Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

This rule detects the creation or modification of Exchange mailbox rules (Forward, Redirect, Delete, or Mark as Read) involving sensitive keywords (invoice, wire, payment, finance, remittance) shortly after an anomalous sign-in event or a password reset on the same account. This combination is a strong indicator of account takeover and mailbox persistence.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
201
Detects a service principal attempting to delete multiple Azure SQL databases in a short timeframe, resulting in failures. This pattern is characteristic of malicious data destruction activity, such as that observed in Storm-3168 (JADEPUFFER) campaigns, but accounts for the possibility of misconfigured infrastructure-as-code pipelines by requiring a high volume of failed requests across distinct resources.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a service principal attempting to delete multiple Azure SQL databases in a short timeframe, resulting in failures. This pattern is characteristic of malicious data destruction activity, such as that observed in Storm-3168 (JADEPUFFER) campaigns, but accounts for the possibility of misconfigured infrastructure-as-code pipelines by requiring a high volume of failed requests across distinct resources.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a service principal attempting to delete multiple Azure SQL databases in a short timeframe, resulting in failures. This pattern is characteristic of malicious data destruction activity, such as that observed in Storm-3168 (JADEPUFFER) campaigns, but accounts for the possibility of misconfigured infrastructure-as-code pipelines by requiring a high volume of failed requests across distinct resources.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects the creation of Windows scheduled tasks that include suspicious interpreters (PowerShell, cmd.exe, rundll32) or execution paths located in common attacker-writable directories (Temp, AppData, ProgramData), which is a common technique for persistence and command-and-control re-establishment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects a service principal or user account performing a burst of 'ListKeys' operations across multiple Azure Storage accounts. This behavior is indicative of an attacker attempting to dump access keys for multiple storage accounts after initial compromise or privilege escalation to gain further access to sensitive cloud data.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects a service principal or user account performing a burst of 'ListKeys' operations across multiple Azure Storage accounts. This behavior is indicative of an attacker attempting to dump access keys for multiple storage accounts after initial compromise or privilege escalation to gain further access to sensitive cloud data.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects a single user account performing an unusually high volume of Kerberos Service Ticket (TGS) requests (Event ID 4769) within a short window, specifically using RC4 encryption (0x17). This behavior is highly characteristic of Kerberoasting, where attackers request tickets for various service principal names (SPNs) to perform offline password cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects techniques associated with LSASS process credential dumping, including direct handle access to the LSASS process with specific access masks (common in tools like Mimikatz), the use of rundll32.exe to invoke comsvcs.dll for memory dumping, and the creation of LSASS dump files on disk.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects attempts to delete Azure resource locks protecting Site Recovery or Backup services, followed by credential retrieval (ListKeys) within a one-hour window. This sequence pattern is a strong indicator of an adversary attempting to disable backup protection before potentially destroying data or exfiltrating keys.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects attempts to delete Azure resource locks protecting Site Recovery or Backup services, followed by credential retrieval (ListKeys) within a one-hour window. This sequence pattern is a strong indicator of an adversary attempting to disable backup protection before potentially destroying data or exfiltrating keys.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects attempts to delete Azure resource locks protecting Site Recovery or Backup services, followed by credential retrieval (ListKeys) within a one-hour window. This sequence pattern is a strong indicator of an adversary attempting to disable backup protection before potentially destroying data or exfiltrating keys.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects attempts to delete Azure resource locks protecting Site Recovery or Backup services, followed by credential retrieval (ListKeys) within a one-hour window. This sequence pattern is a strong indicator of an adversary attempting to disable backup protection before potentially destroying data or exfiltrating keys.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects execution of PowerShell processes employing common obfuscation and evasion techniques frequently associated with fileless malware loaders and malicious script execution. This includes the use of EncodedCommand, Base64 strings, IEX/Invoke-Expression download cradles, and stealth execution flags (e.g., hidden windows combined with non-interactive modes).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects reconnaissance activity targeting Azure App Service instances, specifically looking for attempts to access web-shell-like files, WordPress administration paths, PHP-CGI endpoints, or LangFlow code validation paths. It identifies potential Storm-3168 actor infrastructure through known IOCs or through patterns of high-volume, path-diverse HTTP requests that deviate from typical noise, helping to distinguish targeted probing from common internet background scanning.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects persistence attempts by monitoring modifications to Windows registry run keys (Run, RunOnce, Winlogon Shell/Userinit) or file creation within the Startup folder. It alerts when these locations are updated to reference suspicious file paths (Temp/AppData) or execute scripts (vbs, ps1, js, wsf, bat, hta).
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects a precursor pattern identified as JADEPUFFER, where a failed 'ListKeys' operation (indicating an attempt to discover or access keys for a non-existent storage account) is immediately followed by a burst of destructive delete operations on critical cloud resources (e.g., storage, databases, key vaults) by the same actor.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
9 days ago
000
Detects a precursor pattern identified as JADEPUFFER, where a failed 'ListKeys' operation (indicating an attempt to discover or access keys for a non-existent storage account) is immediately followed by a burst of destructive delete operations on critical cloud resources (e.g., storage, databases, key vaults) by the same actor.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects a precursor pattern identified as JADEPUFFER, where a failed 'ListKeys' operation (indicating an attempt to discover or access keys for a non-existent storage account) is immediately followed by a burst of destructive delete operations on critical cloud resources (e.g., storage, databases, key vaults) by the same actor.
avatar
Arnold Chan@slaz
avatar
Hunters
9 days ago
000
Detects multiple Kerberos AS-REQ (Event ID 4768) requests initiated for distinct user accounts from a single source IP within a short timeframe (10 minutes) where Kerberos pre-authentication was not used (Pre-Authentication Type 0). This pattern is a key indicator of AS-REP roasting activity, often performed by tools like Rubeus or Impacket's GetNPUsers.py to harvest user TGTs for offline cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects unauthorized directory service access requests (Event ID 4662) utilizing the 'DS-Replication-Get-Changes' or 'DS-Replication-Get-Changes-All' extended rights GUIDs. These rights are required for the DCSync technique used by tools like Mimikatz or Impacket to replicate Active Directory data. The rule specifically flags when such requests originate from a non-domain controller host, which is a strong indicator of credential theft or unauthorized replication attempts.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001