Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects potential vishing or account takeover precursor activity where an external or guest Microsoft Teams user, impersonating IT or Help Desk support, communicates with a user who subsequently modifies their credentials or MFA configuration within the same 24-hour period.
Detects MFA or credential reset activities on high-value or privileged accounts that lack a corresponding out-of-band verification signal, such as manager approval or identity proofing, within a one-hour window. This behavior is indicative of social engineering attempts where attackers manipulate help-desk procedures to bypass identity protections.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
Detects a sequence of suspicious activities on a Windows host aimed at inhibiting system recovery, such as deleting shadow copies, modifying boot recovery configurations, deleting backup catalogs, or stopping security and backup-related services. This rule aggregates distinct categories of these actions by DeviceId and Account to identify potential malicious intent characteristic of ransomware or data destructive attacks.
Single-source Sigma proxy for the authentication-persistence stage of the multi-stage device-code-phishing-to-Graph-collection chain (see the companion KQL correlation rule "Passkey Persistence: Device-Code Phishing to MFA Takeover and Graph Collection" for the full, threshold-gated, cross-table detection). Sigma has no join, temporal-windowing, or aggregation support, so this rule fires on the authentication-persistence event alone and does NOT enforce the device-code sign-in precursor or the subsequent Graph-activity burst - both required by the full correlation. Scoped to the two highest-signal operations only (new security-info registration, and any admin-initiated registration on another user's account) to cut noise from routine self-service profile edits.
Single-source Sigma proxy for the authentication-persistence stage of the multi-stage device-code-phishing-to-Graph-collection chain (see the companion KQL correlation rule "Passkey Persistence: Device-Code Phishing to MFA Takeover and Graph Collection" for the full, threshold-gated, cross-table detection). Sigma has no join, temporal-windowing, or aggregation support, so this rule fires on the authentication-persistence event alone and does NOT enforce the device-code sign-in precursor or the subsequent Graph-activity burst - both required by the full correlation. Scoped to the two highest-signal operations only (new security-info registration, and any admin-initiated registration on another user's account) to cut noise from routine self-service profile edits.
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
Detects the multi-stage Microsoft cloud identity compromise chain reported by Microsoft Security Research (September 2026): a victim completes a successful Entra ID device-code sign-in (often induced by passkey-themed device-code phishing), the same identity's authentication/security info is registered or changed (MFA/passkey persistence) within 60 minutes (deduplicated to the earliest such event per sign-in), followed within 120 minutes by a burst of at least 25 successful, delegated-context Microsoft Graph API calls (Scopes claim populated, i.e. user-delegated permissions rather than pure application/client-credential access) spanning at least 3 distinct resource paths, exhibiting reconnaissance (>=5 requests against /users, /groups, /directoryRoles, /roleManagement, /applications, /servicePrincipals, /organization) and/or collection (>=10 requests against /messages, /mailFolders, /attachments, /drive, /drives, /sites, /lists, /search) patterns. Restricting to delegated (Scopes-bearing) Graph calls and requiring resource-path breadth removes the two largest false-positive sources: service-principal/application-only automation jobs (Roles-only tokens) and single-endpoint polling tools. Pure behavioral correlation across SigninLogs, AuditLogs, and MicrosoftGraphActivityLogs - no static IOCs. Flags whether Graph activity originated from an IP different from the original device-code sign-in IP as a strong pivot/session-reuse indicator.
This rule identifies potential phishing attempts by correlating email delivery events with known suspicious sender addresses and URLs containing typosquatting domains impersonating legitimate organizations.
Detects an exploitation chain originating from a Chrome browser process, characterized by the execution of an anomalous child process followed by the creation of an executable file named 'chrome_cleanup.exe' within a short time window. This sequence is indicative of multi-stage exploitation, involving remote code execution via browser vulnerability and subsequent privilege escalation.
Detects the use of PowerShell's Start-Sleep cmdlet with a duration of 3 minutes or longer within process command lines. This technique is commonly used by malware, such as ClickFix-style droppers, to bypass sandbox time-based analysis by delaying execution until the sandbox timeout period has elapsed.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
This rule detects suspicious PowerShell execution initiated by a Node.js process (node.exe). It monitors for command lines containing common bypass flags (-NoProfile, -NonInteractive, -ExecutionPolicy Bypass) and a specific string pattern 'wra-ps-', which is often associated with malicious scripts or remote access trojans (RATs) being executed via a Node.js application.
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
Detects various persistence mechanisms used by the CARBONATO botnet on Linux systems, including registration of cron jobs, systemd services/timers, and the usage of 'chattr +i' to make persistence files immutable.
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).



