Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,125
- detections
Showing 30 of 11,125
Identifies the installation of custom Application Compatibility Shim databases. This Windows functionality has been abused by attackers to stealthily gain persistence and arbitrary code execution in legitimate Windows processes.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- c5ce48a6-7f57-4ee8-9313-3d0024caee10
Identifies a client generating many unique, unusually long DNS query names to the same registered domain within a five-minute window. Malware DNS tunnels and DNS command-and-control commonly encode data in lengthy subdomain portions under one apex domain.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- 89ed957d-609b-4b00-b8c6-a5cbd187632c
Cobalt Strike is a threat emulation platform commonly modified and used by adversaries to conduct network attack and exploitation campaigns. This rule detects a network activity algorithm leveraged by Cobalt Strike implant beacons for command and control.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- cf53f532-9cc9-445a-9ae7-fced307ec53c
Identifies the macOS Screen Sharing file copy helper SSFileCopyReceiver creating or modifying files in common persistence locations, including system-wide and per-user LaunchDaemons/LaunchAgents, shell profiles, SSH authorized_keys, cron tabs, and hidden paths under root's home directory. SSFileCopyReceiver performs file writes with root authority on behalf of a remote viewer.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- 5773cef4-11a5-4d51-a40b-0e0a79d68432
Identifies execution of the macOS Screen Sharing file-copy helper SSFileCopySender with root UID/GID attributes (0 80). Under the native Apple authentication path this helper runs in the connecting user's context; execution as root is anomalous and consistent with pre-authentication exploitation of the Screen Sharing service (CVE-2026-65400), where a flawed SRP validation path lets an unauthenticated attacker reach privileged file operations.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- e54c3f36-e243-402d-9d44-8f7349eb8c88
This rule detects the creation of a binfmt configuration file. Binfmt is a utility that is used to configure the behavior of the Linux kernel when executing binary files. By creating a malicious binfmt configuration file, threat actors can execute a backdoor script or command on the target system.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- a3b47d21-20d6-45b0-8b75-fc27073bdef2
This rule detects when a file is downloaded by curl or wget, and piped to an interpreter. Attackers may use this technique to download and execute payloads for various malicious purposes, such as establishing persistence or exfiltrating data.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- 3ebdc01e-7788-4845-8e7a-c8a671ad46ea
This rule detects command lines that reference another process or thread's procfs syscall file. The "/proc/<pid>/syscall" interface exposes the current syscall arguments, stack pointer, and instruction pointer, which can support process discovery and preparation for process injection. Self and thread-self aliases are excluded.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- 6327bdae-4dc4-4e2e-b29d-3fd100af522c
Detects a sequence where a principal creates or modifies a Role/ClusterRole to include high-risk permissions (e.g., wildcard access or escalation verbs) and then creates or patches a workload resource (DaemonSet, Deployment, or CronJob) shortly after, which may indicate RBAC-based privilege escalation followed by payload deployment. This pattern is often used by adversaries to gain unauthorized access to sensitive resources and deploy malicious payloads.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- 3c82bf84-5941-495b-ac41-0302f28e1a90
Detects when the same GKE identity creates or modifies a Role or ClusterRole with high-risk permissions (wildcard access, RBAC escalation verbs, or access to secrets / privileged APIs) and also creates or patches a DaemonSet, Deployment, or CronJob within five minutes. This correlation is consistent with RBAC-based privilege escalation followed by payload deployment.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- 3ec2175d-8f34-4be9-b3be-c5821538760e
Detects an SES email identity being verified and subsequently deleted within a 30-minute window, performed by the same AWS identity. Amazon SES requires email addresses and domains to be verified before they can be used as senders. An adversary who obtains SES credentials may verify a domain or address they control, use it to send phishing or spam email, then delete the identity to remove evidence of the sending domain from the account's verified identity list.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- 8e4bde35-125d-4eb3-9a2e-d7e77a053a08
Detects the creation of an AWS Bedrock AgentCore resource (code interpreter, agent runtime, browser, or harness) with an IAM execution role attached. When an attacker with iam:PassRole permission creates an AgentCore resource and attaches a privileged role, subsequent invocations inside that resource execute as the attached role — enabling privilege escalation to roles that trust bedrock-agentcore.amazonaws.com.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- 2d8f6e1a-4b7c-4f9d-8e3a-1c5d2f8b9a0e
Detects the first occurrence in 7 days of an AWS identity attaching the managed policy AmazonSESFullAccess to an IAM user, role, or group. AmazonSESFullAccess grants unrestricted permission to send email, manage identities and templates, manage suppression lists, and access SES account-level settings. Granting this policy to an unexpected IAM entity, particularly a newly created user or a role not previously associated with email operations, is a documented technique used by threat actors to
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 2, 2026
- Upstream
- d2e3f4a5-b6c7-8901-bcde-f23456789012
This query looks for messages related to file downloads of suspicious file types. This query uses the Exchange HttpProxy AOBGeneratorLog, you will need to onboard this log as a custom log under the table http_proxy_oab_CL before using this query. Reference: https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 03e04c97-8cae-48b3-9d2f-4ab262e4ffff
This query looks for messages related to file downloads of suspicious file types on an Exchange Server. This could indicate attempted deployment of webshells. This query uses the Exchange HttpProxy AOBGeneratorLog, you will need to onboard this log as a custom log under the table http_proxy_oab_CL before using this query. This log is commonly found at C:\Program Files\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog on the Exchange server.
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 8955c0fb-3408-47b0-a3b9-a1faec41e427
Alerts in links that have been shared across multiple Zoom chat channels by the same user in a short space if time. Adjust the threshold figure to change the number of channels a message needs to be posted in before an alert is raised.
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 1218175f-c534-421c-8070-5dcaabf28067
The alert shows users that join a Zoom meeting from a time zone other than the one the meeting was created in. You can also whitelist known good time zones in the tz_whitelist value using the tz database name format https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 58fc0170-0877-4ea8-a9ff-d805e361cfae
This alerts when the account setting is changed to allow either external domain access or anonymous access to meetings.
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 8e267e91-6bda-4b3c-bf68-9f5cbdd103a3
This alerts when end to end encryption is disabled for Zoom meetings.
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- e4779bdc-397a-4b71-be28-59e6a1e1d16b
This query looks for suspicious request patterns to Exchange servers that fit a pattern observed by Silk Typhoon actors. The same query can be run on HTTPProxy logs from on-premise hosted Exchange servers. Reference: https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 23005e87-2d3a-482b-b03d-edbebd1ae151
This query looks for suspicious request patterns to Exchange servers that fit patterns recently blogged about by PeterJson. This exploitation chain utilises an SSRF vulnerability in Exchange which eventually allows the attacker to execute arbitrary Powershell on the server. In the example powershell can be used to write an email to disk with an encoded attachment containing a shell. Reference: https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1
- Licence
- MIT License
- Written by
- Thomas McElroy
- Published
- Sep 2, 2026
- Upstream
- 968358d6-6af8-49bb-aaa4-187b3067fb95
Identifies when 30 or more ports are used for a given client IP in 10 minutes occurring on the IIS server. This could be indicative of attempted port scanning or exploit attempt at internet facing web applications. This could also simply indicate a misconfigured service or device. References: IIS status code mapping - https://support.microsoft.com/help/943891/the-http-status-code-in-iis-7-0-iis-7-5-and-iis-8-0 Win32 Status code mapping - https://msdn.microsoft.com/library/cc231199.aspx
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 44a555d8-ecee-4a25-95ce-055879b4b14b
Identifies when 100 or more failed attempts by a given user in 10 minutes occur on the IIS Server. This could be indicative of attempted brute force based on known account information. This could also simply indicate a misconfigured service or device. References: IIS status code mapping - https://support.microsoft.com/help/943891/the-http-status-code-in-iis-7-0-iis-7-5-and-iis-8-0 Win32 Status code mapping - https://msdn.microsoft.com/library/cc231199.aspx
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 884c4957-70ea-4f57-80b9-1bca3890315b
Identifies when 20 or more failed attempts from a given client IP in 1 minute occur on the IIS server. This could be indicative of an attempted brute force. This could also simply indicate a misconfigured service or device. Recommendations: Validate that these are expected connections from the given Client IP. If the client IP is not recognized, potentially block these connections at the edge device.
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 19e01883-15d8-4eb6-a7a5-3276cd668388
Identifies connection attempts (success or fail) from clients with very short or very long User Agent strings and with less than 100 connection attempts.
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- f845881e-2500-44dc-8ed7-b372af3e1e25
Detects when there is a Service Principal login attempt from a country that has not seen a successful login in the previous 14 days. Threat actors may attempt to authenticate with credentials from compromised accounts - monitoring attempts from anomalous locations may help identify these attempts. Authentication attempts should be investigated to ensure the activity was legitimate and if there is other similar activity. Ref: https://docs.microsoft.
- Licence
- MIT License
- Written by
- Pete Bryan
- Published
- Sep 2, 2026
- Upstream
- 1baaaf00-655f-4de9-8ff8-312e902cda71
Detects a successful logon by a privileged account from an ASN not logged in from in the last 14 days. Monitor these logons to ensure they are legitimate and identify if there are any similar sign ins.
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- 55073036-bb86-47d3-a85a-b113ac3d9396
Identifies an interrupted sign-in session from a country the user has not sign-in before in the last 7 days, where the password was correct. Although the session is interrupted by other controls such as multi factor authentication or conditional access policies, the user credentials should be reset due to logs indicating a correct password was observed during sign-in.
- Licence
- MIT License
- Written by
- Juanse
- Published
- Sep 2, 2026
- Upstream
- 7808c05a-3afd-4d13-998a-a59e2297693f
Detects when a privileged user account successfully authenticates from a location, device or ASN that another admin has not logged in from in the last 7 days. Privileged accounts are a key target for threat actors, monitoring for logins from these accounts that deviate from normal activity can help identify compromised accounts. Authentication attempts should be investigated to ensure the activity was legitimate and if there is other similar activity. Ref: https://docs.microsoft.
- Licence
- MIT License
- Written by
- Pete Bryan
- Published
- Sep 2, 2026
- Upstream
- af435ca1-fb70-4de1-92c1-7435c48482a9
Detects when there is a login attempt from a country that has not seen a successful login in the previous 14 days. Threat actors may attempt to authenticate with credentials from compromised accounts - monitoring attempts from anomalous locations may help identify these attempts. Authentication attempts should be investigated to ensure the activity was legitimate and if there is other similar activity. Ref: https://docs.microsoft.
- Licence
- MIT License
- Written by
- Microsoft Security Research
- Published
- Sep 2, 2026
- Upstream
- ef895ada-e8e8-4cf0-9313-b1ab67fab69f