Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- detections
Loading detections…
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
Loading detections…
Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice
Identifies anomalous device logon events from Microsoft Defender for Endpoint (MDE) where a user connects to a device for the first time or a device connects from a new IP address. The query filters high-priority anomalies and provides key details such as timestamp, action type, source IP, location, and associated user, device, and activity insights for investigation.
Outside the enterprise matrix