Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the deletion of .zip files within the Public directory by VBScript or JScript interpreters (wscript.exe or cscript.exe). This pattern is often indicative of a malicious dropper or downloader that extracts a payload from a staged archive and subsequently removes the evidence to hinder analysis and forensics.
Detects the execution of a .vbs script file that contains '.pdf' in its filename, followed within 5 minutes by the execution of a WMI query via wscript.exe. This behavior is indicative of a malicious VBScript dropper attempting to perform system discovery using WMI.
Detects Azure AD sign-in events where Multi-Factor Authentication (MFA) was reportedly satisfied by an External Authentication Method (EAM) claim without evidence of a traditional secondary authentication challenge. This behavior is indicative of a 'TrustSink' technique where a rogue or compromised OIDC provider injects a spoofed assertion of MFA success into the authentication token.
Detects the execution of Windows Script Host (wscript.exe/cscript.exe) loading WMI-related modules (wbemprox.dll, wbemcomn.dll, etc.). This pattern is often indicative of scripts attempting to query WMI for system information, environment configuration, or locale data, which is a common reconnaissance technique used by malware to identify the victim environment.
Detects the execution of a .vbs script file that contains '.pdf' in its filename, followed within 5 minutes by the execution of a WMI query via wscript.exe. This behavior is indicative of a malicious VBScript dropper attempting to perform system discovery using WMI.
Detects instances where wscript.exe deletes a .zip archive from within the C:\Users\Public\ directory structure. This activity is frequently associated with VBScript droppers performing anti-forensic cleanup by removing staged payloads after extraction but prior to execution.
Detects when a user account assigned to high-privileged roles (Global Administrator or Authentication Policy Administrator) performs sensitive operations such as application registration, service principal creation, or modifications to authentication policies within a short timeframe (4 hours) of a successful sign-in. This activity is often associated with the initial setup phases of MFA bypass or persistence techniques in Entra ID.
This rule detects the execution of script files (such as .vbs, .vbe, .js, .jse) via wscript.exe when the file name uses a double-extension technique (e.g., .pdf.vbs) to masquerade as a benign PDF document. These files are typically found in temporary or user-download directories, indicating potential malicious activity initiated by downloaded attachments.
Detects the execution of wscript.exe or cscript.exe with a command line containing a .vbs file, occurring within a 5-minute window of the creation of a file named 'notepad++.exe' or 'readme.txt' within a sub-directory of 'C:\Users\Public\'. This behavior is indicative of a potential multi-stage execution where a script is used to drop or interact with files in public-accessible folders.
Detects potential malicious VBScript behavior where the script queries system language settings via WMI and subsequently launches a decoy message box commonly associated with initial-stage malware loaders or droppers to deceive users before initiating a payload download.
This rule identifies sign-in events using an External Authentication Method (EAM) that occur within the 2-day cache window immediately following a certificate or key credential update for an application or service principal in Entra ID. This detection highlights a timeframe where an attacker potentially possessing a compromised old signing key could use it to forge tokens before the Entra cache refreshes.
Detects outbound network traffic (TLS SNI and HTTP requests) directed to the Telegram Bot API endpoint. This behavior is often associated with malware using Telegram as a command-and-control (C2) channel or for the exfiltration of stolen data, credentials, or sensitive information.
This rule detects potential phishing emails themed around financial documents or shared files that contain URLs associated with device-code authorization phishing lures, such as ARToken PhaaS, or links hosted on workers.dev platforms commonly used for such activities.
Detects potential theft and reuse of session or refresh tokens for Microsoft 365 services (Exchange/SharePoint) by identifying multiple authentication events for the same user account from different geographic locations and IP addresses within a short timeframe, specifically when no new MFA challenge was performed.
Detects HTTP requests containing potential session, handoff, or access tokens within the URI pattern commonly associated with ORAX Adversary-in-the-Middle (AiTM) phishing infrastructure. The rule specifically targets requests routed to wildcard subdomains that mimic legitimate deployment or service endpoints, indicating an attempt to harvest authentication tokens from victims.
Detects potential abuse of the Microsoft Graph API by correlating device-code authentication events with subsequent high-volume activity, such as mail or file enumeration, from the same account within a short window. This pattern is indicative of ARToken-style token proxying, where an attacker intercepts an OAuth device-code token to gain unauthorized access to an user's resources.
Detects the creation of suspicious O365 inbox rules designed to hide (via mark-as-read, move, or delete actions) or forward/redirect email messages containing keywords associated with financial transactions such as payment, wire, or invoice. This behavior is indicative of post-compromise activity, specifically targeted at invoice fraud or email thread hijacking.
Detects phishing emails that use common voicemail notification subject lines combined with Mailchimp click-tracking or redirect infrastructure. This combination is often used to bypass traditional email gateway filters by utilizing legitimate marketing service domains to obfuscate final malicious destinations.
Detects phishing emails that impersonate invoice-related correspondence, containing SharePoint links and a .url shortcut file attachment, a common technique for credential harvesting or malware delivery.
Detects network indicators associated with the ORAX Phishing-as-a-Service (PhaaS) platform. This includes patterns for emoji-matching CAPTCHAs, spoofed Cloudflare security pages, specific wildcard subdomain DNS queries, and the use of anti-analysis gate sequences to prevent sandbox inspection.
Detects network activity associated with a phishing campaign leveraging Cloudflare Workers, identified as 'ARToken'. The rules monitor for specific TLS SNI patterns, HTTP Host headers, and subsequent C2-like behavior involving device code authentication flows (api/device/start and api/device/poll) hosted on 'workers.dev'.
