Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects anomalous service principal activity characterized by multiple, rapidly issued, and overlapping OAuth tokens within a short time window. This pattern is associated with automated/agentic token orchestration (e.g., JADEPUFFER/Storm-3168 campaign) rather than standard manual operator activity, specifically when leveraging the python-requests user agent.
Detects anomalous service principal activity characterized by multiple, rapidly issued, and overlapping OAuth tokens within a short time window. This pattern is associated with automated/agentic token orchestration (e.g., JADEPUFFER/Storm-3168 campaign) rather than standard manual operator activity, specifically when leveraging the python-requests user agent.
Detects anomalous service principal activity characterized by multiple, rapidly issued, and overlapping OAuth tokens within a short time window. This pattern is associated with automated/agentic token orchestration (e.g., JADEPUFFER/Storm-3168 campaign) rather than standard manual operator activity, specifically when leveraging the python-requests user agent.
Detects instances where a user grants OAuth application permissions for high-risk scopes (e.g., mail access, offline access). The rule flags these grants, with higher risk scores assigned if the application publisher is unverified or unknown, helping identify potential illicit consent grant attacks often used to maintain long-term persistence in cloud environments.
Detects high-risk IAM policy modifications, specifically the attachment or creation of policies that grant wildcard permissions or full administrator access. The rule optionally correlates these permission changes with the recent creation of access keys or service account credentials for the same principal, indicating potential preparation for persistence or unauthorized access escalation.
This rule detects potential device code phishing attacks by identifying successful sign-ins using the OAuth device code flow from non-standard applications, followed shortly by a user granting consent to that application. This pattern is commonly used in consent phishing to gain unauthorized access to user accounts or data.
Detects the assignment of special, highly privileged rights (e.g., SeDebugPrivilege, SeImpersonatePrivilege) to standard user accounts using Windows Security Event ID 4672. This activity, without an associated new logon event, is a common indicator of access token manipulation or impersonation techniques (such as those used by tools like Incognito) to gain elevated system privileges.
Detects the abuse of the Windows Background Intelligent Transfer Service (BITS) via the bitsadmin command-line tool or PowerShell's Start-BitsTransfer to download files (such as .exe, .dll, or .ps1) or facilitate potential persistence. Adversaries use these methods to transfer malicious payloads stealthily in the background or to maintain persistence on a compromised host.
Detects the loading of known-vulnerable signed drivers typically associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. These drivers are frequently abused to gain kernel-mode privileges, allowing attackers to disable or terminate EDR, antivirus, and other security processes.
Detects suspicious PowerShell command lines that load a .dat file, decode its Base64 content, and execute it in-memory. This behavior is indicative of the 'TASK#STOMP' loader pattern, where malicious code is hidden in external files and invoked directly into memory to bypass traditional file-based security controls.
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
Detects anomalous DNS traffic patterns indicative of DNS tunneling, which is often used for command-and-control (C2) communication or data exfiltration. The rule identifies suspicious indicators such as abnormally long subdomain labels (potentially containing encoded payloads), misuse of TXT or NULL record types for data transport, and high-frequency queries to a single apex domain, while excluding common CDN providers to reduce false positives.
Detects rapid mass-cloning or downloading of private GitHub repositories shortly after an OAuth token authorization, originating from IP addresses or countries not previously associated with the user account. This behavior is indicative of unauthorized bulk data extraction using compromised credentials, consistent with threat actor activity (e.g., TeamPCP/UNC6780).
Detects instances where a removed GitHub organization member performed bulk repository access (cloning or downloading) shortly before their removal, potentially indicating exploitation of retained access by a departed employee or an adversary using a valid account before deprovisioning. The rule identifies activity occurring more than 24 hours prior to removal involving multiple repositories or multiple access actions.
Detects the execution of PowerShell with suspicious command-line arguments often used by adversaries for obfuscation, evasion, or in-memory code execution, such as encoded commands, hidden windows, and downloading external content.
This rule detects potential Kerberoasting activity by monitoring for an unusually high volume of Kerberos Service Ticket (TGS) requests (event ID 4769) for non-machine service accounts, specifically focusing on tickets encrypted with RC4 (etype 23). A high count of ticket requests or distinct Service Principal Names (SPNs) requested by a single client in a short period is characteristic of an adversary attempting to harvest hashes for offline cracking.
This rule detects the use of native Windows utilities certutil.exe and bitsadmin.exe for potentially malicious purposes. Specifically, it flags certutil.exe being used for decoding or cached URL operations, and bitsadmin.exe being used to initiate file transfers from remote URLs or network paths. These tools are commonly abused by attackers for file staging, ingress tool transfer, and deobfuscation of malicious payloads.
This rule detects the creation of named pipes with names patterns commonly associated with post-exploitation frameworks, such as Cobalt Strike and Sliver. These frameworks frequently use specific, sometimes randomized, pipe patterns for inter-process communication, lateral movement, or command and control (C2) operations. Monitoring these pipe names can help identify malicious activity occurring within a compromised environment.
Detects outbound HTTP requests to the Telegram Bot API associated with the malicious 'indexed-btree' npm package. The rule specifically monitors for hardcoded Telegram bot tokens and chat IDs used for data exfiltration.
Detects outbound network connections to a known malicious IP address (45.94.31.112) associated with C2 beaconing. The rule identifies communication directed to specific API endpoints (/api/v3/r, /api/v3/s) originating from processes other than common web browsers, suggesting the use of dedicated beaconing or malware agents (e.g., direct WinHTTP usage).
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).



