Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects high-frequency connection attempts from a single source IP to multiple destination IPs over the non-standard DVRIP port 37777, often used by Dahua surveillance equipment. This behavior is indicative of automated scanning, brute-forcing, or exploitation attempts targeting vulnerable IoT/CCTV devices.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
13 days ago
002
Detects rapid mass-cloning or downloading of private GitHub repositories shortly after an OAuth token authorization, originating from IP addresses or countries not previously associated with the user account. This behavior is indicative of unauthorized bulk data extraction using compromised credentials, consistent with threat actor activity (e.g., TeamPCP/UNC6780).
avatar
Arnold Chan@slaz
Defender - KQL
17 days ago
006
This rule detects potential cloud service enumeration activity originating from a specific, potentially malicious IP address (23.234.84.102). It flags instances where this source IP performs specific API calls ('GetCallerIdentity' and 'ListTopics') without expected user-agent strings typical of legitimate AWS service traffic.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
006
Detects rapid, bulk cloning or downloading of GitHub repositories containing sensitive data (e.g., consensus algorithms, PII, internal blocklists). This behavior is characteristic of unauthorized data exfiltration, specifically tracking activity involving suspicious OAuth token prefixes (gho_) and rapid high-volume access to sensitive organizational assets within a short timeframe.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
006
Detects network traffic (DNS, TLS SNI, and HTTP Host headers) attempting to communicate with infrastructure associated with the EvilTokens Phishing-as-a-Service (PhaaS) platform. This activity is indicative of credential harvesting or adversary-in-the-middle (AiTM) attacks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
Defender - KQL
13 days ago
002
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
102
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
13 days ago
002
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects potentially malicious OAuth device code sign-ins by identifying sign-in events that exhibit anomalous characteristics, such as atypical geographic locations, rare client-application combinations, unmanaged/noncompliant device status, or elevated risk signals associated with the account. This detection helps identify account compromise or malicious OAuth consent activity often associated with 'EvilTokens' or device-code phishing attacks.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
102
Detects potentially malicious OAuth device code sign-ins by identifying sign-in events that exhibit anomalous characteristics, such as atypical geographic locations, rare client-application combinations, unmanaged/noncompliant device status, or elevated risk signals associated with the account. This detection helps identify account compromise or malicious OAuth consent activity often associated with 'EvilTokens' or device-code phishing attacks.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects potential device code phishing patterns where a successful OAuth device-code authentication is rapidly followed by Microsoft Graph resource access from the same account. The rule identifies suspicious polling sessions (e.g., EvilTokens) by monitoring for successful device-code sign-ins and immediate, subsequent Graph API activity. It filters known first-party applications and incorporates risk-based triggers and reconnaissance behavioral patterns to minimize false positives.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects the creation of an email inbox rule that includes both a concealment/deletion action and an external forwarding destination, occurring within 4 hours of a high-risk or compromised device-code authentication event. This pattern is indicative of account takeover where an attacker establishes persistence and exfiltration while hiding their activity.
avatar
Arnold Chan@slaz
avatar
Hunters
13 days ago
202
Detects anomalous network polling patterns consistent with 'EvilTokens' or similar adversary-in-the-middle (AiTM) OAuth phishing kits. The rule identifies web browsers performing high-frequency, low-interval polling (3-6s) against non-reputable/unseen domains (the attacker-controlled status endpoint) immediately preceding or following successful Microsoft OAuth device-code authentication sequences.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects automated post-compromise mailbox reconnaissance following an anomalous OAuth device code sign-in that exhibits high-risk indicators. The rule identifies programmatic access to a high volume of mail items within a short window following suspicious token issuance, which is characteristic of automated scanning or data exfiltration tooling.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
13 days ago
002
Detects potential post-authentication persistent actions (e.g., OAuth app grants, MFA changes, mailbox rule updates) performed shortly after a successful Google Workspace login, specifically flagging actions originating from IP addresses different from the login session to identify session hijacking or token replay (AiTM) activity. Includes suppression for known corporate IP ranges, trusted OAuth application consents, and recurring user behavior.
avatar
Arnold Chan@slaz
avatar
Hunters
17 days ago
006
Detects a suspicious sequence of events where a user modifies the Entra Authentication Methods Policy to register an external authentication method (EAM) provider, followed immediately by the same user associating a new FIDO key with their account. This behavior can be indicative of an adversary setting up a persistence mechanism via a malicious or unauthorized MFA provider.
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
13 days ago
202
Detects sign-in events where Multi-Factor Authentication (MFA) was satisfied using an External Authentication Method (EAM) that asserts specific possession or inherence claims (e.g., 'hwk' - hardware key). This behavior may indicate an adversary attempting to bypass or forge MFA responses via a rogue EAM provider.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
102
This rule detects persistence by identifying accounts that continue to authenticate using an External Authentication Method (EAM) both before and after a password reset event. This behavior suggests that an adversary has established a persistent authentication mechanism (such as an EAM) that survives a standard password reset, indicating potential account compromise and bypass of primary authentication controls.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
602
Detects the creation of an application registered with a specific Microsoft external authentication provider URI, immediately followed by the configuration of its service principal with reply URLs pointing to external tunneling services like ngrok. This sequence is indicative of an attacker attempting to register a rogue MFA provider to intercept authentication requests.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
13 days ago
102
Detects VBScript droppers that utilize excessive 'WScript.Sleep' delays to bypass sandbox analysis, often combined with error suppression and downloader APIs to execute malicious payloads.
avatar
Subhankar H@Andrewsec57
avatar
Detections.ai Community
13 days ago
002