Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a suspected account takeover pattern where an Azure AD account logs into the Azure Portal shortly after experiencing failed authentication attempts from the same IP address. The detection correlates password spraying or VPN probing activity (multiple failed logins against different users from a single IP) with subsequent successful or near-successful logins (MFA enrollment interrupts) on the Azure Portal, signaling potential post-compromise activity.
Detects a suspected account takeover pattern where an Azure AD account logs into the Azure Portal shortly after experiencing failed authentication attempts from the same IP address. The detection correlates password spraying or VPN probing activity (multiple failed logins against different users from a single IP) with subsequent successful or near-successful logins (MFA enrollment interrupts) on the Azure Portal, signaling potential post-compromise activity.
Detects a suspected account takeover pattern where an Azure AD account logs into the Azure Portal shortly after experiencing failed authentication attempts from the same IP address. The detection correlates password spraying or VPN probing activity (multiple failed logins against different users from a single IP) with subsequent successful or near-successful logins (MFA enrollment interrupts) on the Azure Portal, signaling potential post-compromise activity.
Detects the TeamFiltration/UNK_CondorFiltration spray signature: a large
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.
Detects the TeamFiltration/UNK_CondorFiltration spray signature: a large
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.
number of distinct target UserPrincipalNames within a single tenant, each
receiving only a handful of sign-in attempts, spread across many distinct
AWS EC2-hosted source IPs/regions within a short time window. Individual
sign-ins from AWS-hosted IP ranges (VPN gateways, corporate cloud proxies,
remote contractors) are not flagged on their own; the rule requires both
the account-fanout and the IP-rotation dimensions to co-occur for the same
tenant in the same window.
Detects a distributed password spraying campaign targeting cloud accounts, characterized by a large number of distinct accounts being targeted simultaneously from multiple AWS-hosted IP addresses, with a low volume of attempts per account per hour to evade standard threshold-based detection.
Detects a distributed password spraying campaign targeting cloud accounts, characterized by a large number of distinct accounts being targeted simultaneously from multiple AWS-hosted IP addresses, with a low volume of attempts per account per hour to evade standard threshold-based detection.
Detects a distributed password spraying campaign targeting cloud accounts, characterized by a large number of distinct accounts being targeted simultaneously from multiple AWS-hosted IP addresses, with a low volume of attempts per account per hour to evade standard threshold-based detection.
Detects a distributed password spraying campaign targeting cloud accounts, characterized by a large number of distinct accounts being targeted simultaneously from multiple AWS-hosted IP addresses, with a low volume of attempts per account per hour to evade standard threshold-based detection.
Detects a distributed password spraying campaign targeting cloud accounts, characterized by a large number of distinct accounts being targeted simultaneously from multiple AWS-hosted IP addresses, with a low volume of attempts per account per hour to evade standard threshold-based detection.
This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
This rule monitors for the execution of an executable file (.exe) from a user's 'Downloads' directory followed shortly (within 5 minutes) by a network connection to port 4321, which is characteristic of the Bear C2 HTTPS-AES beacon pattern. This behavior is indicative of a potential secondary stage malware execution or C2 check-in after an initial user-driven download.
This rule detects the execution of a file with an .exe extension from the user's Downloads directory that has been previously tagged with the Mark-of-the-Web (MOTW) Zone.Identifier. It correlates file creation events, the application of the MOTW alternate data stream, and subsequent process execution to identify potentially malicious downloaded executables.
Detects network communication associated with the Bear C2 framework by identifying specific beacon URI patterns (/beacon?id=<uuid>) and connections to known non-standard listener ports (4321, 8080). The rule also monitors for process command lines containing specific hardcoded identifiers associated with this C2 implant.
This rule monitors for the execution of an executable file (.exe) from a user's 'Downloads' directory followed shortly (within 5 minutes) by a network connection to port 4321, which is characteristic of the Bear C2 HTTPS-AES beacon pattern. This behavior is indicative of a potential secondary stage malware execution or C2 check-in after an initial user-driven download.
This rule detects the execution of a file with an .exe extension from the user's Downloads directory that has been previously tagged with the Mark-of-the-Web (MOTW) Zone.Identifier. It correlates file creation events, the application of the MOTW alternate data stream, and subsequent process execution to identify potentially malicious downloaded executables.
Detects network communication associated with the Bear C2 framework by identifying specific beacon URI patterns (/beacon?id=<uuid>) and connections to known non-standard listener ports (4321, 8080). The rule also monitors for process command lines containing specific hardcoded identifiers associated with this C2 implant.
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
Detects non-interactive sign-in activity using a Primary Refresh Token (PRT) occurring shortly after a risky or AiTM-flagged interactive sign-in for the same user, originating from a device that has not been previously associated with that user account.
No description available.
Detects instances where an administrative user performs a password or MFA method reset on a target account, followed within 24 hours by a sign-in event from that same target account flagged with a high or medium risk level. This sequence is characteristic of Adversary-in-the-Middle (AiTM) attacks, where an attacker utilizes stolen session tokens and subsequently coerces helpdesk or administrative intervention to reset MFA requirements to maintain unauthorized access.


