sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

7,367
detections

Showing 30 of 7,367

HighElastic detection rules
Suspicious Child Process of PaperCut Server Component

Detects suspicious child process execution originating from PaperCut server components, including the PaperCut NG/MF Application Server (pc-app.exe) and PaperCut Hive print job spooler (pc-printjob-spooler.exe). Active exploitation of CVE-2026-82078 and CVE-2026-81578 abuses unsafe dynamic class loading and an authentication bypass to achieve pre-authenticated remote code execution under pc-app.exe.

T1059T1059.001T1059.003T1190
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 29, 2026
Upstream
1d0cf8ae-ed2c-4c74-bc01-462cfd928b64
MediumElastic detection rules
Finder Sync Plugin Registered and Enabled

Finder Sync plugins enable users to extend Finder’s functionality by modifying the user interface. Adversaries may abuse this feature by adding a rogue Finder Plugin to repeatedly execute malicious payloads for persistence.

T1543
Licence
Elastic License 2.0
Written by
Elastic +1
Published
Aug 29, 2026
Upstream
37f638ea-909d-4f94-9248-edd21e4a9906
MediumElastic detection rules
Remote SSH Login Enabled via systemsetup Command

Detects use of the systemsetup command to enable remote SSH Login.

T1021T1021.004T1133
Licence
Elastic License 2.0
Written by
Elastic +1
Published
Aug 29, 2026
Upstream
5ae4e6f8-d1bf-40fa-96ba-e29645e1e4dc
MediumElastic detection rules
Potential Privacy Control Bypass via TCCDB Modification

Identifies the use of sqlite3 to directly modify the Transparency, Consent, and Control (TCC) SQLite database. This may indicate an attempt to bypass macOS privacy controls, including access to sensitive resources like the system camera, microphone, address book, and calendar.

T1548T1548.006T1562T1562.001
Licence
Elastic License 2.0
Written by
Elastic +1
Published
Aug 29, 2026
Upstream
eea82229-b002-470e-a9e1-00be38b14d32
HighElastic detection rules
Suspicious Web Browser Sensitive File Access

Identifies the access or file open of web browser sensitive files by an untrusted/unsigned process or osascript. Adversaries may acquire credentials from web browsers by reading files specific to the target browser.

T1005T1539T1555T1555.003
Licence
Elastic License 2.0
Written by
Elastic +1
Published
Aug 29, 2026
Upstream
20457e4f-d1de-4b92-ae69-142e27a4342a
HighElastic detection rules
Dumping Account Hashes via Built-In Commands

Identifies the execution of macOS built-in commands used to dump user account hashes. Adversaries may attempt to dump credentials to obtain account login information in the form of a hash. These hashes can be cracked or leveraged for lateral movement.

T1003T1003.008
Licence
Elastic License 2.0
Written by
Elastic +1
Published
Aug 29, 2026
Upstream
02ea4563-ec10-4974-b7de-12e65aa4f9b3
HighElastic detection rules
Potential Privilege Escalation via SUID/SGID

Detects potential privilege escalation under the root effective user when the real user and parent user are not root, indicative of the execution of binaries with SUID or SGID bits set.

T1548T1548.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 29, 2026
Upstream
769a2e72-11bd-437b-9503-e51e7790d273
HighElastic detection rules
Potential Privilege Escalation via unshare and UID Change

Identifies potentially suspicious use of unshare to create a user namespace context followed by a UID change event indicating a transition to root. Adversaries may use unshare-based primitives as part of local privilege escalation chains. This rule is intentionally generic and can surface multiple local privesc patterns beyond a single CVE.

T1068T1548
Licence
Elastic License 2.0
Written by
Elastic +1
Published
Aug 29, 2026
Upstream
b51dbc92-84e2-4af1-ba47-65183fcd0c57
MediumElastic detection rules
Sensitive Files Compression

Identifies the use of a compression utility to collect known files containing sensitive information, such as credentials and system configurations.

T1005T1552T1552.001T1560T1560.001
Licence
Elastic License 2.0
Written by
Elastic +1
Published
Aug 29, 2026
Upstream
6b84d470-9036-4cc0-a27c-6d90bbfe81ab
CriticalElastic detection rules
Suspicious Java Class File Created in PaperCut Server Library

Detects creation of Java .class files within the PaperCut NG/MF Application Server library directory. During active exploitation of CVE-2026-82078 (chained with CVE-2026-81578), attackers deliver hex-encoded malicious .class payloads into the PaperCut server/lib path (observed examples include Udydn.class and Moo97.class) so arbitrary bytecode executes inside the PaperCut JVM / Application Server process.

T1059T1190T1620
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 29, 2026
Upstream
a2d4508e-e9c2-41f6-9466-0c3aed8cc2c9
HighElastic detection rules
Windows Service Installed via an Unusual Client

Identifies the creation of a Windows service by an unusual client process. Services may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges from administrator to SYSTEM.

T1543T1543.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
55c2bf58-2a39-4c58-a384-c8b1978153c2
HighElastic detection rules
Process Created with an Elevated Token

Identifies the creation of a process running as SYSTEM while impersonating the token context of a Windows core binary. Adversaries may create a new process with a different token to escalate privileges and bypass access controls.

T1134T1134.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
02a23ee7-c8f8-4701-b99d-e9038ce313cb
HighElastic detection rules
Privilege Escalation via Rogue Named Pipe Impersonation

Identifies a privilege escalation attempt via rogue named pipe impersonation. An adversary may abuse this technique by masquerading as a known named pipe and manipulating a privileged process to connect to it.

T1134T1134.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
76ddb638-abf7-42d5-be22-4a70b0bf7241
HighElastic detection rules
Privileges Elevation via Parent Process PID Spoofing

Identifies parent process spoofing used to create an elevated child process. Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.

T1134T1134.002T1134.004
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
26b01043-4f04-4d2f-882a-5a1d2e95751b
MediumElastic detection rules
Unusual Service Host Child Process - Childless Service

Identifies unusual child processes of Service Host (svchost.exe) that traditionally do not spawn any child processes. This may indicate a code injection or an equivalent form of exploitation.

T1055T1055.012
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
6a8ab9cc-4023-4d17-b5df-1a3e16882ce7
MediumElastic detection rules
Unusual Print Spooler Child Process

Detects unusual Print Spooler service (spoolsv.exe) child processes. This may indicate an attempt to exploit privilege escalation vulnerabilities related to the Printing Service on Windows.

T1068
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
ee5300a7-7e31-4a72-a258-250abb8b3aa1
MediumElastic detection rules
Unusual Parent-Child Relationship

Identifies Windows programs run from unexpected parent processes. This could indicate masquerading or other strange activity on a system.

T1036T1036.009T1055T1055.012T1134+1 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
35df0dd8-092d-4a83-88c1-5151a804f31b
LowElastic detection rules
Potential Exploitation of an Unquoted Service Path Vulnerability

Adversaries may leverage unquoted service path vulnerabilities to escalate privileges. By placing an executable in a higher-level directory within the path of an unquoted service executable, Windows will natively launch this executable from its defined path variable instead of the benign one in a deeper directory, thus leading to code execution.

T1574T1574.009
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
12de29d4-bbb0-4eef-b687-857e8a163870
MediumElastic detection rules
UAC Bypass via Windows Firewall Snap-In Hijack

Identifies attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in. Attackers bypass UAC to stealthily execute code with elevated permissions.

T1218T1218.014T1548T1548.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
1178ae09-5aff-460a-9f2f-455cd0ac4d8e
HighElastic detection rules
UAC Bypass Attempt via Windows Directory Masquerading

Identifies an attempt to bypass User Account Control (UAC) by masquerading as a Microsoft trusted Windows directory. Attackers may bypass UAC to stealthily execute code with elevated permissions.

T1036T1036.005T1548T1548.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
290aca65-e94d-403b-ba0f-62f320e63f51
HighElastic detection rules
Bypass UAC via Event Viewer

Identifies User Account Control (UAC) bypass via eventvwr.exe. Attackers bypass UAC to stealthily execute code with elevated permissions.

T1548T1548.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
31b4c719-f2b4-41f6-a9bd-fce93c2eaf62
HighElastic detection rules
UAC Bypass Attempt via Privileged IFileOperation COM Interface

Identifies attempts to bypass User Account Control (UAC) via DLL side-loading. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.

T1548T1548.002T1574T1574.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
5a14d01d-7ac8-4545-914c-b687c2cf66b3
MediumElastic detection rules
UAC Bypass via DiskCleanup Scheduled Task Hijack

Identifies User Account Control (UAC) bypass via hijacking DiskCleanup Scheduled Task. Attackers bypass UAC to stealthily execute code with elevated permissions.

T1053T1053.005T1548T1548.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
1dcc51f6-ba26-49e7-9ef4-2655abb2361e
HighElastic detection rules
UAC Bypass via ICMLuaUtil Elevated COM Interface

Identifies User Account Control (UAC) bypass attempts via the ICMLuaUtil Elevated COM interface. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.

T1548T1548.002T1559T1559.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
68d56fdc-7ffa-4419-8e95-81641bd6f845
MediumElastic detection rules
UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer

Identifies User Account Control (UAC) bypass attempts by abusing an elevated COM Interface to launch a malicious program. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.

T1218T1548T1548.002T1559T1559.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
fc7c0fa4-8f03-4b3e-8336-c5feab0be022
HighElastic detection rules
UAC Bypass Attempt with IEditionUpgradeManager Elevated COM Interface

Identifies attempts to bypass User Account Control (UAC) by abusing an elevated COM Interface to launch a rogue Windows ClipUp program. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.

T1548T1548.002T1559T1559.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
b90cdde7-7e0d-4359-8bf0-2c112ce2008a
MediumElastic detection rules
SeDebugPrivilege Enabled by a Suspicious Process

Identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege. Adversaries may enable this privilege to debug and modify other processes, typically reserved for system-level tasks, to escalate privileges and bypass access controls.

T1134
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
97020e61-e591-4191-8a3b-2861a2b887cd
HighElastic detection rules
Suspicious SeIncreaseBasePriorityPrivilege Use

Identifies attempts to use the SeIncreaseBasePriorityPrivilege privilege by an unusual process. This could be related to hijack execution flow of a process via threats priority manipulation.

T1134
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
6fa0f15b-1926-419b-8de2-fce1429797ba
MediumElastic detection rules
Potential Account Takeover - Logon from New Source IP

Identifies a user account that normally logs in with high volume from one source IP suddenly logging in from a different source IP. This pattern (one IP with many successful logons, another IP with very few) may indicate account takeover or use of stolen credentials from a new location.

T1078
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
a1b2c3d4-e5f6-4a5b-8c9d-0e1f2a3b4c5d
HighElastic detection rules
Remote Computer Account DnsHostName Update

Identifies the remote update to a computer account's DnsHostName attribute. If the new value set is a valid domain controller DNS hostname and the subject computer name is not a domain controller, then it's highly likely a preparation step to exploit CVE-2022-26923 in an attempt to elevate privileges from a standard domain user to domain admin privileges.

T1068T1078T1078.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Aug 27, 2026
Upstream
6bed021a-0afb-461c-acbe-ffdb9574d3f3
Loading detections