Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects Azure AD user sign-ins from multiple distinct IP addresses or countries within a 1-hour window. This is a common heuristic used to identify potentially compromised credentials or impossible travel scenarios, where a single user account authenticates from geographically distant or disparate network locations in an unrealistic timeframe.
Detects potential OAuth device code phishing attempts by identifying sign-ins via the device code flow using applications not previously used by the specific user, especially when occurring in a burst pattern across multiple users.
Detects a suspicious execution chain where a browser process makes a network connection, followed shortly by a direct execution of command-line tools (powershell.exe, mshta.exe, or cmd.exe) from the Windows explorer.exe process (e.g., via the Run dialog). This behavior is characteristic of 'ClickFix' social engineering attacks where users are tricked into copying and pasting malicious commands from a web page directly into their local environment.
This rule detects potential social engineering attacks where an external or federated user impersonates an IT or helpdesk entity within Microsoft Teams (via chats, messages, or calls) followed shortly by an MFA registration or password reset event for the targeted user. This sequence is indicative of a vishing or phishing attack aimed at account takeover.
Detects instances where a user account modifies security information, registers a new MFA method, or resets a password shortly after a successful sign-in from a country not observed for that user within the previous 30 days. This pattern is indicative of potential account takeover where an adversary adds persistence or MFA bypass methods to a newly compromised account.
Detects MFA fatigue or push-bombing attacks where a user account experiences an abnormally high volume of MFA request denials in a short duration (10 minutes), followed by a successful authentication event. The rule specifically looks for evidence where the successful authentication potentially originates from a different IP address than the failed attempts.
Detects phishing emails containing suspicious URLs pointing to PaaS platforms (Azure Static Web Apps, Cloudflare, Firebase) that exhibit credential harvesting characteristics (branded keywords or base64 patterns). The rule correlates these emails with subsequent clicks and a successful M365 sign-in by the same user within 30 minutes of the click, indicating a probable successful credential compromise.
Detects inbound .ics calendar invite attachments that contain URLs, originating from sender domains not previously seen within the organization over the last 90 days, and distributed to 10 or more recipients. This pattern is indicative of a mass-distributed phishing campaign using calendar invites as a lure.
This rule detects mass phishing campaigns by identifying HTML/HTM email attachments that contain embedded URLs. It monitors for a pattern where the same sender distributes these attachments to multiple recipients, a common behavior for HTML smuggling delivery vectors where malicious payloads are constructed client-side to bypass static email gateway inspection.
Detects newly consented OAuth applications that immediately perform mass access or exfiltration of mail and file data across multiple mailboxes or drives within a short period, potentially indicating an attacker utilizing a malicious OAuth application.
Detects inbound emails where the sender domain or embedded URLs use Punycode (xn--) or homoglyph-based lookalikes of trusted brand domains (e.g., Microsoft, Google, DocuSign). The rule further prioritizes alerts where the email subject contains urgency-based social engineering language typically used in credential harvesting campaigns.
Detects potential Business Email Compromise (BEC) by monitoring inbound email threads for unexpected changes in the sender domain during ongoing conversations. This rule flags replies that contain payment-related keywords (e.g., IBAN, SWIFT, bank details) where the sender domain has not been observed in the previous 30 days of the thread's history.
Detects potential Business Email Compromise (BEC) fraud involving AI voice-cloning. The rule correlates external or unrecognized Microsoft Teams activity (calls/chats) directed at finance users with high-value financial transactions or vendor bank detail updates occurring on the same day, specifically when these transactions lack evidence of legitimate out-of-band or second-approver verification.
Detects the use of the 'finger.exe' utility in a suspicious manner, indicative of payload staging in a 'ClickFix' phishing attack scenario. The rule monitors for instances where 'finger.exe' is executed with suspicious command-line arguments (containing '@' or '-l') by common parent processes associated with malicious copy-paste activities (cmd.exe, powershell.exe, or explorer.exe).
Detects the use of PowerShell or Windows Script Host to access files within common web browser cache directories combined with indicators of Base64 decoding and pixel data manipulation. This behavior is indicative of extracting malicious payloads hidden via steganography within browser-cached image files, a technique often used in phishing campaigns to evade detection.
Detects instances where a user grants consent to an unverified OAuth application requesting high-privilege scopes (e.g., Mail.Read, Files.ReadWrite.All). This behavior is characteristic of consent phishing attacks aimed at obtaining persistent access to sensitive data and mailbox contents.
Detects HTTP proxy requests for script files (.hta, .js, .ps1) where the HTTP referer indicates the request originated from a search engine or known ad/syndication network. This behavior is highly indicative of 'ClickFix' phishing campaigns, where users are lured from malicious search results or advertisements to download and execute scripts.
Detects the creation of files on disk by a browser process where the Zone.Identifier metadata indicates the origin was a blob:, data:, or about:blank URI. This behavior is indicative of HTML smuggling, where malicious payloads are reconstructed client-side from within an HTML document, bypassing network-based security controls.
Detects a multi-stage Telephone-Oriented Attack Delivery (TOAD) campaign. The first stage identifies phishing emails containing billing or security-themed subjects and phone numbers without links or attachments to evade automated analysis. The second stage monitors for the subsequent installation or execution of common remote-support tools (e.g., AnyDesk, TeamViewer, ScreenConnect). A final correlative rule detects these events occurring sequentially on the same host, indicating a high-confidence indicator of a successful callback phishing social-engineering attempt.
Detects an anomalous volume of artificial intelligence model inference API calls (e.g., AWS Bedrock, Azure OpenAI, Google Vertex AI) initiated by a single IAM principal or API key within a short time window. This activity is indicative of 'LLMjacking', where compromised cloud credentials are leveraged by threat actors to perform unauthorized, high-cost AI model inference tasks.
Detects instances where an AI agent's persistent memory store is updated with suspicious content (e.g., prompt injection, role overrides, or embedded credentials) by a user other than the authorized agent owner, followed by subsequent tool invocations in an independent session. This behavior aligns with prompt injection attacks aimed at manipulating agent logic and unauthorized resource access via the AI agent.
