sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

7,365
detections

Showing 30 of 7,365

HighElastic detection rules
Windows Service Installed via an Unusual Client

Identifies the creation of a Windows service by an unusual client process. Services may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges from administrator to SYSTEM.

T1543T1543.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
55c2bf58-2a39-4c58-a384-c8b1978153c2
HighElastic detection rules
Process Created with an Elevated Token

Identifies the creation of a process running as SYSTEM while impersonating the token context of a Windows core binary. Adversaries may create a new process with a different token to escalate privileges and bypass access controls.

T1134T1134.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
02a23ee7-c8f8-4701-b99d-e9038ce313cb
HighElastic detection rules
Privilege Escalation via Rogue Named Pipe Impersonation

Identifies a privilege escalation attempt via rogue named pipe impersonation. An adversary may abuse this technique by masquerading as a known named pipe and manipulating a privileged process to connect to it.

T1134T1134.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
76ddb638-abf7-42d5-be22-4a70b0bf7241
HighElastic detection rules
Privileges Elevation via Parent Process PID Spoofing

Identifies parent process spoofing used to create an elevated child process. Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.

T1134T1134.002T1134.004
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
26b01043-4f04-4d2f-882a-5a1d2e95751b
MediumElastic detection rules
Unusual Service Host Child Process - Childless Service

Identifies unusual child processes of Service Host (svchost.exe) that traditionally do not spawn any child processes. This may indicate a code injection or an equivalent form of exploitation.

T1055T1055.012
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
6a8ab9cc-4023-4d17-b5df-1a3e16882ce7
MediumElastic detection rules
Unusual Print Spooler Child Process

Detects unusual Print Spooler service (spoolsv.exe) child processes. This may indicate an attempt to exploit privilege escalation vulnerabilities related to the Printing Service on Windows.

T1068
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
ee5300a7-7e31-4a72-a258-250abb8b3aa1
MediumElastic detection rules
Unusual Parent-Child Relationship

Identifies Windows programs run from unexpected parent processes. This could indicate masquerading or other strange activity on a system.

T1036T1036.009T1055T1055.012T1134+1 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
35df0dd8-092d-4a83-88c1-5151a804f31b
LowElastic detection rules
Potential Exploitation of an Unquoted Service Path Vulnerability

Adversaries may leverage unquoted service path vulnerabilities to escalate privileges. By placing an executable in a higher-level directory within the path of an unquoted service executable, Windows will natively launch this executable from its defined path variable instead of the benign one in a deeper directory, thus leading to code execution.

T1574T1574.009
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
12de29d4-bbb0-4eef-b687-857e8a163870
MediumElastic detection rules
UAC Bypass via Windows Firewall Snap-In Hijack

Identifies attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in. Attackers bypass UAC to stealthily execute code with elevated permissions.

T1218T1218.014T1548T1548.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
1178ae09-5aff-460a-9f2f-455cd0ac4d8e
HighElastic detection rules
UAC Bypass Attempt via Windows Directory Masquerading

Identifies an attempt to bypass User Account Control (UAC) by masquerading as a Microsoft trusted Windows directory. Attackers may bypass UAC to stealthily execute code with elevated permissions.

T1036T1036.005T1548T1548.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
290aca65-e94d-403b-ba0f-62f320e63f51
HighElastic detection rules
Bypass UAC via Event Viewer

Identifies User Account Control (UAC) bypass via eventvwr.exe. Attackers bypass UAC to stealthily execute code with elevated permissions.

T1548T1548.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
31b4c719-f2b4-41f6-a9bd-fce93c2eaf62
HighElastic detection rules
UAC Bypass Attempt via Privileged IFileOperation COM Interface

Identifies attempts to bypass User Account Control (UAC) via DLL side-loading. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.

T1548T1548.002T1574T1574.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
5a14d01d-7ac8-4545-914c-b687c2cf66b3
MediumElastic detection rules
UAC Bypass via DiskCleanup Scheduled Task Hijack

Identifies User Account Control (UAC) bypass via hijacking DiskCleanup Scheduled Task. Attackers bypass UAC to stealthily execute code with elevated permissions.

T1053T1053.005T1548T1548.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
1dcc51f6-ba26-49e7-9ef4-2655abb2361e
HighElastic detection rules
UAC Bypass via ICMLuaUtil Elevated COM Interface

Identifies User Account Control (UAC) bypass attempts via the ICMLuaUtil Elevated COM interface. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.

T1548T1548.002T1559T1559.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
68d56fdc-7ffa-4419-8e95-81641bd6f845
MediumElastic detection rules
UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer

Identifies User Account Control (UAC) bypass attempts by abusing an elevated COM Interface to launch a malicious program. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.

T1218T1548T1548.002T1559T1559.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
fc7c0fa4-8f03-4b3e-8336-c5feab0be022
HighElastic detection rules
UAC Bypass Attempt with IEditionUpgradeManager Elevated COM Interface

Identifies attempts to bypass User Account Control (UAC) by abusing an elevated COM Interface to launch a rogue Windows ClipUp program. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.

T1548T1548.002T1559T1559.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
b90cdde7-7e0d-4359-8bf0-2c112ce2008a
MediumElastic detection rules
SeDebugPrivilege Enabled by a Suspicious Process

Identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege. Adversaries may enable this privilege to debug and modify other processes, typically reserved for system-level tasks, to escalate privileges and bypass access controls.

T1134
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
97020e61-e591-4191-8a3b-2861a2b887cd
HighElastic detection rules
Suspicious SeIncreaseBasePriorityPrivilege Use

Identifies attempts to use the SeIncreaseBasePriorityPrivilege privilege by an unusual process. This could be related to hijack execution flow of a process via threats priority manipulation.

T1134
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
6fa0f15b-1926-419b-8de2-fce1429797ba
MediumElastic detection rules
Potential Account Takeover - Logon from New Source IP

Identifies a user account that normally logs in with high volume from one source IP suddenly logging in from a different source IP. This pattern (one IP with many successful logons, another IP with very few) may indicate account takeover or use of stolen credentials from a new location.

T1078
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
a1b2c3d4-e5f6-4a5b-8c9d-0e1f2a3b4c5d
HighElastic detection rules
Remote Computer Account DnsHostName Update

Identifies the remote update to a computer account's DnsHostName attribute. If the new value set is a valid domain controller DNS hostname and the subject computer name is not a domain controller, then it's highly likely a preparation step to exploit CVE-2022-26923 in an attempt to elevate privileges from a standard domain user to domain admin privileges.

T1068T1078T1078.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
6bed021a-0afb-461c-acbe-ffdb9574d3f3
LowElastic detection rules
Service Control Spawned via Script Interpreter

Identifies Service Control (sc.exe) spawning from script interpreter processes to create, modify, or start services. This can potentially indicate an attempt to elevate privileges or maintain persistence.

T1047T1059T1059.001T1059.003T1059.005+8 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
e8571d5f-bea1-46c2-9f56-998de2d3ed95
HighElastic detection rules
Potential Privileged Escalation via SamAccountName Spoofing

Identifies a suspicious computer account name rename event, which may indicate an attempt to exploit CVE-2021-42278 to elevate privileges from a standard domain user to a user with domain admin privileges. CVE-2021-42278 is a security vulnerability that allows potential attackers to impersonate a domain controller via samAccountName attribute spoofing.

T1036T1068T1078T1078.002T1098
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
bdcf646b-08d4-492c-870a-6c04e3700034
HighElastic detection rules
Privilege Escalation via Windir Environment Variable

Identifies a privilege escalation attempt via a rogue Windows directory (Windir) environment variable. This is a known primitive that is often combined with other vulnerabilities to elevate privileges.

T1112T1574T1574.007
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
d563aaba-2e72-462b-8658-3e5ea22db3a6
MediumElastic detection rules
Potential Privilege Escalation via Service ImagePath Modification

Identifies registry modifications to default services that could enable privilege escalation to SYSTEM. Attackers with privileges from groups like Server Operators may change the ImagePath of services to executables under their control or to execute commands.

T1112T1543T1543.003T1569T1569.002+2 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
b66b7e2b-d50a-49b9-a6fc-3a383baedc6b
LowElastic detection rules
Suspicious Print Spooler SPL File Created

Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service including CVE-2020-1048 and CVE-2020-1337.

T1068
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
a7ccae7b-9d2c-44b2-a061-98e5946971fa
MediumElastic detection rules
Suspicious Print Spooler File Deletion

Detects deletion of print driver files by an unusual process. This may indicate a clean up attempt post successful privilege escalation via Print Spooler service related vulnerabilities.

T1068T1070T1070.004
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
c4818812-d44f-47be-aaef-4cfb2f9cc799
HighElastic detection rules
Suspicious Print Spooler Point and Print DLL

Detects attempts to exploit a privilege escalation vulnerability (CVE-2020-1030) related to the print spooler service. Exploitation involves chaining multiple primitives to load an arbitrary DLL into the print spooler process running as SYSTEM.

T1068T1112T1574
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
bd7eefee-f671-494e-98df-f01daf9e5f17
MediumElastic detection rules
PowerShell Script with Token Impersonation Capabilities

Detects PowerShell scripts that references token manipulation and impersonation APIs such as CreateProcessWithTokenW, DuplicateToken/ImpersonateLoggedOnUser, or AdjustTokenPrivileges (SeDebugPrivilege). Attackers abuse token impersonation to elevate privileges and bypass access controls.

T1059T1059.001T1106T1134T1134.001+1 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
11dd9713-0ec6-4110-9707-32daae1ee68c
MediumElastic detection rules
Potential Port Monitor or Print Processor Registration Abuse

Identifies port monitor and print processor registry modifications. Adversaries may abuse port monitor and print processors to run malicious DLLs during system boot that will be executed as SYSTEM for privilege escalation and/or persistence, if permissions allow writing a fully-qualified pathname for that DLL.

T1547T1547.010T1547.012
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
8f3e91c7-d791-4704-80a1-42c160d7aa27
HighElastic detection rules
Suspicious DLL Loaded for Persistence or Privilege Escalation

Identifies the loading of a non Microsoft signed DLL that is missing on a default Windows install (phantom DLL) or one that can be loaded from a different location by a native Windows process. This may be abused to persist or elevate privileges via privileged file write vulnerabilities.

T1036T1036.001T1574T1574.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
bfeaf89b-a2a7-48a3-817f-e41829dc61ee
Loading detections