClickFix' phishing attack scenario. The rule monitors for instances where 'finger.exe' is executed with suspicious command-line arguments (containing '@' or '-l') by common parent processes associated with malicious copy-paste activities (cmd.exe, powershell.exe, or explorer.exe).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the use of PowerShell or Windows Script Host to access files within common web browser cache directories combined with indicators of Base64 decoding and pixel data manipulation. This behavior is indicative of extracting malicious payloads hidden via steganography within browser-cached image files, a technique often used in phishing campaigns to evade detection.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects instances where a user grants consent to an unverified OAuth application requesting high-privilege scopes (e.g., Mail.Read, Files.ReadWrite.All). This behavior is characteristic of consent phishing attacks aimed at obtaining persistent access to sensitive data and mailbox contents.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects HTTP proxy requests for script files (.hta, .js, .ps1) where the HTTP referer indicates the request originated from a search engine or known ad/syndication network. This behavior is highly indicative of 'ClickFix' phishing campaigns, where users are lured from malicious search results or advertisements to download and execute scripts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the creation of files on disk by a browser process where the Zone.Identifier metadata indicates the origin was a blob:, data:, or about:blank URI. This behavior is indicative of HTML smuggling, where malicious payloads are reconstructed client-side from within an HTML document, bypassing network-based security controls.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a multi-stage Telephone-Oriented Attack Delivery (TOAD) campaign. The first stage identifies phishing emails containing billing or security-themed subjects and phone numbers without links or attachments to evade automated analysis. The second stage monitors for the subsequent installation or execution of common remote-support tools (e.g., AnyDesk, TeamViewer, ScreenConnect). A final correlative rule detects these events occurring sequentially on the same host, indicating a high-confidence indicator of a successful callback phishing social-engineering attempt.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects an anomalous volume of artificial intelligence model inference API calls (e.g., AWS Bedrock, Azure OpenAI, Google Vertex AI) initiated by a single IAM principal or API key within a short time window. This activity is indicative of 'LLMjacking', where compromised cloud credentials are leveraged by threat actors to perform unauthorized, high-cost AI model inference tasks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects instances where an AI agent's persistent memory store is updated with suspicious content (e.g., prompt injection, role overrides, or embedded credentials) by a user other than the authorized agent owner, followed by subsequent tool invocations in an independent session. This behavior aligns with prompt injection attacks aimed at manipulating agent logic and unauthorized resource access via the AI agent.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001