Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 7,365
- detections
Showing 30 of 7,365
Identifies the creation of a Windows service by an unusual client process. Services may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges from administrator to SYSTEM.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 55c2bf58-2a39-4c58-a384-c8b1978153c2
Identifies the creation of a process running as SYSTEM while impersonating the token context of a Windows core binary. Adversaries may create a new process with a different token to escalate privileges and bypass access controls.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 02a23ee7-c8f8-4701-b99d-e9038ce313cb
Identifies a privilege escalation attempt via rogue named pipe impersonation. An adversary may abuse this technique by masquerading as a known named pipe and manipulating a privileged process to connect to it.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 76ddb638-abf7-42d5-be22-4a70b0bf7241
Identifies parent process spoofing used to create an elevated child process. Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 26b01043-4f04-4d2f-882a-5a1d2e95751b
Identifies unusual child processes of Service Host (svchost.exe) that traditionally do not spawn any child processes. This may indicate a code injection or an equivalent form of exploitation.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 6a8ab9cc-4023-4d17-b5df-1a3e16882ce7
Detects unusual Print Spooler service (spoolsv.exe) child processes. This may indicate an attempt to exploit privilege escalation vulnerabilities related to the Printing Service on Windows.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- ee5300a7-7e31-4a72-a258-250abb8b3aa1
Identifies Windows programs run from unexpected parent processes. This could indicate masquerading or other strange activity on a system.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 35df0dd8-092d-4a83-88c1-5151a804f31b
Adversaries may leverage unquoted service path vulnerabilities to escalate privileges. By placing an executable in a higher-level directory within the path of an unquoted service executable, Windows will natively launch this executable from its defined path variable instead of the benign one in a deeper directory, thus leading to code execution.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 12de29d4-bbb0-4eef-b687-857e8a163870
Identifies attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in. Attackers bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 1178ae09-5aff-460a-9f2f-455cd0ac4d8e
Identifies an attempt to bypass User Account Control (UAC) by masquerading as a Microsoft trusted Windows directory. Attackers may bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 290aca65-e94d-403b-ba0f-62f320e63f51
Identifies User Account Control (UAC) bypass via eventvwr.exe. Attackers bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 31b4c719-f2b4-41f6-a9bd-fce93c2eaf62
Identifies attempts to bypass User Account Control (UAC) via DLL side-loading. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 5a14d01d-7ac8-4545-914c-b687c2cf66b3
Identifies User Account Control (UAC) bypass via hijacking DiskCleanup Scheduled Task. Attackers bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 1dcc51f6-ba26-49e7-9ef4-2655abb2361e
Identifies User Account Control (UAC) bypass attempts via the ICMLuaUtil Elevated COM interface. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 68d56fdc-7ffa-4419-8e95-81641bd6f845
Identifies User Account Control (UAC) bypass attempts by abusing an elevated COM Interface to launch a malicious program. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- fc7c0fa4-8f03-4b3e-8336-c5feab0be022
Identifies attempts to bypass User Account Control (UAC) by abusing an elevated COM Interface to launch a rogue Windows ClipUp program. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- b90cdde7-7e0d-4359-8bf0-2c112ce2008a
Identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege. Adversaries may enable this privilege to debug and modify other processes, typically reserved for system-level tasks, to escalate privileges and bypass access controls.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 97020e61-e591-4191-8a3b-2861a2b887cd
Identifies attempts to use the SeIncreaseBasePriorityPrivilege privilege by an unusual process. This could be related to hijack execution flow of a process via threats priority manipulation.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 6fa0f15b-1926-419b-8de2-fce1429797ba
Identifies a user account that normally logs in with high volume from one source IP suddenly logging in from a different source IP. This pattern (one IP with many successful logons, another IP with very few) may indicate account takeover or use of stolen credentials from a new location.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- a1b2c3d4-e5f6-4a5b-8c9d-0e1f2a3b4c5d
Identifies the remote update to a computer account's DnsHostName attribute. If the new value set is a valid domain controller DNS hostname and the subject computer name is not a domain controller, then it's highly likely a preparation step to exploit CVE-2022-26923 in an attempt to elevate privileges from a standard domain user to domain admin privileges.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 6bed021a-0afb-461c-acbe-ffdb9574d3f3
Identifies Service Control (sc.exe) spawning from script interpreter processes to create, modify, or start services. This can potentially indicate an attempt to elevate privileges or maintain persistence.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- e8571d5f-bea1-46c2-9f56-998de2d3ed95
Identifies a suspicious computer account name rename event, which may indicate an attempt to exploit CVE-2021-42278 to elevate privileges from a standard domain user to a user with domain admin privileges. CVE-2021-42278 is a security vulnerability that allows potential attackers to impersonate a domain controller via samAccountName attribute spoofing.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- bdcf646b-08d4-492c-870a-6c04e3700034
Identifies a privilege escalation attempt via a rogue Windows directory (Windir) environment variable. This is a known primitive that is often combined with other vulnerabilities to elevate privileges.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- d563aaba-2e72-462b-8658-3e5ea22db3a6
Identifies registry modifications to default services that could enable privilege escalation to SYSTEM. Attackers with privileges from groups like Server Operators may change the ImagePath of services to executables under their control or to execute commands.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- b66b7e2b-d50a-49b9-a6fc-3a383baedc6b
Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service including CVE-2020-1048 and CVE-2020-1337.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- a7ccae7b-9d2c-44b2-a061-98e5946971fa
Detects deletion of print driver files by an unusual process. This may indicate a clean up attempt post successful privilege escalation via Print Spooler service related vulnerabilities.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- c4818812-d44f-47be-aaef-4cfb2f9cc799
Detects attempts to exploit a privilege escalation vulnerability (CVE-2020-1030) related to the print spooler service. Exploitation involves chaining multiple primitives to load an arbitrary DLL into the print spooler process running as SYSTEM.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- bd7eefee-f671-494e-98df-f01daf9e5f17
Detects PowerShell scripts that references token manipulation and impersonation APIs such as CreateProcessWithTokenW, DuplicateToken/ImpersonateLoggedOnUser, or AdjustTokenPrivileges (SeDebugPrivilege). Attackers abuse token impersonation to elevate privileges and bypass access controls.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 11dd9713-0ec6-4110-9707-32daae1ee68c
Identifies port monitor and print processor registry modifications. Adversaries may abuse port monitor and print processors to run malicious DLLs during system boot that will be executed as SYSTEM for privilege escalation and/or persistence, if permissions allow writing a fully-qualified pathname for that DLL.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 8f3e91c7-d791-4704-80a1-42c160d7aa27
Identifies the loading of a non Microsoft signed DLL that is missing on a default Windows install (phantom DLL) or one that can be loaded from a different location by a native Windows process. This may be abused to persist or elevate privileges via privileged file write vulnerabilities.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- bfeaf89b-a2a7-48a3-817f-e41829dc61ee