Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,217
- detections
Showing 30 of 11,217
The following analytic detects the execution of `whoami.exe` without any arguments. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs. This activity is significant because both Red Teams and adversaries use `whoami.exe` to identify the current logged-in user, aiding in situational awareness and Active Directory discovery.
- Licence
- Apache License 2.0
- Written by
- Mauricio Velazco +1
- Published
- Sep 4, 2026
- Upstream
- 894fc43e-6f50-47d5-a68b-ee9ee23e18f4
The following analytic detects the execution of `arp.exe` with the `-a` flag, which is used to list network connections on a compromised system. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, command-line executions, and related telemetry. Monitoring this activity is significant because both Red Teams and adversaries use `arp.exe` for situational awareness and Active Directory discovery.
- Licence
- Apache License 2.0
- Written by
- Mauricio Velazco +1
- Published
- Sep 4, 2026
- Upstream
- ae008c0f-83bd-4ed4-9350-98d4328e15d2
The following analytic detects a Python process making an outbound network connection during package installation. Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.
- Licence
- Apache License 2.0
- Written by
- Onur Mustafa Erdogan +1
- Published
- Sep 4, 2026
- Upstream
- 03c9c504-2294-44da-8180-beefe1ca8ba8
The following analytic detects suspicious command-lines that modify user profile files to automatically execute scripts or executables upon system reboot. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving profile files like ~/.bashrc and /etc/profile. This activity is significant as it indicates potential persistence mechanisms used by adversaries to maintain access to compromised hosts.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 4, 2026
- Upstream
- 9c94732a-61af-11ec-91e3-acde48001122
The following analytic detects excessive usage of the nslookup application, which may indicate potential DNS exfiltration attempts. It leverages Sysmon EventCode 1 to monitor process executions, specifically focusing on nslookup.exe. The detection identifies outliers by comparing the frequency of nslookup executions against a calculated threshold. This activity is significant as it can reveal attempts by malware or APT groups to exfiltrate data via DNS queries.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +2
- Published
- Sep 4, 2026
- Upstream
- 0a69fdaa-a2b8-11eb-b16d-acde48001122
Detect unusual logon times, MFA fatigue, or service principal misuse across hybrid environments. Get visibility into geo-location of events and Threat Intelligence insights. Here''s an example of how you can easily discover Accounts authenticating without MFA and from uncommonly connected countries using UEBA behaviorAnalytics table:
- Licence
- MIT License
- Published
- Sep 4, 2026
Detects users who have been compromised multiple times within a 7-day window. This may indicate a persistent threat or inadequate remediation. Ref: https://data443.com/tacitred-attack-surface-intelligence/
- Licence
- MIT License
- Published
- Sep 4, 2026
This query searches for guest is not an admin in Azure
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies beaconing patterns from PAN traffic logs based on recurrent timedelta patterns. Reference Blog:https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/detect-network-beaconing-via-intra-request-time-delta-patterns/ba-p/779586
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies Palo Alto Threat signatures from unusual IP addresses which are not historically seen. This detection is also leveraged and required for MDE and PAN Fusion scenario https://docs.microsoft.com/Azure/sentinel/fusion-scenario-reference#network-request-to-tor-anonymization-service-followed-by-anomalous-traffic-flagged-by-palo-alto-networks-firewall
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies a list of internal Source IPs (10.x.x.x Hosts) that have triggered 10 or more non-graceful tcp server resets from one or more Destination IPs which results in an "ApplicationProtocol = incomplete" designation. The server resets coupled with an "Incomplete" ApplicationProtocol designation can be an indication of internal to external port scanning or probing attack. References: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUvCAK and https://knowledgebase.
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies beaconing patterns from Palo Alto Network traffic logs based on recurrent timedelta patterns. The query leverages various KQL functions to calculate time deltas and then compares it with total events observed in a day to find percentage of beaconing. This outbound beaconing pattern to untrusted public networks should be investigated for any malware callbacks or data exfiltration attempts. Reference Blog: https://medium.
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies the host and account that executed AdFind by hash and filename in addition to common and unique flags that are used by many threat actors in discovery.
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies suspicious child processes of SolarWinds.Orion.Core.BusinessLayer.dll that may be evidence of the SUNBURST backdoor
- Licence
- MIT License
- Published
- Sep 4, 2026
This query visualises the daily amount of emails that had a post delivery action from zero-hour auto purge, summarizing by phish,spam or malware detection action
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- dbc25434-bbe7-4517-bf4b-48ad9cb4e980
This query visualises the daily amount of emails that had an admin post delivery action, summarizing the data by action type
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 21bafecb-ae8f-4667-b7d6-144e047cb602
Visualises the top 10 users with click attempts on URLs in emails detected as spam, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 3a2fdf32-ebe7-4f65-a1c3-fc7faf23ae90
Visualises the top 10 users with click attempts on URLs in emails detected as phishing, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- a937905e-ee5c-406c-ab86-8e2581240112
Visualises the top 10 users with click attempts on URLs in emails detected as malware, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 5a84e13a-bb17-4124-9564-d74cdb84c124
This query visualises inbound email detections involving URLs embedded in QR codes over time, split by the threat type of the detection (phishing, malware, spam).
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 88035c0e-0e2d-4805-a249-34d54a88c3fe
This query visualises inbound email phishing detections attributed to URL-based detection technologies over time.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 4bce2a7c-31fb-46e9-8487-ce611bd98004
This query visualises inbound email malware detections attributed to URL-based detection technologies over time.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- effba60e-0a4a-4558-bbf6-4e099607d82e
This query summarises URL threat protection activity (Safe Links click outcomes and distinct URLs seen in email) as a set of headline metrics for the selected period.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- a0d5391b-a44c-433c-8e08-7137f6e4a23c
This query shows malicious URL click-throughs (where the user proceeded past the Safe Links warning) broken down by the workload the click came from.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 07e1f2f5-3662-4e8b-8f52-5273d220976b
This query lists the malicious URLs that registered the most user clicks, with threat type, click action and workload, using the UrlClickEvents table.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- d31069b5-44a5-4a5d-96fa-68db27074023
This query lists the top 20 URLs carrying a detection ranked by the number of clicks registered, with the threat type, click action and workload for each.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 13e20569-a96c-48c4-b0d7-3c2058d24245
This query visualises blocked Safe Links URL clicks over time broken down by the workload the click came from (Email, Teams, Office, Microsoft 365 Copilot).
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 22811654-25ac-43d6-ba63-699ec29dd6af
This query surfaces the largest malicious inbound email campaigns, clustered by EmailClusterId, with one row per attack wave, using the EmailEvents table.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- a92a3921-1a71-4a4d-8382-873b689ff7d8
This query visualises user false positive submissions by submission state.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 2f8a0226-b3f3-4a31-b32b-2dd15d644625
This query visualises user false positive submissions by the original spam filter verdict on the reported message.
- Licence
- MIT License
- Published
- Sep 4, 2026
- Upstream
- 05d933db-f605-48d5-a177-af64be537cf4
First-Contact External Email Senders
This query lists external email senders seen for the first time in the period (most recent first), surfacing new first-contact relationships, using the EmailEvents table.
ATT&CK coverage
Detection requirements
- Log source product
- microsoftthreatprotection
- Log source service
- emailevents