Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,217
- detections
Showing 30 of 11,217
Detect unusual logon times, MFA fatigue, or service principal misuse across hybrid environments. Get visibility into geo-location of events and Threat Intelligence insights. Here''s an example of how you can easily discover Accounts authenticating without MFA and from uncommonly connected countries using UEBA behaviorAnalytics table:
- Licence
- MIT License
- Published
- Sep 4, 2026
Detects users who have been compromised multiple times within a 7-day window. This may indicate a persistent threat or inadequate remediation. Ref: https://data443.com/tacitred-attack-surface-intelligence/
- Licence
- MIT License
- Published
- Sep 4, 2026
This query searches for guest is not an admin in Azure
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies beaconing patterns from PAN traffic logs based on recurrent timedelta patterns. Reference Blog:https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/detect-network-beaconing-via-intra-request-time-delta-patterns/ba-p/779586
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies Palo Alto Threat signatures from unusual IP addresses which are not historically seen. This detection is also leveraged and required for MDE and PAN Fusion scenario https://docs.microsoft.com/Azure/sentinel/fusion-scenario-reference#network-request-to-tor-anonymization-service-followed-by-anomalous-traffic-flagged-by-palo-alto-networks-firewall
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies a list of internal Source IPs (10.x.x.x Hosts) that have triggered 10 or more non-graceful tcp server resets from one or more Destination IPs which results in an "ApplicationProtocol = incomplete" designation. The server resets coupled with an "Incomplete" ApplicationProtocol designation can be an indication of internal to external port scanning or probing attack. References: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUvCAK and https://knowledgebase.
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies beaconing patterns from Palo Alto Network traffic logs based on recurrent timedelta patterns. The query leverages various KQL functions to calculate time deltas and then compares it with total events observed in a day to find percentage of beaconing. This outbound beaconing pattern to untrusted public networks should be investigated for any malware callbacks or data exfiltration attempts. Reference Blog: https://medium.
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies the host and account that executed AdFind by hash and filename in addition to common and unique flags that are used by many threat actors in discovery.
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies suspicious child processes of SolarWinds.Orion.Core.BusinessLayer.dll that may be evidence of the SUNBURST backdoor
- Licence
- MIT License
- Published
- Sep 4, 2026
This query visualises the daily amount of emails that had a post delivery action from zero-hour auto purge, summarizing by phish,spam or malware detection action
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- dbc25434-bbe7-4517-bf4b-48ad9cb4e980
This query visualises the daily amount of emails that had an admin post delivery action, summarizing the data by action type
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 21bafecb-ae8f-4667-b7d6-144e047cb602
Visualises the top 10 users with click attempts on URLs in emails detected as spam, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 3a2fdf32-ebe7-4f65-a1c3-fc7faf23ae90
Visualises the top 10 users with click attempts on URLs in emails detected as phishing, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- a937905e-ee5c-406c-ab86-8e2581240112
Visualises the top 10 users with click attempts on URLs in emails detected as malware, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 5a84e13a-bb17-4124-9564-d74cdb84c124
This query visualises inbound email detections involving URLs embedded in QR codes over time, split by the threat type of the detection (phishing, malware, spam).
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 88035c0e-0e2d-4805-a249-34d54a88c3fe
This query visualises inbound email phishing detections attributed to URL-based detection technologies over time.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 4bce2a7c-31fb-46e9-8487-ce611bd98004
This query visualises inbound email malware detections attributed to URL-based detection technologies over time.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- effba60e-0a4a-4558-bbf6-4e099607d82e
This query summarises URL threat protection activity (Safe Links click outcomes and distinct URLs seen in email) as a set of headline metrics for the selected period.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- a0d5391b-a44c-433c-8e08-7137f6e4a23c
This query shows malicious URL click-throughs (where the user proceeded past the Safe Links warning) broken down by the workload the click came from.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 07e1f2f5-3662-4e8b-8f52-5273d220976b
This query lists the malicious URLs that registered the most user clicks, with threat type, click action and workload, using the UrlClickEvents table.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- d31069b5-44a5-4a5d-96fa-68db27074023
This query lists the top 20 URLs carrying a detection ranked by the number of clicks registered, with the threat type, click action and workload for each.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 13e20569-a96c-48c4-b0d7-3c2058d24245
This query visualises blocked Safe Links URL clicks over time broken down by the workload the click came from (Email, Teams, Office, Microsoft 365 Copilot).
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 22811654-25ac-43d6-ba63-699ec29dd6af
This query surfaces the largest malicious inbound email campaigns, clustered by EmailClusterId, with one row per attack wave, using the EmailEvents table.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- a92a3921-1a71-4a4d-8382-873b689ff7d8
This query visualises user false positive submissions by submission state.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 2f8a0226-b3f3-4a31-b32b-2dd15d644625
This query visualises user false positive submissions by the original spam filter verdict on the reported message.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 05d933db-f605-48d5-a177-af64be537cf4
This query visualises user false positive submissions by the original phish filter verdict on the reported message.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 4ae87c11-4030-42cb-b87d-993198ca40e0
This query visualises the daily amount of user false positive email submissions over time.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 97f0d020-be70-4732-b5d7-abcfeecc459c
This query visualises the top 10 inbound senders of emails submitted as false positives by users.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 37511ce4-f88e-4e2d-b505-27411af1a226
This query visualises the top 10 sender domains of emails submitted as false positives by users.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 97f19cad-130a-47b3-a3bb-cbc2e66845f0
This query visualises the top 10 intra-org senders of emails submitted as false positives by users.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 6b26701a-a1c7-4782-a662-f44cdca5bb5f
AWS GetFederationToken Followed by Console Login via Federation Exchange
Detects the three-event chain produced by tools like aws_consoler that convert exfiltrated long-term IAM access keys into browser-accessible AWS console sessions: GetFederationToken obtains temporary credentials, GetSigninToken exchanges them for a federation sign-in token via the AWS federation endpoint, and ConsoleLogin confirms the resulting console session was opened — all from the same source IP within two minutes. This sequence is a high-confidence indicator of credential abuse using stolen IAM access keys.
ATT&CK coverage
Detection requirements
- Log source category
- event_index
What the source says
What fires this without an attack behind it
- Legacy federation broker applications that call GetFederationToken and immediately redirect users to a console session from the same host may trigger this rule. Validate the source IP against known application server infrastructure and confirm the federation architecture is documented.
References
- https://docs.aws.amazon.com/STS/latest/APIReference/API_GetFederationToken.html
- https://github.com/NetSPI/aws_consoler
- https://securitylabs.datadoghq.com/cloud-security-atlas/attacks/accessing-the-aws-console-with-getfederationtoken/
- https://www.netspi.com/blog/technical-blog/cloud-pentesting/gaining-aws-console-access-via-api-keys/
Tagged by the source as
Detection logic
Its licence does not clear it for publishing here
Detections publishes a detection’s own text only where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.