Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule monitors for suspicious administrative modifications to identity federation settings within Entra ID (Azure AD) and potential unauthorized alterations to on-premises Active Directory objects related to the 'AZUREADSSOACC' account. These activities are indicative of persistence mechanisms or credential manipulation in hybrid identity environments, potentially used to subvert authentication processes.
Detects two distinct suspicious patterns: first, the deletion of executable files residing in common user-writable temporary directories (e.g., Temp, Downloads, AppData) using command-line tools like 'del' or 'erase', which is often indicative of anti-forensic activity after malware execution. Second, it monitors for network traffic involving HTTP POST requests or specific SOAP headers related to 'tempuri.org', which are commonly associated with default .NET WCF service scaffolding and may be used by adversaries for C2 communication or exfiltration.
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
Detects a potential post-compromise lateral movement sequence where a host, previously identified as accessing sensitive browser credential files by an unauthorized process, subsequently initiates RDP or WinRM connections to other internal hosts using an account not previously observed performing interactive logons on that source host.
Detects instances where a process that is not a recognized web browser (chrome, msedge, firefox, brave, opera, or explorer) accesses multiple unique browser cookie files. This is a common pattern for credential harvesting malware attempting to steal browser sessions.
Detects instances where a suspicious PowerShell, mshta, or pwsh command, typically involving download or obfuscation patterns, is launched as a child process of Windows Explorer within two minutes of a modification to the Explorer RunMRU registry key. This behavior is indicative of an adversary attempting to achieve execution, often following user interaction or persistence triggers.
Detects unauthorized access or modification attempts to common web browser credential storage files (such as 'Login Data' or 'key4.db') by processes other than standard, trusted web browsers (e.g., Chrome, Edge, Firefox). This behavior is indicative of credential harvesting, where an adversary attempts to steal saved login information from browser data stores.
This rule detects non-browser processes that simultaneously access a web browser's 'Local State' file and the Windows DPAPI master key storage directory. This behavior is a common precursor to credential dumping, as adversaries must decrypt browser-protected secrets (passwords and cookies) using DPAPI keys stored in the user's profile.
This rule detects potential account compromise by identifying 'impossible travel' scenarios where successful logins for the same user occur from different geolocations within a short timeframe (less than 1 hour), specifically when at least one authentication event uses a refresh or session token rather than interactive MFA. It correlates these suspicious logins with previous endpoint infostealer detections on the same device within the last 72 hours, indicating that the token may have been stolen by malware.
This rule detects the installation or execution of common Remote Monitoring and Management (RMM) tools (e.g., AnyDesk, ScreenConnect, Atera, Splashtop, TeamViewer) on Windows endpoints within a 4-hour window of associated cloud identity risk activity (such as risky sign-ins, MFA changes, or privilege grants). It filters out legitimate activity initiated via standard software management pipelines (e.g., SCCM, Intune) to identify potential unauthorized use of remote access software by adversaries following account compromise.
Detects the creation of a 'manifest.json' file within directory paths containing 'extensions' by a process other than standard web browsers. This behavior is indicative of unauthorized manual installation or modification of browser extensions, which may be used for persistence or to facilitate credential/session theft.
This rule correlates endpoint-based alerts related to credential theft or infostealer malware with subsequent successful cloud identity authentication events. It identifies situations where a user, who has recently triggered a credential theft alert on an endpoint, logs into a cloud environment from a country or IP address that has not been historically associated with that user within a 24-hour window.
This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools (e.g., ScreenConnect, AnyDesk, Atera, Splashtop, NinjaOne, Action1) when the command line includes silent install or installation flags. The detection correlates this activity with recent (within 72 hours) identity-related alerts (e.g., impossible travel, anomalous sign-in, credential compromise) for the same user, suggesting a potential high-risk scenario where an adversary is establishing remote access following a credential compromise.
Detects unauthorized access to sensitive Chromium-based browser files such as 'Login Data' (password database) or 'Local State' (encryption keys) by processes other than standard web browsers (Chrome, Edge, Brave, Firefox). The rule also elevates risk if the access is followed by the execution of known data-handling tools like sqlite, python, or powershell, which are frequently used by information stealers to parse and exfiltrate browser-stored credentials.
Detects potential infostealer activity where an unsigned or non-system process accesses the Windows DPAPI master key store followed by access to common browser credential and cookie storage files within a 10-minute window. This behavior is indicative of malware attempting to decrypt and exfiltrate saved browser passwords and cookies.
Detects potential lateral movement by identifying users who have recently had a confirmed infostealer malware infection on a source host and subsequently initiate RDP or WinRM connections from a different host to internal network resources.
Detects unauthorized access by a non-browser process to Chromium-based 'Cookies' SQLite database files, which are used by browsers like Chrome, Edge, and Brave. This behavior is a strong indicator of credential theft or session hijacking, as attackers target these files to extract session cookies and bypass MFA for cloud services.
Detects unauthorized access attempts to Chromium-based browser credential storage files, specifically 'Login Data' (SQLite database) and 'Local State' (master key storage), by processes other than standard browsers or known security products. This activity is a common indicator of credential harvesting by information stealers such as LummaC2, Vidar, and RedLine.
Detects interactive (Logon Type 10) or network (Logon Type 3) authentication to Windows hosts originating from external, non-RFC1918 IP addresses using 'Negotiate' authentication. This pattern is indicative of potential lateral movement from a cloud-connected environment into on-premises infrastructure, specifically where an adversary might be leveraging stolen session artifacts or credentials to bypass standard Kerberos-based domain authentication.
This rule detects typical behavior associated with infostealers targeting browser data, specifically the creation of compressed archives (.zip, .rar) in temporary directories (Temp or AppData) and the subsequent exfiltration of data via known webhook services (e.g., Discord, Telegram, Pastebin) or direct IP connections. It filters out common signed backup and synchronization software to minimize noise.
Detects the ClickFix/fake-CAPTCHA initial access pattern where users are socially engineered into copying and pasting malicious commands into the Windows Run dialog or a browser-spawned shell. The rule matches on process creation events involving mshta.exe, powershell.exe, or wscript.exe initiated by explorer.exe or common shell-related processes, filtering out known administrative and deployment software.
Page 71 of 1870
