Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,137 detections

Detects anomalous service principal activity characterized by multiple, rapidly issued, and overlapping OAuth tokens within a short time window. This pattern is associated with automated/agentic token orchestration (e.g., JADEPUFFER/Storm-3168 campaign) rather than standard manual operator activity, specifically when leveraging the python-requests user agent.
avatar
Arnold Chan@slaz
Defender - KQL
9 days ago
000
Detects anomalous service principal activity characterized by multiple, rapidly issued, and overlapping OAuth tokens within a short time window. This pattern is associated with automated/agentic token orchestration (e.g., JADEPUFFER/Storm-3168 campaign) rather than standard manual operator activity, specifically when leveraging the python-requests user agent.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
9 days ago
000
Detects anomalous service principal activity characterized by multiple, rapidly issued, and overlapping OAuth tokens within a short time window. This pattern is associated with automated/agentic token orchestration (e.g., JADEPUFFER/Storm-3168 campaign) rather than standard manual operator activity, specifically when leveraging the python-requests user agent.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
9 days ago
000
Detects instances where a user grants OAuth application permissions for high-risk scopes (e.g., mail access, offline access). The rule flags these grants, with higher risk scores assigned if the application publisher is unverified or unknown, helping identify potential illicit consent grant attacks often used to maintain long-term persistence in cloud environments.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects high-risk IAM policy modifications, specifically the attachment or creation of policies that grant wildcard permissions or full administrator access. The rule optionally correlates these permission changes with the recent creation of access keys or service account credentials for the same principal, indicating potential preparation for persistence or unauthorized access escalation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
301
This rule detects potential device code phishing attacks by identifying successful sign-ins using the OAuth device code flow from non-standard applications, followed shortly by a user granting consent to that application. This pattern is commonly used in consent phishing to gain unauthorized access to user accounts or data.
avatar
Kush rana@Kushblueteamer
avatar
Detections.ai Community
19 days ago
2010
Detects the assignment of special, highly privileged rights (e.g., SeDebugPrivilege, SeImpersonatePrivilege) to standard user accounts using Windows Security Event ID 4672. This activity, without an associated new logon event, is a common indicator of access token manipulation or impersonation techniques (such as those used by tools like Incognito) to gain elevated system privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the abuse of the Windows Background Intelligent Transfer Service (BITS) via the bitsadmin command-line tool or PowerShell's Start-BitsTransfer to download files (such as .exe, .dll, or .ps1) or facilitate potential persistence. Adversaries use these methods to transfer malicious payloads stealthily in the background or to maintain persistence on a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects the loading of known-vulnerable signed drivers typically associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. These drivers are frequently abused to gain kernel-mode privileges, allowing attackers to disable or terminate EDR, antivirus, and other security processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
avatar
Ankit Mehta@Secvyn
avatar
Hunters
13 days ago
102
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
avatar
Ankit Mehta@Secvyn
avatar
SlimKQL
13 days ago
102
Detects anomalous DNS traffic patterns indicative of DNS tunneling, which is often used for command-and-control (C2) communication or data exfiltration. The rule identifies suspicious indicators such as abnormally long subdomain labels (potentially containing encoded payloads), misuse of TXT or NULL record types for data transport, and high-frequency queries to a single apex domain, while excluding common CDN providers to reduce false positives.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
Detects rapid mass-cloning or downloading of private GitHub repositories shortly after an OAuth token authorization, originating from IP addresses or countries not previously associated with the user account. This behavior is indicative of unauthorized bulk data extraction using compromised credentials, consistent with threat actor activity (e.g., TeamPCP/UNC6780).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
17 days ago
005
Detects instances where a removed GitHub organization member performed bulk repository access (cloning or downloading) shortly before their removal, potentially indicating exploitation of retained access by a departed employee or an adversary using a valid account before deprovisioning. The rule identifies activity occurring more than 24 hours prior to removal involving multiple repositories or multiple access actions.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
17 days ago
005
Detects the execution of PowerShell with suspicious command-line arguments often used by adversaries for obfuscation, evasion, or in-memory code execution, such as encoded commands, hidden windows, and downloading external content.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos Service Ticket (TGS) requests (event ID 4769) for non-machine service accounts, specifically focusing on tickets encrypted with RC4 (etype 23). A high count of ticket requests or distinct Service Principal Names (SPNs) requested by a single client in a short period is characteristic of an adversary attempting to harvest hashes for offline cracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
001
This rule detects the use of native Windows utilities certutil.exe and bitsadmin.exe for potentially malicious purposes. Specifically, it flags certutil.exe being used for decoding or cached URL operations, and bitsadmin.exe being used to initiate file transfers from remote URLs or network paths. These tools are commonly abused by attackers for file staging, ingress tool transfer, and deobfuscation of malicious payloads.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
This rule detects the creation of named pipes with names patterns commonly associated with post-exploitation frameworks, such as Cobalt Strike and Sliver. These frameworks frequently use specific, sometimes randomized, pipe patterns for inter-process communication, lateral movement, or command and control (C2) operations. Monitoring these pipe names can help identify malicious activity occurring within a compromised environment.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
12 days ago
101
Detects outbound HTTP requests to the Telegram Bot API associated with the malicious 'indexed-btree' npm package. The rule specifically monitors for hardcoded Telegram bot tokens and chat IDs used for data exfiltration.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
15 days ago
003
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
avatar
Ankit Mehta@Secvyn
avatar
Hunters
12 days ago
001
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
avatar
Ankit Mehta@Secvyn
avatar
Detection & Hunting Community
12 days ago
001