Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects unauthorized processes attempting to read or create sensitive browser credential files ('Login Data', 'Web Data', 'Cookies', 'logins.json', 'key4.db'). This activity is commonly associated with information-stealing malware (such as Lumma, StealC, Vidar, RedLine, and Amadey) that targets browser databases to extract stored secrets, often bypassing standard browser process access.
This rule detects a multi-stage attack chain where a device shows signs of credential theft (accessing browser credential stores or cookies) followed closely by a successful cloud authentication from that same user using a device identifier not previously observed in the last 30 days.
This rule correlates events across the end-to-end kill chain of an enterprise intrusion, specifically tracking the progression from initial endpoint-based infostealer activity (credential access), through anomalous or non-interactive sign-in activity, into privilege escalation or mailbox delegation within the cloud environment, and finally to mass data exfiltration or mail access. It detects accounts involved in at least three distinct stages of this progression within a 72-hour window.
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
Detects instances where a user account associated with a detected infostealer malware infection (e.g., Redline, Raccoon, Vidar) successfully authenticates to a cloud service from a suspicious network location, such as a VPN, residential proxy, or Tor exit node, within 24 hours of the infection alert.
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
This rule detects potential account compromise by identifying 'impossible travel' scenarios where successful logins for the same user occur from different geolocations within a short timeframe (less than 1 hour), specifically when at least one authentication event uses a refresh or session token rather than interactive MFA. It correlates these suspicious logins with previous endpoint infostealer detections on the same device within the last 72 hours, indicating that the token may have been stolen by malware.
This rule detects the installation or execution of common Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop, TeamViewer) on Windows endpoints within a 4-hour window of associated cloud identity risk activity (such as risky sign-ins, MFA changes, or privilege grants). It filters out legitimate activity initiated via standard software management pipelines (e.g., SCCM, Intune) to identify potential unauthorized use of remote access software by adversaries following account compromise.
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
Detects the use of common archiving utilities (7zip, WinRAR, Tar, or PowerShell Compress-Archive) to bundle sensitive Google Chrome user data, such as cookies, login data, or the entire user data profile directory. This behavior is indicative of an adversary attempting to stage sensitive information for exfiltration.
Detects impossible-travel activity where a single user account authenticates successfully from multiple distinct countries or IP addresses within a short 15-minute window. This behavior is highly indicative of potential session hijacking or the concurrent use of a stolen session token by both an attacker and a legitimate user.
This rule detects the execution of common command-line cloud synchronization and file transfer utilities (such as rclone, rsync, and MEGAcmd) when invoked with flags or patterns indicative of data staging or exfiltration, such as copy, sync, or targeting remote cloud storage locations.
Detects periodic, beacon-like network activity targeting public platforms such as Steam community profiles or Telegram (api.telegram.org / t.me) originating from suspicious processes (script interpreters, unsigned binaries). This behavior is characteristic of LummaC2 and similar malware families using public web services as dead-drop resolvers for C2 fallback communication.
Detects instances of potential lateral movement using PsExec or WMI following an alert related to credential compromise, infostealers, or session hijacking, where the same user account is involved in both events.
Detects a single process reading browser cookie SQLite database files across multiple distinct browser profile directories or different web browsers within a short time window. This behavior is indicative of infostealer activity attempting to harvest session cookies for session hijacking and MFA bypass.
Detects a suspected infostealer activity chain involving the unauthorized access of credential and session cookie files, followed by the archival of these files into a temporary or staging directory, and concluding with an outbound network connection to an uncommon destination from the archiving process.
This rule detects potential session hijacking by correlating endpoint-based detections of known infostealer malware (e.g., Vidar, Lumma, Redline) with a subsequent cloud Identity Provider (IdP) login for the same user. The correlation specifically focuses on instances where the IdP authentication originates from an IP address different from the infected host, suggesting the use of stolen session cookies by an external actor to access corporate resources.
Detects the loading of specific commonly side-loaded DLLs (libcef.dll, version.dll, msimg32.dll) from user-writable directories such as Downloads, Temp, or AppData. Attackers often use these locations to drop malicious DLLs alongside legitimate applications to achieve DLL side-loading for persistence or defense evasion.
Detects unauthorized non-browser processes attempting to access Chrome browser master keys or bypass App-Bound Encryption by interacting with the Chrome IElevator service, DPAPI routines, or the 'Local State' configuration file. This behavior is indicative of infostealer activity aiming to decrypt browser-stored session cookies and credentials.
Detects unauthorized processes attempting to read sensitive session files or databases associated with messaging applications like Telegram, Signal, and Discord. Accessing these files (such as 'tdata', 'db.sqlite', or 'leveldb') allows for full account takeover by extracting session tokens, enabling attackers to bypass authentication and 2FA.
Detects non-CLI and non-DevOps utility processes accessing sensitive cloud credential and configuration files, including AWS SSO caches, AWS credentials, kubeconfig, and gcloud configuration files. This behavior is indicative of credential theft or discovery by infostealers attempting to gain unauthorized access to cloud environments.
Page 37 of 1870
