Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,217
detections

Showing 30 of 11,217

Unknown
Anomalous AWS Console Login Without MFA from Uncommon Country

Detect unusual logon times, MFA fatigue, or service principal misuse across hybrid environments. Get visibility into geo-location of events and Threat Intelligence insights. Here''s an example of how you can easily discover Accounts authenticating without MFA and from uncommonly connected countries using UEBA behaviorAnalytics table:

T1078T1110
Licence
MIT License
Published
Sep 4, 2026
High
TacitRed - Repeat Compromise Detection

Detects users who have been compromised multiple times within a 7-day window. This may indicate a persistent threat or inadequate remediation. Ref: https://data443.com/tacitred-attack-surface-intelligence/

T1078
Licence
MIT License
Published
Sep 4, 2026
Unknown
Non-admin guest

This query searches for guest is not an admin in Azure

T1078
Licence
MIT License
Published
Sep 4, 2026
Low
Palo Alto - potential beaconing detected

Identifies beaconing patterns from PAN traffic logs based on recurrent timedelta patterns. Reference Blog:https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/detect-network-beaconing-via-intra-request-time-delta-patterns/ba-p/779586

T1071T1571
Licence
MIT License
Published
Sep 4, 2026
Medium
Palo Alto Threat signatures from Unusual IP addresses

Identifies Palo Alto Threat signatures from unusual IP addresses which are not historically seen. This detection is also leveraged and required for MDE and PAN Fusion scenario https://docs.microsoft.com/Azure/sentinel/fusion-scenario-reference#network-request-to-tor-anonymization-service-followed-by-anomalous-traffic-flagged-by-palo-alto-networks-firewall

T1030T1046T1071.001
Licence
MIT License
Published
Sep 4, 2026
Low
Palo Alto - possible internal to external port scanning

Identifies a list of internal Source IPs (10.x.x.x Hosts) that have triggered 10 or more non-graceful tcp server resets from one or more Destination IPs which results in an "ApplicationProtocol = incomplete" designation. The server resets coupled with an "Incomplete" ApplicationProtocol designation can be an indication of internal to external port scanning or probing attack. References: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUvCAK and https://knowledgebase.

T1046
Licence
MIT License
Published
Sep 4, 2026
Low
Palo Alto - potential beaconing detected

Identifies beaconing patterns from Palo Alto Network traffic logs based on recurrent timedelta patterns. The query leverages various KQL functions to calculate time deltas and then compares it with total events observed in a day to find percentage of beaconing. This outbound beaconing pattern to untrusted public networks should be investigated for any malware callbacks or data exfiltration attempts. Reference Blog: https://medium.

T1071T1571
Licence
MIT License
Published
Sep 4, 2026
High
Probable AdFind Recon Tool Usage

Identifies the host and account that executed AdFind by hash and filename in addition to common and unique flags that are used by many threat actors in discovery.

T1018
Licence
MIT License
Published
Sep 4, 2026
Medium
SUNBURST suspicious SolarWinds child processes

Identifies suspicious child processes of SolarWinds.Orion.Core.BusinessLayer.dll that may be evidence of the SUNBURST backdoor

T1059T1543
Licence
MIT License
Published
Sep 4, 2026
UnknownMicrosoft Sentinel analytics
Post Delivery Events by ZAP type

This query visualises the daily amount of emails that had a post delivery action from zero-hour auto purge, summarizing by phish,spam or malware detection action

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
dbc25434-bbe7-4517-bf4b-48ad9cb4e980
UnknownMicrosoft Sentinel analytics
Post Delivery Events by Admin

This query visualises the daily amount of emails that had an admin post delivery action, summarizing the data by action type

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
21bafecb-ae8f-4667-b7d6-144e047cb602
UnknownMicrosoft Sentinel analytics
Top 10 Users clicking on Malicious URLs (Spam)

Visualises the top 10 users with click attempts on URLs in emails detected as spam, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
3a2fdf32-ebe7-4f65-a1c3-fc7faf23ae90
UnknownMicrosoft Sentinel analytics
Top 10 Users clicking on Malicious URLs (Phish)

Visualises the top 10 users with click attempts on URLs in emails detected as phishing, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
a937905e-ee5c-406c-ab86-8e2581240112
UnknownMicrosoft Sentinel analytics
Top 10 Users clicking on Malicious URLs (Malware)

Visualises the top 10 users with click attempts on URLs in emails detected as malware, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
5a84e13a-bb17-4124-9564-d74cdb84c124
UnknownMicrosoft Sentinel analytics
QR Code URL Detections Trend

This query visualises inbound email detections involving URLs embedded in QR codes over time, split by the threat type of the detection (phishing, malware, spam).

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
88035c0e-0e2d-4805-a249-34d54a88c3fe
UnknownMicrosoft Sentinel analytics
Phishing URL Detections Trend

This query visualises inbound email phishing detections attributed to URL-based detection technologies over time.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
4bce2a7c-31fb-46e9-8487-ce611bd98004
UnknownMicrosoft Sentinel analytics
Malware URL Detections Trend

This query visualises inbound email malware detections attributed to URL-based detection technologies over time.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
effba60e-0a4a-4558-bbf6-4e099607d82e
UnknownMicrosoft Sentinel analytics
URL Threat Protection Summary

This query summarises URL threat protection activity (Safe Links click outcomes and distinct URLs seen in email) as a set of headline metrics for the selected period.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
a0d5391b-a44c-433c-8e08-7137f6e4a23c
UnknownMicrosoft Sentinel analytics
URL Click-Through by Workload

This query shows malicious URL click-throughs (where the user proceeded past the Safe Links warning) broken down by the workload the click came from.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
07e1f2f5-3662-4e8b-8f52-5273d220976b
UnknownMicrosoft Sentinel analytics
Top Clicks on Malicious URLs

This query lists the malicious URLs that registered the most user clicks, with threat type, click action and workload, using the UrlClickEvents table.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
d31069b5-44a5-4a5d-96fa-68db27074023
UnknownMicrosoft Sentinel analytics
Top 20 Malicious URLs by Clicks

This query lists the top 20 URLs carrying a detection ranked by the number of clicks registered, with the threat type, click action and workload for each.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
13e20569-a96c-48c4-b0d7-3c2058d24245
UnknownMicrosoft Sentinel analytics
Blocked URL Clicks by Workload

This query visualises blocked Safe Links URL clicks over time broken down by the workload the click came from (Email, Teams, Office, Microsoft 365 Copilot).

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
22811654-25ac-43d6-ba63-699ec29dd6af
UnknownMicrosoft Sentinel analytics
Largest Malicious Email Campaigns by Cluster

This query surfaces the largest malicious inbound email campaigns, clustered by EmailClusterId, with one row per attack wave, using the EmailEvents table.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
a92a3921-1a71-4a4d-8382-873b689ff7d8
UnknownMicrosoft Sentinel analytics
User Submissions by Submission State (FP)

This query visualises user false positive submissions by submission state.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
2f8a0226-b3f3-4a31-b32b-2dd15d644625
UnknownMicrosoft Sentinel analytics
User Submissions by Detection Method - Spam (FP)

This query visualises user false positive submissions by the original spam filter verdict on the reported message.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
05d933db-f605-48d5-a177-af64be537cf4
UnknownMicrosoft Sentinel analytics
User Submissions by Detection Method - Phish (FP)

This query visualises user false positive submissions by the original phish filter verdict on the reported message.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
4ae87c11-4030-42cb-b87d-993198ca40e0
UnknownMicrosoft Sentinel analytics
User Email Submission Trend (FP)

This query visualises the daily amount of user false positive email submissions over time.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
97f0d020-be70-4732-b5d7-abcfeecc459c
UnknownMicrosoft Sentinel analytics
User Email Submissions (FP) - Top Inbound P2 Senders

This query visualises the top 10 inbound senders of emails submitted as false positives by users.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
37511ce4-f88e-4e2d-b505-27411af1a226
UnknownMicrosoft Sentinel analytics
User Email Submissions (FP) - Top P2 Sender Domains

This query visualises the top 10 sender domains of emails submitted as false positives by users.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
97f19cad-130a-47b3-a3bb-cbc2e66845f0
UnknownMicrosoft Sentinel analytics
User Email Submissions (FP) - Top Intra-Org P2 Senders

This query visualises the top 10 intra-org senders of emails submitted as false positives by users.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
6b26701a-a1c7-4782-a662-f44cdca5bb5f

AWS GuardDuty Threat Intelligence Set Deleted

Detects the deletion of an Amazon GuardDuty threat intelligence set. Threat intelligence sets are custom lists of known-malicious IP addresses or domains that GuardDuty uses to generate findings when monitored resources communicate with those indicators. Deleting a threat intel set degrades GuardDuty's detection capability for known adversary infrastructure, allowing communication with threat-actor-controlled IP ranges to go undetected.

ATT&CK coverage

Detection requirements

Log source category
event_index

What the source says

What fires this without an attack behind it

  • Removal of an outdated or inaccurate threat intelligence set during a scheduled feed rotation may trigger this rule. Confirm the deletion corresponds to a planned feed update and that a replacement set was activated.

Tagged by the source as

Data Source: AWS CloudTrailDomain: CloudPlatform: AWSResources: Investigation GuideRule Type: Custom Query (KQL)Service: AWS GuardDutyTactic: Defense Evasion

Detection logic

Its licence does not clear it for publishing here

Detections publishes a detection’s own text only where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice