Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- detections
Loading detections…
Loading detections
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
Loading detections…
Detects PowerShell scripts that references native Windows API functions commonly used for discovery of users, groups, shares, sessions, domain trusts, and service security. Attackers use these APIs for situational awareness and targeting prior to lateral movement or collection.
Published to signed-in readers
The query as its source wrote it, its canonical form, and the content hash that pins this exact revision.