Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

This rule detects potential account compromise by identifying scenarios where a user's security information (MFA methods) is modified, deleted, or updated, followed shortly after (within 24 hours) by a successful sign-in using a less secure authentication method (SMS, Voice, OATH, or Mobile App notification) instead of a stronger method like FIDO2 or Passkey.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects instances where a user grants OAuth consent to a non-verified application requesting high-privilege scopes related to mail access (Mail.Read, Mail.Send) and persistence (offline_access, full_access_as_app), which is a common indicator of consent phishing attacks.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects successful Azure AD sign-in attempts that utilize legacy or basic authentication protocols (e.g., POP, IMAP, SMTP, Exchange ActiveSync) where Conditional Access MFA enforcement was not applied. This behavior indicates a potential attempt to circumvent modern authentication security controls, often associated with AiTM-facilitated account takeover or legacy protocol abuse.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects outbound proxy traffic indicating potential Adversary-in-the-Middle (AiTM) phishing activity. The rule identifies requests directed at domains mimicking major Identity Providers (Microsoft, Okta, Duo, Google) that either utilize punycode homograph encoding or arrive via known URL shortener/redirector services, while filtering out known legitimate brand domains.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects MFA request abuse (T1621) by identifying a user receiving 5 or more MFA push, SMS, or call denials/timeouts within a 10-minute window across Entra ID, Okta, or Duo authentication logs. This behavior is indicative of an MFA fatigue attack, where an adversary continuously triggers MFA prompts until the user eventually approves the request out of frustration or confusion.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects web-proxy or webserver log activity associated with domains registered within the last 30 days that mimic branding or structure of major identity providers (Microsoft, Okta, Google, Duo). This behavior is characteristic of adversary-in-the-middle (AiTM) phishing infrastructure staging.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the reuse of session identifiers (SessionId, DeviceId, or RefreshTokenJti) across different device fingerprints (e.g., changes in User-Agent, OS, or Browser) within a short timeframe. This behavior is indicative of session hijacking or adversary-in-the-middle (AiTM) attacks, where stolen session tokens or cookies are replayed by an attacker from a different endpoint than the original user.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects instances where a user account successfully registers or joins a device to Entra ID (Azure AD) immediately after performing a sign-in operation that was flagged with a medium or high-risk level. This pattern may indicate an adversary is attempting to enroll a malicious device to bypass conditional access policies or establish persistence in the environment using compromised credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects adversary-in-the-middle (AiTM) phishing activity utilizing reverse-proxy kits (such as Evilginx2, EvilProxy, or Modlishka) to bypass MFA. The rule identifies suspicious login requests by correlating common identity provider login paths with missing security headers (CSP/HSTS) and anomalous server or hostname characteristics typical of proxied phishing infrastructure.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects high-risk sign-in events in Azure AD that exhibit indicators of token replay, impossible travel, or anomalous sessions, while simultaneously leveraging certificate-based authentication or valid Primary Refresh Tokens (PRT). This combination often indicates an adversary is using stolen session material or PRTs to establish persistent, MFA-exempt access to the environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects successful sign-in events using the OAuth 2.0 device authorization grant (device code flow). This technique is frequently abused in AiTM/consent-phishing campaigns where an adversary tricks a user into authorizing a device, effectively obtaining a fully authenticated session token. The rule identifies successful device-code authentications, which should be correlated with source IP discrepancies or unusual volume per tenant to identify malicious activity.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects successful Azure AD sign-in events where the session is marked as compliant or trusted by Conditional Access policies, but simultaneously flagged by Identity Protection as originating from an anonymized IP (e.g., residential proxy, VPN). This indicates an adversary has bypassed location-based Conditional Access controls, likely in the context of an Adversary-in-the-Middle (AiTM) phishing attack.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects potential Adversary-in-the-Middle (AiTM) phishing activity by identifying requests to common tunneling services (e.g., ngrok, Cloudflare Tunnel) that include suspicious authentication or login-related URI paths, correlated with referrers from well-known email providers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the reuse of a single authenticated session or refresh token from multiple distinct IP addresses or ASN origins within a short timeframe following a successful MFA event. This pattern is indicative of session hijacking, where an adversary uses an Adversary-in-the-Middle (AiTM) toolkit (e.g., Evilginx) to capture a valid session cookie from a victim and replay it from their own infrastructure to bypass authentication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects Browser-in-the-Browser (BitB) phishing pages by inspecting web proxy or EDR-captured page content for malicious HTML/JS structures. The rule identifies fabricated browser chrome, such as fake address bars and title bars, initialized via window.open with specific dimensions, while ensuring the serving domain is not a known, legitimate identity provider.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects the registration or modification of multi-factor authentication (MFA) security information in Entra ID or Okta that occurs within 15 minutes of a sign-in event flagged as risky. This behavioral pattern is a common indicator of persistence being established by an attacker after performing an adversary-in-the-middle (AiTM) attack, where they leverage a stolen session to register their own MFA factors to maintain long-term access.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects successful multi-factor authentication (MFA) events associated with risk signals categorized as 'unfamiliarFeatures' in Azure AD sign-in logs. This combination is often indicative of an adversary-in-the-middle (AiTM) attack, where the attacker has captured authentication tokens or is forcing an MFA prompt and receiving immediate approval from a new or suspicious device and network location.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects sign-in activity where an attacker or user fails a phishing-resistant MFA challenge (such as FIDO2, Windows Hello, or Passwordless Phone) and immediately succeeds using a lower-assurance, phishable factor (SMS, Voice call, or Push notification). This pattern is indicative of an Adversary-in-the-Middle (AiTM) attack attempting to bypass stronger authentication methods.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
Detects a suspicious authentication pattern involving 3 or more MFA failures within 15 minutes, immediately followed by an MFA success for the same user. This pattern is characteristic of potential Adversary-in-the-Middle (AiTM) activity, where an attacker intercepts a session or MFA token and relays it through separate infrastructure, while the legitimate user's own MFA attempts fail or time out.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
001
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000