Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 10,962
- detections
Showing 30 of 10,962
Detects when SMB traffic crosses Production and Non-Production Realms. Possible network share discovery or lateral tool transfer across realms
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- a36de6c3-3198-4d37-92ae-e19e36712c2e
Identifies web traffic where the iboss platform flagged malware. A populated MalwareDetected flag indicates the gateway detected a malicious file or payload associated with the request. Surfaces the destination, user, and other details to support triage.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- cad35734-b97a-4209-9269-b98c916379eb
Identifies web traffic where the iboss platform flagged command-and-control (C2) activity. A populated CNCDetected flag indicates the gateway observed communication to a known or suspected C2 destination. Surfaces the user, destination URL, and host to support triage of potentially compromised endpoints.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 40cf9670-d4be-4149-9082-5809a2b12ca1
Detects repeated use of the same OAuth token across different IPs or locations over time. This can indicate token theft or session abuse.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 67802748-435b-4f80-9f61-b9a9ac6ea15c
Detects when a privileged role is assigned to a new user account. This can indicate unauthorized elevation of privileges.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- b64ac0e2-a241-4b9a-ad3e-ae572630b295
Detects when a user is assigned a privileged role in Microsoft Entra ID. This may indicate unauthorized privilege escalation and should be validated promptly.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- fad0f8b9-a0a5-430a-9a94-049a1144bf54
Detects denied privilege elevation requests in Microsoft Entra ID. Review the requester and the target workflow for possible abuse or misconfiguration.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- aceee46e-8fb3-42d9-967a-aac637bcefd4
Detects multiple privileged role changes occurring around the same time. This may signal bulk abuse or administrative misconfiguration.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- d6cd3c6f-1d2a-4c42-a048-dbe91cf35b18
Detects changes to domain federation trust settings or domain authentication mode. These changes can be used to redirect sign-in trust and should be reviewed immediately.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 944d0ab5-b654-47f9-a398-2e77a0b7906e
Detects changes to authentication methods on privileged accounts. This may indicate an attacker added a new method to maintain access.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 9f7197b6-eeb2-46f3-83b1-a2c4dfca46a0
Detects when an application receives permission to assign Microsoft Entra ID roles. This can enable directory privilege escalation and should be reviewed immediately.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- ef34b272-930c-41c8-a682-8c2093cd2024
Detects an application receiving administrator permissions and then using them to assign a role. This pattern can indicate rapid privilege escalation through app consent abuse.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 90bacdf4-e35b-47cb-92d1-29d8397eb4a0
Detects Azure VM Run Command execution correlated with unusual sign-in behavior from UEBA. This can indicate administrative abuse or post-compromise activity.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 6fa564ac-dfb7-4753-a49b-5fc919866c28
Query shows server error by user.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 22545900-422d-11ec-81d3-0242ac130003
Query shows users access groups.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 018e11f4-4627-11ec-81d3-0242ac130003
Query shows rare urlhostname requests.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- d311eb1e-4231-11ec-81d3-0242ac130003
Query shows top source IP.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- baf67720-4623-11ec-81d3-0242ac130003
Query shows top connectors.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 26d5244a-462f-11ec-81d3-0242ac130003
Query shows Users by source location countries.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- bf8ce3e8-422a-11ec-81d3-0242ac130003
Query shows destination ports by IP address.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 20733e72-4231-11ec-81d3-0242ac130003
Query shows connection close reasons.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 5467efc0-422c-11ec-81d3-0242ac130003
Query shows applications using by accounts.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 6ae7b9e0-462a-11ec-81d3-0242ac130003
Query shows abnormal total bytes size.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 181dc982-4631-11ec-81d3-0242ac130003
Detects Unexpected ZPA session duration.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- e07846e0-43ad-11ec-81d3-0242ac130003
Detects ZAP connections outside operational hours.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 2859ad22-46c8-4cc7-ad7b-80ce0cba0af3
Detects ZPA connections from new IP.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 24f0779d-3927-403a-aac1-cc8791653606
Detects ZPA connections from new country.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- c4902121-7a7e-44d1-810b-88d26db622ff
Detects ZPA connections by new user.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 236a7ec1-0120-40f2-a157-c1a72dde8bcb
Detects ZPA connections by dormant user.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 66bc77ee-3e45-11ec-9bbc-0242ac130002
Detects unexpected version of update operation.
- Licence
- MIT License
- Published
- Sep 1, 2026
- Upstream
- 672e2846-4226-11ec-81d3-0242ac130003