Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
Detects PE executables whose embedded filename strings claim to be Adobe, TrueConf, or 1C software but whose PE metadata (company/product name) or digital signature does not match the claimed vendor, as used by NightEagle/GhostContainer operators to blend malicious tooling into normal process activity
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
Detects instances where a development-oriented web server (such as Vite or Node.js) is configured to bind to all network interfaces ('0.0.0.0') and is simultaneously receiving inbound connections from non-private, external IP addresses on a common development port (5173). This rule filters out common CI/CD environments to focus on potentially insecure exposure of development tools to the public internet.
Detects an exploitation attempt against the Vite Development Server (CVE-2026-39364) where an attacker uses specific query parameters to bypass file access restrictions and disclose sensitive files. The rule triggers on GET requests containing suspicious import-related query parameters and checks the resulting response to ensure a successful 200/206 status code and non-HTML content type.
Bigbear V2 Ioc Hunt
Sigma
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
BigBear 2.0 IOC HUNT (Cortex XDR)
Cortex XDR
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
BigBear 2.0 IOC HUNT (Gravwell)
Gravwell
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
BigBear 2.0 IOC HUNT (Gravwell)
Gravwell
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
Detects Mimikatz binary or in-memory module used for credential harvesting following PaperCut RCE exploitation
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
Detects the execution of the Rubeus.exe utility with command-line arguments indicative of Kerberos-related credential harvesting and abuse, such as Kerberoasting, AS-REP Roasting, and Pass-the-Ticket attacks.
Detects the execution of the Rubeus.exe utility with command-line arguments indicative of Kerberos-related credential harvesting and abuse, such as Kerberoasting, AS-REP Roasting, and Pass-the-Ticket attacks.
Page 327 of 1871
