Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects a multi-stage attack chain where a device shows signs of credential theft (accessing browser credential stores or cookies) followed closely by a successful cloud authentication from that same user using a device identifier not previously observed in the last 30 days.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule monitors for suspicious administrative modifications to identity federation settings within Entra ID (Azure AD) and potential unauthorized alterations to on-premises Active Directory objects related to the 'AZUREADSSOACC' account. These activities are indicative of persistence mechanisms or credential manipulation in hybrid identity environments, potentially used to subvert authentication processes.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects a potential post-compromise lateral movement sequence where a host, previously identified as accessing sensitive browser credential files by an unauthorized process, subsequently initiates RDP or WinRM connections to other internal hosts using an account not previously observed performing interactive logons on that source host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances where a process that is not a recognized web browser (chrome, msedge, firefox, brave, opera, or explorer) accesses multiple unique browser cookie files. This is a common pattern for credential harvesting malware attempting to steal browser sessions.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects instances where a suspicious PowerShell, mshta, or pwsh command, typically involving download or obfuscation patterns, is launched as a child process of Windows Explorer within two minutes of a modification to the Explorer RunMRU registry key. This behavior is indicative of an adversary attempting to achieve execution, often following user interaction or persistence triggers.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized access or modification attempts to common web browser credential storage files (such as 'Login Data' or 'key4.db') by processes other than standard, trusted web browsers (e.g., Chrome, Edge, Firefox). This behavior is indicative of credential harvesting, where an adversary attempts to steal saved login information from browser data stores.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects potential account compromise by identifying 'impossible travel' scenarios where successful logins for the same user occur from different geolocations within a short timeframe (less than 1 hour), specifically when at least one authentication event uses a refresh or session token rather than interactive MFA. It correlates these suspicious logins with previous endpoint infostealer detections on the same device within the last 72 hours, indicating that the token may have been stolen by malware.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects the installation or execution of common Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop, TeamViewer) on Windows endpoints within a 4-hour window of associated cloud identity risk activity (such as risky sign-ins, MFA changes, or privilege grants). It filters out legitimate activity initiated via standard software management pipelines (e.g., SCCM, Intune) to identify potential unauthorized use of remote access software by adversaries following account compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects the creation of a 'manifest.json' file within directory paths containing 'extensions' by a process other than standard web browsers. This behavior is indicative of unauthorized manual installation or modification of browser extensions, which may be used for persistence or to facilitate credential/session theft.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule correlates endpoint-based alerts related to credential theft or infostealer malware with subsequent successful cloud identity authentication events. It identifies situations where a user, who has recently triggered a credential theft alert on an endpoint, logs into a cloud environment from a country or IP address that has not been historically associated with that user within a 24-hour window.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools (e.g., ScreenConnect, AnyDesk, Atera, Splashtop, NinjaOne, Action1) when the command line includes silent install or installation flags. The detection correlates this activity with recent (within 72 hours) identity-related alerts (e.g., impossible travel, anomalous sign-in, credential compromise) for the same user, suggesting a potential high-risk scenario where an adversary is establishing remote access following a credential compromise.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects unauthorized access to sensitive Chromium-based browser files such as 'Login Data' (password database) or 'Local State' (encryption keys) by processes other than standard web browsers (Chrome, Edge, Brave, Firefox). The rule also elevates risk if the access is followed by the execution of known data-handling tools like sqlite, python, or powershell, which are frequently used by information stealers to parse and exfiltrate browser-stored credentials.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential infostealer activity where an unsigned or non-system process accesses the Windows DPAPI master key store followed by access to common browser credential and cookie storage files within a 10-minute window. This behavior is indicative of malware attempting to decrypt and exfiltrate saved browser passwords and cookies.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Detects potential lateral movement by identifying users who have recently had a confirmed infostealer malware infection on a source host and subsequently initiate RDP or WinRM connections from a different host to internal network resources.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
8 days ago
000
Page 65 of 1866