Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

10,962
detections

Showing 30 of 10,962

MediumMicrosoft Sentinel analytics
vArmour AppController - SMB Realm Traversal

Detects when SMB traffic crosses Production and Non-Production Realms. Possible network share discovery or lateral tool transfer across realms

T1135T1570
Licence
MIT License
Published
Sep 1, 2026
Upstream
a36de6c3-3198-4d37-92ae-e19e36712c2e
HighMicrosoft Sentinel analytics
iboss - Malware Detected

Identifies web traffic where the iboss platform flagged malware. A populated MalwareDetected flag indicates the gateway detected a malicious file or payload associated with the request. Surfaces the destination, user, and other details to support triage.

T1204
Licence
MIT License
Published
Sep 1, 2026
Upstream
cad35734-b97a-4209-9269-b98c916379eb
HighMicrosoft Sentinel analytics
iboss - Command-and-Control Detected

Identifies web traffic where the iboss platform flagged command-and-control (C2) activity. A populated CNCDetected flag indicates the gateway observed communication to a known or suspected C2 destination. Surfaces the user, destination URL, and host to support triage of potentially compromised endpoints.

T1071
Licence
MIT License
Published
Sep 1, 2026
Upstream
40cf9670-d4be-4149-9082-5809a2b12ca1
HighMicrosoft Sentinel analytics
[Entra ID] Suspicious Continuous OAuth Token Usage

Detects repeated use of the same OAuth token across different IPs or locations over time. This can indicate token theft or session abuse.

T1606
Licence
MIT License
Published
Sep 1, 2026
Upstream
67802748-435b-4f80-9f61-b9a9ac6ea15c
HighMicrosoft Sentinel analytics
[Entra ID] Privileged Role Assigned to a New User

Detects when a privileged role is assigned to a new user account. This can indicate unauthorized elevation of privileges.

T1078.004
Licence
MIT License
Published
Sep 1, 2026
Upstream
b64ac0e2-a241-4b9a-ad3e-ae572630b295
HighMicrosoft Sentinel analytics
[Entra ID] Privileged Role Assigned to User

Detects when a user is assigned a privileged role in Microsoft Entra ID. This may indicate unauthorized privilege escalation and should be validated promptly.

T1078.004
Licence
MIT License
Published
Sep 1, 2026
Upstream
fad0f8b9-a0a5-430a-9a94-049a1144bf54
HighMicrosoft Sentinel analytics
[Entra ID] Privilege Elevation Request Denied

Detects denied privilege elevation requests in Microsoft Entra ID. Review the requester and the target workflow for possible abuse or misconfiguration.

T1078.004
Licence
MIT License
Published
Sep 1, 2026
Upstream
aceee46e-8fb3-42d9-967a-aac637bcefd4
HighMicrosoft Sentinel analytics
[Entra ID] Mass Privileged Role Change Activity Detected

Detects multiple privileged role changes occurring around the same time. This may signal bulk abuse or administrative misconfiguration.

T1078
Licence
MIT License
Published
Sep 1, 2026
Upstream
d6cd3c6f-1d2a-4c42-a048-dbe91cf35b18
HighMicrosoft Sentinel analytics
[Entra ID] Domain Federation Trust Settings Modified

Detects changes to domain federation trust settings or domain authentication mode. These changes can be used to redirect sign-in trust and should be reviewed immediately.

T1098T1555
Licence
MIT License
Published
Sep 1, 2026
Upstream
944d0ab5-b654-47f9-a398-2e77a0b7906e
HighMicrosoft Sentinel analytics
[Entra ID] Authentication Method Changed for Privileged Account

Detects changes to authentication methods on privileged accounts. This may indicate an attacker added a new method to maintain access.

T1098
Licence
MIT License
Published
Sep 1, 2026
Upstream
9f7197b6-eeb2-46f3-83b1-a2c4dfca46a0
HighMicrosoft Sentinel analytics
[Entra ID] Application Granted Administrative Permission to Assign Microsoft Entra ID Roles

Detects when an application receives permission to assign Microsoft Entra ID roles. This can enable directory privilege escalation and should be reviewed immediately.

T1098.003
Licence
MIT License
Published
Sep 1, 2026
Upstream
ef34b272-930c-41c8-a682-8c2093cd2024
HighMicrosoft Sentinel analytics
[Entra ID] Application Assigned Administrator Permissions Immediately After Obtaining Role Management Permissions

Detects an application receiving administrator permissions and then using them to assign a role. This pattern can indicate rapid privilege escalation through app consent abuse.

T1078.004T1098.003
Licence
MIT License
Published
Sep 1, 2026
Upstream
90bacdf4-e35b-47cb-92d1-29d8397eb4a0
HighMicrosoft Sentinel analytics
[AzureSubscription] Suspicious Azure VM Run Command Execution Detected

Detects Azure VM Run Command execution correlated with unusual sign-in behavior from UEBA. This can indicate administrative abuse or post-compromise activity.

T1212T1570
Licence
MIT License
Published
Sep 1, 2026
Upstream
6fa564ac-dfb7-4753-a49b-5fc919866c28
LowMicrosoft Sentinel analytics
Zscaler - Server error by user

Query shows server error by user.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
22545900-422d-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Users access groups

Query shows users access groups.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
018e11f4-4627-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Rare urlhostname requests

Query shows rare urlhostname requests.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
d311eb1e-4231-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Top source IP

Query shows top source IP.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
baf67720-4623-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Top connectors

Query shows top connectors.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
26d5244a-462f-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Users by source location countries

Query shows Users by source location countries.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
bf8ce3e8-422a-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Destination ports by IP

Query shows destination ports by IP address.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
20733e72-4231-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Connection close reasons

Query shows connection close reasons.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
5467efc0-422c-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Applications using by accounts

Query shows applications using by accounts.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
6ae7b9e0-462a-11ec-81d3-0242ac130003
LowMicrosoft Sentinel analytics
Zscaler - Abnormal total bytes size

Query shows abnormal total bytes size.

T1530T1537
Licence
MIT License
Published
Sep 1, 2026
Upstream
181dc982-4631-11ec-81d3-0242ac130003
MediumMicrosoft Sentinel analytics
Zscaler - Unexpected ZPA session duration

Detects Unexpected ZPA session duration.

T1078T1133
Licence
MIT License
Published
Sep 1, 2026
Upstream
e07846e0-43ad-11ec-81d3-0242ac130003
MediumMicrosoft Sentinel analytics
Zscaler - ZPA connections outside operational hours

Detects ZAP connections outside operational hours.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
2859ad22-46c8-4cc7-ad7b-80ce0cba0af3
MediumMicrosoft Sentinel analytics
Zscaler - ZPA connections from new IP

Detects ZPA connections from new IP.

T1078T1133
Licence
MIT License
Published
Sep 1, 2026
Upstream
24f0779d-3927-403a-aac1-cc8791653606
MediumMicrosoft Sentinel analytics
Zscaler - ZPA connections from new country

Detects ZPA connections from new country.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
c4902121-7a7e-44d1-810b-88d26db622ff
MediumMicrosoft Sentinel analytics
Zscaler - ZPA connections by new user

Detects ZPA connections by new user.

T1078
Licence
MIT License
Published
Sep 1, 2026
Upstream
236a7ec1-0120-40f2-a157-c1a72dde8bcb
HighMicrosoft Sentinel analytics
Zscaler - Connections by dormant user

Detects ZPA connections by dormant user.

T1078
Licence
MIT License
Published
Sep 1, 2026
Upstream
66bc77ee-3e45-11ec-9bbc-0242ac130002
MediumMicrosoft Sentinel analytics
Zscaler - Unexpected update operation

Detects unexpected version of update operation.

T1133T1190
Licence
MIT License
Published
Sep 1, 2026
Upstream
672e2846-4226-11ec-81d3-0242ac130003
Loading detections

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice

Service principal not using client credentials · Sunturai