Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
2
Contributors
2
Categories
1
1
1
1
1
Platforms
1
1
1
Products / Services
10,366
9,516
6,509
4,363
3,687
MITRE Techniques
1
Surfaces entities generating an unusually high volume of low-fidelity alerts that can mask a true-positive escalation event — the alert-fatigue and untuned-tooling gap CISA identified as a root cause of Organization A's failed detection.
Detects accounts authenticating from compromised webmail/CMS infrastructure that pivot, within a tight time window and matching source IP, to authenticate against internal virtualization-management systems — the lateral-movement pattern Jewelbug used to reach a national webmail estate's backing infrastructure.
