Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Surfaces entities generating an unusually high volume of low-fidelity alerts that can mask a true-positive escalation event — the alert-fatigue and untuned-tooling gap CISA identified as a root cause of Organization A's failed detection.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
1 month ago
307
Detects accounts authenticating from compromised webmail/CMS infrastructure that pivot, within a tight time window and matching source IP, to authenticate against internal virtualization-management systems — the lateral-movement pattern Jewelbug used to reach a national webmail estate's backing infrastructure.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103