Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,125
detections

Showing 30 of 11,125

MediumElastic detection rules
Installation of Custom Shim Databases

Identifies the installation of custom Application Compatibility Shim databases. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes.

T1546T1546.011
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
c5ce48a6-7f57-4ee8-9313-3d0024caee10
MediumElastic detection rules
Potential DNS Tunneling via Long and Unique Subdomains

Identifies a client generating many unique, unusually long DNS query names to the same registered domain within a five-minute window. Malware DNS tunnels and DNS command-and-control commonly encode data in lengthy subdomain portions under one apex domain.

T1048T1048.003T1071T1071.004T1572
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
89ed957d-609b-4b00-b8c6-a5cbd187632c
HighElastic detection rules
Cobalt Strike Command and Control Beacon

Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control.

T1071T1071.001T1568T1568.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
cf53f532-9cc9-445a-9ae7-fced307ec53c
HighElastic detection rules
SSFileCopyReceiver Writing to Common Persistence Locations

Identifies the macOS Screen Sharing file copy helper SSFileCopyReceiver creating or modifying files in common persistence locations, including system-wide and per-user LaunchDaemons/LaunchAgents, shell profiles, SSH authorized_keys, cron tabs, and hidden paths under root's home directory. SSFileCopyReceiver performs file writes with root authority on behalf of a remote viewer.

T1098T1098.004T1543T1543.001T1543.004+2 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
5773cef4-11a5-4d51-a40b-0e0a79d68432
MediumElastic detection rules
SSFileCopySender Executed as Root

Identifies execution of the macOS Screen Sharing file-copy helper SSFileCopySender with root UID/GID attributes (0 80). Under the native Apple authentication path this helper runs in the connecting user's context; execution as root is anomalous and consistent with pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400), where a flawed SRP validation path lets an unauthenticated attacker reach privileged file operations.

T1068T1190
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
e54c3f36-e243-402d-9d44-8f7349eb8c88
LowElastic detection rules
Binfmt Configuration File Creation

This rule detects the creation of a binfmt configuration file. Binfmt is a utility that is used to configure the behavior of the Linux kernel when executing binary files. By creating a malicious binfmt configuration file, threat actors can execute a backdoor script or command on the target system.

T1546
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
a3b47d21-20d6-45b0-8b75-fc27073bdef2
MediumElastic detection rules
File Downloaded by Curl/Wget and Piped to Interpreter

This rule detects when a file is downloaded by curl or wget, and piped to an interpreter. Attackers may use this technique to download and execute payloads for various malicious purposes, such as establishing persistence or exfiltrating data.

T1059T1059.004T1071
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
3ebdc01e-7788-4845-8e7a-c8a671ad46ea
MediumElastic detection rules
Suspicious Reading of procfs Syscall File

This rule detects command lines that reference another process or thread's procfs syscall file. The "/proc/<pid>/syscall" interface exposes the current syscall arguments, stack pointer, and instruction pointer, which can support process discovery and preparation for process injection. Self and thread-self aliases are excluded.

T1057
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
6327bdae-4dc4-4e2e-b29d-3fd100af522c
MediumElastic detection rules
Kubernetes Sensitive RBAC Change Followed by Workload Modification

Detects a sequence where a principal creates or modifies a Role/ClusterRole to include high-risk permissions (e.g., wildcard access or escalation verbs) and then creates or patches a workload resource (DaemonSet, Deployment, or CronJob) shortly after, which may indicate RBAC-based privilege escalation followed by payload deployment. This pattern is often used by adversaries to gain unauthorized access to sensitive resources and deploy malicious payloads.

T1098T1098.006
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
3c82bf84-5941-495b-ac41-0302f28e1a90
MediumElastic detection rules
GKE Sensitive RBAC Change Followed by Workload Modification

Detects when the same GKE identity creates or modifies a Role or ClusterRole with high-risk permissions (wildcard access, RBAC escalation verbs, or access to secrets / privileged APIs) and also creates or patches a DaemonSet, Deployment, or CronJob within five minutes. This correlation is consistent with RBAC-based privilege escalation followed by payload deployment.

T1098T1098.006
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
3ec2175d-8f34-4be9-b3be-c5821538760e
MediumElastic detection rules
AWS SES Email Identity Verified Then Deleted

Detects an SES email identity being verified and subsequently deleted within a 30-minute window, performed by the same AWS identity. Amazon SES requires email addresses and domains to be verified before they can be used as senders. An adversary who obtains SES credentials may verify a domain or address they control, use it to send phishing or spam email, then delete the identity to remove evidence of the sending domain from the account's verified identity list.

T1070T1583T1583.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
8e4bde35-125d-4eb3-9a2e-d7e77a053a08
MediumElastic detection rules
AWS Bedrock AgentCore Resource Created with IAM Execution Role

Detects the creation of an AWS Bedrock AgentCore resource (code interpreter, agent runtime, browser, or harness) with an IAM execution role attached. When an attacker with iam:PassRole permission creates an AgentCore resource and attaches a privileged role, subsequent invocations inside that resource execute as the attached role — enabling privilege escalation to roles that trust bedrock-agentcore.amazonaws.com.

T1078T1078.004T1098
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
2d8f6e1a-4b7c-4f9d-8e3a-1c5d2f8b9a0e
MediumElastic detection rules
AWS SES Full Access Policy Attached to IAM Entity by Unusual User

Detects the first occurrence in 7 days of an AWS identity attaching the managed policy AmazonSESFullAccess to an IAM user, role, or group. AmazonSESFullAccess grants unrestricted permission to send email, manage identities and templates, manage suppression lists, and access SES account-level settings. Granting this policy to an unexpected IAM entity, particularly a newly created user or a role not previously associated with email operations, is a documented technique used by threat actors to

T1098T1098.003T1608
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 2, 2026
Upstream
d2e3f4a5-b6c7-8901-bcde-f23456789012
MediumMicrosoft Sentinel analytics
Silk Typhoon Suspicious File Downloads.

This query looks for messages related to file downloads of suspicious file types. This query uses the Exchange HttpProxy AOBGeneratorLog, you will need to onboard this log as a custom log under the table http_proxy_oab_CL before using this query. Reference: https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/

T1190
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
03e04c97-8cae-48b3-9d2f-4ab262e4ffff
MediumMicrosoft Sentinel analytics
Exchange Server Suspicious File Downloads.

This query looks for messages related to file downloads of suspicious file types on an Exchange Server. This could indicate attempted deployment of webshells. This query uses the Exchange HttpProxy AOBGeneratorLog, you will need to onboard this log as a custom log under the table http_proxy_oab_CL before using this query. This log is commonly found at C:\Program Files\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog on the Exchange server.

T1190
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
8955c0fb-3408-47b0-a3b9-a1faec41e427
LowMicrosoft Sentinel analytics
Suspicious link sharing pattern

Alerts in links that have been shared across multiple Zoom chat channels by the same user in a short space if time. Adjust the threshold figure to change the number of channels a message needs to be posted in before an alert is raised.

T1598
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
1218175f-c534-421c-8070-5dcaabf28067
LowMicrosoft Sentinel analytics
User joining Zoom meeting from suspicious timezone

The alert shows users that join a Zoom meeting from a time zone other than the one the meeting was created in. You can also whitelist known good time zones in the tz_whitelist value using the tz database name format https://en.wikipedia.org/wiki/List_of_tz_database_time_zones

T1078
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
58fc0170-0877-4ea8-a9ff-d805e361cfae
LowMicrosoft Sentinel analytics
External User Access Enabled

This alerts when the account setting is changed to allow either external domain access or anonymous access to meetings.

T1098T1556
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
8e267e91-6bda-4b3c-bf68-9f5cbdd103a3
MediumMicrosoft Sentinel analytics
Zoom E2E Encryption Disabled

This alerts when end to end encryption is disabled for Zoom meetings.

T1040
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
e4779bdc-397a-4b71-be28-59e6a1e1d16b
MediumMicrosoft Sentinel analytics
Silk Typhoon Suspicious Exchange Request

This query looks for suspicious request patterns to Exchange servers that fit a pattern observed by Silk Typhoon actors. The same query can be run on HTTPProxy logs from on-premise hosted Exchange servers. Reference: https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/

T1190
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
23005e87-2d3a-482b-b03d-edbebd1ae151
HighMicrosoft Sentinel analytics
Exchange SSRF Autodiscover ProxyShell - Detection

This query looks for suspicious request patterns to Exchange servers that fit patterns recently blogged about by PeterJson. This exploitation chain utilises an SSRF vulnerability in Exchange which eventually allows the attacker to execute arbitrary Powershell on the server. In the example powershell can be used to write an email to disk with an encoded attachment containing a shell. Reference: https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1

T1190
Licence
MIT License
Written by
Thomas McElroy
Published
Sep 2, 2026
Upstream
968358d6-6af8-49bb-aaa4-187b3067fb95
MediumMicrosoft Sentinel analytics
High count of connections by client IP on many ports

Identifies when 30 or more ports are used for a given client IP in 10 minutes occurring on the IIS server. This could be indicative of attempted port scanning or exploit attempt at internet facing web applications. This could also simply indicate a misconfigured service or device. References: IIS status code mapping - https://support.microsoft.com/help/943891/the-http-status-code-in-iis-7-0-iis-7-5-and-iis-8-0 Win32 Status code mapping - https://msdn.microsoft.com/library/cc231199.aspx

T1190
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
44a555d8-ecee-4a25-95ce-055879b4b14b
MediumMicrosoft Sentinel analytics
High count of failed logons by a user

Identifies when 100 or more failed attempts by a given user in 10 minutes occur on the IIS Server. This could be indicative of attempted brute force based on known account information. This could also simply indicate a misconfigured service or device. References: IIS status code mapping - https://support.microsoft.com/help/943891/the-http-status-code-in-iis-7-0-iis-7-5-and-iis-8-0 Win32 Status code mapping - https://msdn.microsoft.com/library/cc231199.aspx

T1110
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
884c4957-70ea-4f57-80b9-1bca3890315b
MediumMicrosoft Sentinel analytics
High count of failed attempts from same client IP

Identifies when 20 or more failed attempts from a given client IP in 1 minute occur on the IIS server. This could be indicative of an attempted brute force. This could also simply indicate a misconfigured service or device. Recommendations: Validate that these are expected connections from the given Client IP. If the client IP is not recognized, potentially block these connections at the edge device.

T1110
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
19e01883-15d8-4eb6-a7a5-3276cd668388
LowMicrosoft Sentinel analytics
Anomalous User Agent connection attempt

Identifies connection attempts (success or fail) from clients with very short or very long User Agent strings and with less than 100 connection attempts.

T1190
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
f845881e-2500-44dc-8ed7-b372af3e1e25
MediumMicrosoft Sentinel analytics
Service Principal Authentication Attempt from New Country

Detects when there is a Service Principal login attempt from a country that has not seen a successful login in the previous 14 days. Threat actors may attempt to authenticate with credentials from compromised accounts - monitoring attempts from anomalous locations may help identify these attempts. Authentication attempts should be investigated to ensure the activity was legitimate and if there is other similar activity. Ref: https://docs.microsoft.

T1078.004
Licence
MIT License
Written by
Pete Bryan
Published
Sep 2, 2026
Upstream
1baaaf00-655f-4de9-8ff8-312e902cda71
MediumMicrosoft Sentinel analytics
Privileged User Logon from new ASN

Detects a successful logon by a privileged account from an ASN not logged in from in the last 14 days. Monitor these logons to ensure they are legitimate and identify if there are any similar sign ins.

T1078.004
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
55073036-bb86-47d3-a85a-b113ac3d9396
MediumMicrosoft Sentinel analytics
New country signIn with correct password

Identifies an interrupted sign-in session from a country the user has not sign-in before in the last 7 days, where the password was correct. Although the session is interrupted by other controls such as multi factor authentication or conditional access policies, the user credentials should be reset due to logs indicating a correct password was observed during sign-in.

T1078T1110
Licence
MIT License
Written by
Juanse
Published
Sep 2, 2026
Upstream
7808c05a-3afd-4d13-998a-a59e2297693f
MediumMicrosoft Sentinel analytics
Authentications of Privileged Accounts Outside of Expected Controls

Detects when a privileged user account successfully authenticates from a location, device or ASN that another admin has not logged in from in the last 7 days. Privileged accounts are a key target for threat actors, monitoring for logins from these accounts that deviate from normal activity can help identify compromised accounts. Authentication attempts should be investigated to ensure the activity was legitimate and if there is other similar activity. Ref: https://docs.microsoft.

T1078.004
Licence
MIT License
Written by
Pete Bryan
Published
Sep 2, 2026
Upstream
af435ca1-fb70-4de1-92c1-7435c48482a9
MediumMicrosoft Sentinel analytics
Authentication Attempt from New Country

Detects when there is a login attempt from a country that has not seen a successful login in the previous 14 days. Threat actors may attempt to authenticate with credentials from compromised accounts - monitoring attempts from anomalous locations may help identify these attempts. Authentication attempts should be investigated to ensure the activity was legitimate and if there is other similar activity. Ref: https://docs.microsoft.

T1078.004
Licence
MIT License
Written by
Microsoft Security Research
Published
Sep 2, 2026
Upstream
ef895ada-e8e8-4cf0-9313-b1ab67fab69f
Loading detections

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice

Missing Domain Controller Heartbeat · Sunturai