Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,217
detections

Showing 30 of 11,217

MediumSplunk security content
System User Discovery With Whoami

The following analytic detects the execution of `whoami.exe` without any arguments. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs. This activity is significant because both Red Teams and adversaries use `whoami.exe` to identify the current logged-in user, aiding in situational awareness and Active Directory discovery.

T1033
Licence
Apache License 2.0
Written by
Mauricio Velazco +1
Published
Sep 4, 2026
Upstream
894fc43e-6f50-47d5-a68b-ee9ee23e18f4
MediumSplunk security content
Network Connection Discovery With Arp

The following analytic detects the execution of `arp.exe` with the `-a` flag, which is used to list network connections on a compromised system. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, command-line executions, and related telemetry. Monitoring this activity is significant because both Red Teams and adversaries use `arp.exe` for situational awareness and Active Directory discovery.

T1049
Licence
Apache License 2.0
Written by
Mauricio Velazco +1
Published
Sep 4, 2026
Upstream
ae008c0f-83bd-4ed4-9350-98d4328e15d2
InformationalSplunk security content
Python Network Traffic During Package Build

The following analytic detects a Python process making an outbound network connection during package installation. Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.

T1059.006T1195.002
Licence
Apache License 2.0
Written by
Onur Mustafa Erdogan +1
Published
Sep 4, 2026
Upstream
03c9c504-2294-44da-8180-beefe1ca8ba8
InformationalSplunk security content
Linux Possible Append Command To Profile Config File

The following analytic detects suspicious command-lines that modify user profile files to automatically execute scripts or executables upon system reboot. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving profile files like ~/.bashrc and /etc/profile. This activity is significant as it indicates potential persistence mechanisms used by adversaries to maintain access to compromised hosts.

T1546.004
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 4, 2026
Upstream
9c94732a-61af-11ec-91e3-acde48001122
InformationalSplunk security content
Excessive Usage of NSLOOKUP App

The following analytic detects excessive usage of the nslookup application, which may indicate potential DNS exfiltration attempts. It leverages Sysmon EventCode 1 to monitor process executions, specifically focusing on nslookup.exe. The detection identifies outliers by comparing the frequency of nslookup executions against a calculated threshold. This activity is significant as it can reveal attempts by malware or APT groups to exfiltrate data via DNS queries.

T1048
Licence
Apache License 2.0
Written by
Teoderick Contreras +2
Published
Sep 4, 2026
Upstream
0a69fdaa-a2b8-11eb-b16d-acde48001122
Unknown
Anomalous AWS Console Login Without MFA from Uncommon Country

Detect unusual logon times, MFA fatigue, or service principal misuse across hybrid environments. Get visibility into geo-location of events and Threat Intelligence insights. Here''s an example of how you can easily discover Accounts authenticating without MFA and from uncommonly connected countries using UEBA behaviorAnalytics table:

T1078T1110
Licence
MIT License
Published
Sep 4, 2026
High
TacitRed - Repeat Compromise Detection

Detects users who have been compromised multiple times within a 7-day window. This may indicate a persistent threat or inadequate remediation. Ref: https://data443.com/tacitred-attack-surface-intelligence/

T1078
Licence
MIT License
Published
Sep 4, 2026
Unknown
Non-admin guest

This query searches for guest is not an admin in Azure

T1078
Licence
MIT License
Published
Sep 4, 2026
Low
Palo Alto - potential beaconing detected

Identifies beaconing patterns from PAN traffic logs based on recurrent timedelta patterns. Reference Blog:https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/detect-network-beaconing-via-intra-request-time-delta-patterns/ba-p/779586

T1071T1571
Licence
MIT License
Published
Sep 4, 2026
Medium
Palo Alto Threat signatures from Unusual IP addresses

Identifies Palo Alto Threat signatures from unusual IP addresses which are not historically seen. This detection is also leveraged and required for MDE and PAN Fusion scenario https://docs.microsoft.com/Azure/sentinel/fusion-scenario-reference#network-request-to-tor-anonymization-service-followed-by-anomalous-traffic-flagged-by-palo-alto-networks-firewall

T1030T1046T1071.001
Licence
MIT License
Published
Sep 4, 2026
Low
Palo Alto - possible internal to external port scanning

Identifies a list of internal Source IPs (10.x.x.x Hosts) that have triggered 10 or more non-graceful tcp server resets from one or more Destination IPs which results in an "ApplicationProtocol = incomplete" designation. The server resets coupled with an "Incomplete" ApplicationProtocol designation can be an indication of internal to external port scanning or probing attack. References: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUvCAK and https://knowledgebase.

T1046
Licence
MIT License
Published
Sep 4, 2026
Low
Palo Alto - potential beaconing detected

Identifies beaconing patterns from Palo Alto Network traffic logs based on recurrent timedelta patterns. The query leverages various KQL functions to calculate time deltas and then compares it with total events observed in a day to find percentage of beaconing. This outbound beaconing pattern to untrusted public networks should be investigated for any malware callbacks or data exfiltration attempts. Reference Blog: https://medium.

T1071T1571
Licence
MIT License
Published
Sep 4, 2026
High
Probable AdFind Recon Tool Usage

Identifies the host and account that executed AdFind by hash and filename in addition to common and unique flags that are used by many threat actors in discovery.

T1018
Licence
MIT License
Published
Sep 4, 2026
Medium
SUNBURST suspicious SolarWinds child processes

Identifies suspicious child processes of SolarWinds.Orion.Core.BusinessLayer.dll that may be evidence of the SUNBURST backdoor

T1059T1543
Licence
MIT License
Published
Sep 4, 2026
UnknownMicrosoft Sentinel analytics
Post Delivery Events by ZAP type

This query visualises the daily amount of emails that had a post delivery action from zero-hour auto purge, summarizing by phish,spam or malware detection action

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
dbc25434-bbe7-4517-bf4b-48ad9cb4e980
UnknownMicrosoft Sentinel analytics
Post Delivery Events by Admin

This query visualises the daily amount of emails that had an admin post delivery action, summarizing the data by action type

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
21bafecb-ae8f-4667-b7d6-144e047cb602
UnknownMicrosoft Sentinel analytics
Top 10 Users clicking on Malicious URLs (Spam)

Visualises the top 10 users with click attempts on URLs in emails detected as spam, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
3a2fdf32-ebe7-4f65-a1c3-fc7faf23ae90
UnknownMicrosoft Sentinel analytics
Top 10 Users clicking on Malicious URLs (Phish)

Visualises the top 10 users with click attempts on URLs in emails detected as phishing, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
a937905e-ee5c-406c-ab86-8e2581240112
UnknownMicrosoft Sentinel analytics
Top 10 Users clicking on Malicious URLs (Malware)

Visualises the top 10 users with click attempts on URLs in emails detected as malware, helping analysts identify risky user behaviour and potential targets. Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
5a84e13a-bb17-4124-9564-d74cdb84c124
UnknownMicrosoft Sentinel analytics
QR Code URL Detections Trend

This query visualises inbound email detections involving URLs embedded in QR codes over time, split by the threat type of the detection (phishing, malware, spam).

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
88035c0e-0e2d-4805-a249-34d54a88c3fe
UnknownMicrosoft Sentinel analytics
Phishing URL Detections Trend

This query visualises inbound email phishing detections attributed to URL-based detection technologies over time.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
4bce2a7c-31fb-46e9-8487-ce611bd98004
UnknownMicrosoft Sentinel analytics
Malware URL Detections Trend

This query visualises inbound email malware detections attributed to URL-based detection technologies over time.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
effba60e-0a4a-4558-bbf6-4e099607d82e
UnknownMicrosoft Sentinel analytics
URL Threat Protection Summary

This query summarises URL threat protection activity (Safe Links click outcomes and distinct URLs seen in email) as a set of headline metrics for the selected period.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
a0d5391b-a44c-433c-8e08-7137f6e4a23c
UnknownMicrosoft Sentinel analytics
URL Click-Through by Workload

This query shows malicious URL click-throughs (where the user proceeded past the Safe Links warning) broken down by the workload the click came from.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
07e1f2f5-3662-4e8b-8f52-5273d220976b
UnknownMicrosoft Sentinel analytics
Top Clicks on Malicious URLs

This query lists the malicious URLs that registered the most user clicks, with threat type, click action and workload, using the UrlClickEvents table.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
d31069b5-44a5-4a5d-96fa-68db27074023
UnknownMicrosoft Sentinel analytics
Top 20 Malicious URLs by Clicks

This query lists the top 20 URLs carrying a detection ranked by the number of clicks registered, with the threat type, click action and workload for each.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
13e20569-a96c-48c4-b0d7-3c2058d24245
UnknownMicrosoft Sentinel analytics
Blocked URL Clicks by Workload

This query visualises blocked Safe Links URL clicks over time broken down by the workload the click came from (Email, Teams, Office, Microsoft 365 Copilot).

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
22811654-25ac-43d6-ba63-699ec29dd6af
UnknownMicrosoft Sentinel analytics
Largest Malicious Email Campaigns by Cluster

This query surfaces the largest malicious inbound email campaigns, clustered by EmailClusterId, with one row per attack wave, using the EmailEvents table.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
a92a3921-1a71-4a4d-8382-873b689ff7d8
UnknownMicrosoft Sentinel analytics
User Submissions by Submission State (FP)

This query visualises user false positive submissions by submission state.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
2f8a0226-b3f3-4a31-b32b-2dd15d644625
UnknownMicrosoft Sentinel analytics
User Submissions by Detection Method - Spam (FP)

This query visualises user false positive submissions by the original spam filter verdict on the reported message.

T1566
Licence
MIT License
Published
Sep 4, 2026
Upstream
05d933db-f605-48d5-a177-af64be537cf4

Phish Detection IP and Geo Position

This query summarises inbound email phishing detections by sender IP address with geographic coordinates for mapping.

ATT&CK coverage

Detection requirements

Log source product
microsoftthreatprotection
Log source service
emailevents

What the source says

Tagged by the source as

InitialAccess

Detection logic

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice