Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 7,367
- detections
Showing 30 of 7,367
Detects suspicious child process execution originating from PaperCut server components, including the PaperCut NG/MF Application Server (pc-app.exe) and PaperCut Hive print job spooler (pc-printjob-spooler.exe). Active exploitation of CVE-2026-82078 and CVE-2026-81578 abuses unsafe dynamic class loading and an authentication bypass to achieve pre-authenticated remote code execution under pc-app.exe.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 29, 2026
- Upstream
- 1d0cf8ae-ed2c-4c74-bc01-462cfd928b64
Finder Sync plugins enable users to extend Finder’s functionality by modifying the user interface. Adversaries may abuse this feature by adding a rogue Finder Plugin to repeatedly execute malicious payloads for persistence.
- Licence
- Elastic License 2.0
- Written by
- Elastic +1
- Published
- Aug 29, 2026
- Upstream
- 37f638ea-909d-4f94-9248-edd21e4a9906
Detects use of the systemsetup command to enable remote SSH Login.
- Licence
- Elastic License 2.0
- Written by
- Elastic +1
- Published
- Aug 29, 2026
- Upstream
- 5ae4e6f8-d1bf-40fa-96ba-e29645e1e4dc
Identifies the use of sqlite3 to directly modify the Transparency, Consent, and Control (TCC) SQLite database. This may indicate an attempt to bypass macOS privacy controls, including access to sensitive resources like the system camera, microphone, address book, and calendar.
- Licence
- Elastic License 2.0
- Written by
- Elastic +1
- Published
- Aug 29, 2026
- Upstream
- eea82229-b002-470e-a9e1-00be38b14d32
Identifies the access or file open of web browser sensitive files by an untrusted/unsigned process or osascript. Adversaries may acquire credentials from web browsers by reading files specific to the target browser.
- Licence
- Elastic License 2.0
- Written by
- Elastic +1
- Published
- Aug 29, 2026
- Upstream
- 20457e4f-d1de-4b92-ae69-142e27a4342a
Identifies the execution of macOS built-in commands used to dump user account hashes. Adversaries may attempt to dump credentials to obtain account login information in the form of a hash. These hashes can be cracked or leveraged for lateral movement.
- Licence
- Elastic License 2.0
- Written by
- Elastic +1
- Published
- Aug 29, 2026
- Upstream
- 02ea4563-ec10-4974-b7de-12e65aa4f9b3
Detects potential privilege escalation under the root effective user when the real user and parent user are not root, indicative of the execution of binaries with SUID or SGID bits set.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 29, 2026
- Upstream
- 769a2e72-11bd-437b-9503-e51e7790d273
Identifies potentially suspicious use of unshare to create a user namespace context followed by a UID change event indicating a transition to root. Adversaries may use unshare-based primitives as part of local privilege escalation chains. This rule is intentionally generic and can surface multiple local privesc patterns beyond a single CVE.
- Licence
- Elastic License 2.0
- Written by
- Elastic +1
- Published
- Aug 29, 2026
- Upstream
- b51dbc92-84e2-4af1-ba47-65183fcd0c57
Identifies the use of a compression utility to collect known files containing sensitive information, such as credentials and system configurations.
- Licence
- Elastic License 2.0
- Written by
- Elastic +1
- Published
- Aug 29, 2026
- Upstream
- 6b84d470-9036-4cc0-a27c-6d90bbfe81ab
Detects creation of Java .class files within the PaperCut NG/MF Application Server library directory. During active exploitation of CVE-2026-82078 (chained with CVE-2026-81578), attackers deliver hex-encoded malicious .class payloads into the PaperCut server/lib path (observed examples include Udydn.class and Moo97.class) so arbitrary bytecode executes inside the PaperCut JVM / Application Server process.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 29, 2026
- Upstream
- a2d4508e-e9c2-41f6-9466-0c3aed8cc2c9
Identifies the creation of a Windows service by an unusual client process. Services may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges from administrator to SYSTEM.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 55c2bf58-2a39-4c58-a384-c8b1978153c2
Identifies the creation of a process running as SYSTEM while impersonating the token context of a Windows core binary. Adversaries may create a new process with a different token to escalate privileges and bypass access controls.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 02a23ee7-c8f8-4701-b99d-e9038ce313cb
Identifies a privilege escalation attempt via rogue named pipe impersonation. An adversary may abuse this technique by masquerading as a known named pipe and manipulating a privileged process to connect to it.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 76ddb638-abf7-42d5-be22-4a70b0bf7241
Identifies parent process spoofing used to create an elevated child process. Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 26b01043-4f04-4d2f-882a-5a1d2e95751b
Identifies unusual child processes of Service Host (svchost.exe) that traditionally do not spawn any child processes. This may indicate a code injection or an equivalent form of exploitation.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 6a8ab9cc-4023-4d17-b5df-1a3e16882ce7
Detects unusual Print Spooler service (spoolsv.exe) child processes. This may indicate an attempt to exploit privilege escalation vulnerabilities related to the Printing Service on Windows.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- ee5300a7-7e31-4a72-a258-250abb8b3aa1
Identifies Windows programs run from unexpected parent processes. This could indicate masquerading or other strange activity on a system.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 35df0dd8-092d-4a83-88c1-5151a804f31b
Adversaries may leverage unquoted service path vulnerabilities to escalate privileges. By placing an executable in a higher-level directory within the path of an unquoted service executable, Windows will natively launch this executable from its defined path variable instead of the benign one in a deeper directory, thus leading to code execution.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 12de29d4-bbb0-4eef-b687-857e8a163870
Identifies attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in. Attackers bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 1178ae09-5aff-460a-9f2f-455cd0ac4d8e
Identifies an attempt to bypass User Account Control (UAC) by masquerading as a Microsoft trusted Windows directory. Attackers may bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 290aca65-e94d-403b-ba0f-62f320e63f51
Identifies User Account Control (UAC) bypass via eventvwr.exe. Attackers bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 31b4c719-f2b4-41f6-a9bd-fce93c2eaf62
Identifies attempts to bypass User Account Control (UAC) via DLL side-loading. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 5a14d01d-7ac8-4545-914c-b687c2cf66b3
Identifies User Account Control (UAC) bypass via hijacking DiskCleanup Scheduled Task. Attackers bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 1dcc51f6-ba26-49e7-9ef4-2655abb2361e
Identifies User Account Control (UAC) bypass attempts via the ICMLuaUtil Elevated COM interface. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 68d56fdc-7ffa-4419-8e95-81641bd6f845
Identifies User Account Control (UAC) bypass attempts by abusing an elevated COM Interface to launch a malicious program. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- fc7c0fa4-8f03-4b3e-8336-c5feab0be022
Identifies attempts to bypass User Account Control (UAC) by abusing an elevated COM Interface to launch a rogue Windows ClipUp program. Attackers may attempt to bypass UAC to stealthily execute code with elevated permissions.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- b90cdde7-7e0d-4359-8bf0-2c112ce2008a
Identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege. Adversaries may enable this privilege to debug and modify other processes, typically reserved for system-level tasks, to escalate privileges and bypass access controls.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 97020e61-e591-4191-8a3b-2861a2b887cd
Identifies attempts to use the SeIncreaseBasePriorityPrivilege privilege by an unusual process. This could be related to hijack execution flow of a process via threats priority manipulation.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 6fa0f15b-1926-419b-8de2-fce1429797ba
Identifies a user account that normally logs in with high volume from one source IP suddenly logging in from a different source IP. This pattern (one IP with many successful logons, another IP with very few) may indicate account takeover or use of stolen credentials from a new location.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- a1b2c3d4-e5f6-4a5b-8c9d-0e1f2a3b4c5d
Identifies the remote update to a computer account's DnsHostName attribute. If the new value set is a valid domain controller DNS hostname and the subject computer name is not a domain controller, then it's highly likely a preparation step to exploit CVE-2022-26923 in an attempt to elevate privileges from a standard domain user to domain admin privileges.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Aug 27, 2026
- Upstream
- 6bed021a-0afb-461c-acbe-ffdb9574d3f3