Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,221
- detections
Showing 30 of 11,221
The following analytic identifies potential exploitation attempts against Citrix ADC related to CVE-2023-3519. It detects POST requests to specific web endpoints associated with this vulnerability by leveraging the Web datamodel. This activity is significant as CVE-2023-3519 involves a SAML processing overflow issue that can lead to memory corruption, posing a high risk.
- Licence
- Apache License 2.0
- Written by
- Michael Haag +1
- Published
- Sep 5, 2026
- Upstream
- 76ac2dcb-333c-4a77-8ae9-2720cfae47a8
The following analytic detects an unusual process execution pattern where a process running from C:\Windows\SysWOW64\ attempts to execute a binary from C:\Windows\System32\. In a typical Windows environment, 32-bit processes under SysWOW64 should primarily interact with 32-bit binaries within the same directory. However, an execution flow where a 32-bit process spawns a 64-bit binary from System32 can indicate potential process injection, privilege escalation, evasion techniques, or
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 5, 2026
- Upstream
- e4602172-db86-4315-86df-da66fb40bcde
Detects abuse of Tiny-C-Compiler (TinyCC) for shellcode execution, where tcc.exe is renamed to masquerade as svchost.exe and used to compile and execute C source files containing shellcode. This technique was observed in the Lotus Blossom Chrysalis backdoor campaign, where attackers renamed "tcc.exe" to "svchost.exe", and executed a file named "conf.c" containing Metasploit block_api shellcode with the flags -nostdlib -run.
- Licence
- Apache License 2.0
- Written by
- Michael Haag +1
- Published
- Sep 5, 2026
- Upstream
- fdb6774e-e465-4912-86e3-63cf9ab91491
The following analytic identifies processes running from file paths not typically associated with legitimate software. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 5, 2026
- Upstream
- ecddae4e-3d4b-41e2-b3df-e46a88b38521
The following analytic identifies processes running from %temp% directory file paths. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 5, 2026
- Upstream
- f6fbe929-4187-4ba4-901e-8a34be838443
The following analytic identifies processes that retrieve information related to private key files, often used by post-exploitation tools like winpeas. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions that search for private key certificates. This activity is significant as it indicates potential attempts to locate insecurely stored credentials, which adversaries can exploit for privilege escalation, persistence, or remote
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 5, 2026
- Upstream
- 5c1c2877-06c0-40ee-a1a2-db71f1372b5b
The following analytic detects the usage of wevtutil.exe with parameters for clearing event logs such as Application, Security, Setup, Trace, or System. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
- Licence
- Apache License 2.0
- Written by
- David Dorsey +4
- Published
- Sep 5, 2026
- Upstream
- 2827c0fd-e1be-4868-ae25-59d28e0f9d4f
The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.
- Licence
- Apache License 2.0
- Written by
- Michael Haag +1
- Published
- Sep 5, 2026
- Upstream
- d6f2b006-0041-11ec-8885-acde48001122
The following analytic detects suspicious data chunking activities that involve the use of split or dd, potentially indicating an attempt to evade detection by breaking large files into smaller parts. Attackers may use this technique to bypass size-based security controls, facilitating the covert exfiltration of sensitive data. By monitoring for unusual or unauthorized use of these commands, this analytic helps identify potential data exfiltration attempts, allowing security teams to intervene
- Licence
- Apache License 2.0
- Written by
- Raven Tait +1
- Published
- Sep 5, 2026
- Upstream
- 7f1c8bed-9bd4-40b0-a1df-c262cbade0fc
The following analytic detects the creation of a new local user account on a MacOS system. It leverages osquery logs to identify this activity. Monitoring the creation of local accounts is crucial for a SOC as it can indicate unauthorized access or lateral movement within the network. If confirmed malicious, this activity could allow an attacker to establish persistence, escalate privileges, or gain unauthorized access to sensitive systems and data.
- Licence
- Apache License 2.0
- Written by
- Raven Tait +1
- Published
- Sep 5, 2026
- Upstream
- 491004ae-694f-453e-b1e0-fc1e65daeea1
The following analytic identifies public network connections initiated by Living Off the Land Binaries and Scripts (LOLBAS) that rarely require direct outbound network access. It leverages the Network Traffic data model and focuses on native Windows binaries where any public destination should be investigated and explicitly approved. This activity may indicate proxy execution, process injection, payload download, command-and-control, or other abuse of trusted binaries to evade security controls.
- Licence
- Apache License 2.0
- Written by
- Steven Dick +2
- Published
- Sep 5, 2026
- Upstream
- d09b66cc-269b-4675-81b5-a3dabe4f5ac2
The following analytic identifies Living Off the Land Binaries and Scripts (LOLBAS) that can legitimately initiate public network connections but are communicating over uncommon destination ports. It leverages the Network Traffic data model and applies per-binary common-port exclusions to reduce false positives while preserving suspicious non-standard communication.
- Licence
- Apache License 2.0
- Written by
- Steven Dick +2
- Published
- Sep 5, 2026
- Upstream
- a6628e6d-be28-4278-b17d-6b5a32968eea
The following analytic detects exploitation of Ghostscript causing command execution. This can be used by attackers to abuse file conversion services or embedded LibreOffice documents.
- Licence
- Apache License 2.0
- Written by
- Raven Tait +1
- Published
- Sep 5, 2026
- Upstream
- 580f99d8-a4c8-4ef1-9c84-f355867bca41
The following analytic detects the execution of a Unix shell command designed to wipe root directories on a Linux host. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on the 'rm' command with the '--no-preserve-root' option. This activity is significant as it indicates potential data destruction attempts, often associated with malware like Awfulshred.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 5, 2026
- Upstream
- b11d3979-b2f7-411b-bb1a-bd00e642173b
The following analytic detects the use of the crontab command with the list parameter (-l) to enumerate scheduled tasks configured in the invoking user's crontab on Linux systems. Adversaries may use this information to identify persistence mechanisms, scheduled execution, or potential privilege escalation opportunities. The use of crontab -l is also common administrative activity and may require tuning based on the executing user, parent process, and environment.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +3
- Published
- Sep 5, 2026
- Upstream
- 8ef82980-0e95-43d7-a802-b488b668d14f
The following analytic detects the execution of JScript using the cscript.exe process. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry. This behavior is significant because JScript files are typically executed by wscript.exe, making cscript.exe execution unusual and potentially indicative of malicious activity, such as the FIN7 group's tactics.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 5, 2026
- Upstream
- 002f1e24-146e-11ec-a470-acde48001122
The following analytic detects instances where an adversary modifies security permissions of a file or directory using commands like "icacls.exe", "cacls.exe", or "xcacls.exe" with deny options. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it is commonly used by Advanced Persistent Threats (APTs) and coinminer scripts to evade detection and impede access to critical files.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 5, 2026
- Upstream
- cf8d753e-a8fe-11eb-8f58-acde48001122
The following analytic detects the use of download or file reading utilities from Windows, Linux or MacOS to download or read the contents of a file from a remote or local source and pipe it directly to a shell for execution. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions. This activity is significant as it is commonly associated with malicious actions like coinminers and exploits such as CVE-2021-44228 in Log4j.
- Licence
- Apache License 2.0
- Written by
- Michael Haag +3
- Published
- Sep 5, 2026
- Upstream
- 26f86252-1549-45e1-a212-eb26840e86bc
The following analytic identifies the use of Living Off the Land Binaries and Scripts (LOLBAS) with network traffic. It leverages data from the Network Traffic data model to detect when native Windows binaries, often abused by adversaries, initiate network connections. This activity is significant as LOLBAS are frequently used to download malicious payloads, enabling lateral movement, command-and-control, or data exfiltration.
- Licence
- Apache License 2.0
- Written by
- Steven Dick
- Published
- Sep 5, 2026
- Upstream
- 2820f032-19eb-497e-8642-25b04a880359
The following analytic detects suspicious modifications to cron jobs on Linux systems using the crontab command with list parameters. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it may indicate an attempt to establish persistence or execute malicious code on a schedule.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +2
- Published
- Sep 5, 2026
- Upstream
- 52f6d751-1fd4-4c74-a4c9-777ecfeb5c58
Identifies anomalous execution of BrowserCore.exe, the Windows component used by Chromium-based browsers for native messaging with the Web Account Manager (WAM). Adversaries abuse BrowserCore to extract Entra ID Primary Refresh Tokens (PRTs) without interactive browser context, enabling session hijacking. Legitimate BrowserCore launches carry a chrome-extension:// argument from the browser native-messaging host.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 5, 2026
- Upstream
- 8f44478a-5b6a-4463-8a0a-3300bf3a62c9
The following analytic detects the execution of `whoami.exe` without any arguments. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs. This activity is significant because both Red Teams and adversaries use `whoami.exe` to identify the current logged-in user, aiding in situational awareness and Active Directory discovery.
- Licence
- Apache License 2.0
- Written by
- Mauricio Velazco +1
- Published
- Sep 4, 2026
- Upstream
- 894fc43e-6f50-47d5-a68b-ee9ee23e18f4
The following analytic detects the execution of `arp.exe` with the `-a` flag, which is used to list network connections on a compromised system. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, command-line executions, and related telemetry. Monitoring this activity is significant because both Red Teams and adversaries use `arp.exe` for situational awareness and Active Directory discovery.
- Licence
- Apache License 2.0
- Written by
- Mauricio Velazco +1
- Published
- Sep 4, 2026
- Upstream
- ae008c0f-83bd-4ed4-9350-98d4328e15d2
The following analytic detects a Python process making an outbound network connection during package installation. Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.
- Licence
- Apache License 2.0
- Written by
- Onur Mustafa Erdogan +1
- Published
- Sep 4, 2026
- Upstream
- 03c9c504-2294-44da-8180-beefe1ca8ba8
The following analytic detects suspicious command-lines that modify user profile files to automatically execute scripts or executables upon system reboot. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving profile files like ~/.bashrc and /etc/profile. This activity is significant as it indicates potential persistence mechanisms used by adversaries to maintain access to compromised hosts.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +1
- Published
- Sep 4, 2026
- Upstream
- 9c94732a-61af-11ec-91e3-acde48001122
The following analytic detects excessive usage of the nslookup application, which may indicate potential DNS exfiltration attempts. It leverages Sysmon EventCode 1 to monitor process executions, specifically focusing on nslookup.exe. The detection identifies outliers by comparing the frequency of nslookup executions against a calculated threshold. This activity is significant as it can reveal attempts by malware or APT groups to exfiltrate data via DNS queries.
- Licence
- Apache License 2.0
- Written by
- Teoderick Contreras +2
- Published
- Sep 4, 2026
- Upstream
- 0a69fdaa-a2b8-11eb-b16d-acde48001122
Detect unusual logon times, MFA fatigue, or service principal misuse across hybrid environments. Get visibility into geo-location of events and Threat Intelligence insights. Here''s an example of how you can easily discover Accounts authenticating without MFA and from uncommonly connected countries using UEBA behaviorAnalytics table:
- Licence
- MIT License
- Published
- Sep 4, 2026
Detects users who have been compromised multiple times within a 7-day window. This may indicate a persistent threat or inadequate remediation. Ref: https://data443.com/tacitred-attack-surface-intelligence/
- Licence
- MIT License
- Published
- Sep 4, 2026
This query searches for guest is not an admin in Azure
- Licence
- MIT License
- Published
- Sep 4, 2026
Identifies beaconing patterns from PAN traffic logs based on recurrent timedelta patterns. Reference Blog:https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/detect-network-beaconing-via-intra-request-time-delta-patterns/ba-p/779586
- Licence
- MIT License
- Published
- Sep 4, 2026
Linux Crontab Enumeration
The following analytic detects the use of the crontab command with the list parameter (-l) to enumerate scheduled tasks configured in the invoking user's crontab on Linux systems. Adversaries may use this information to identify persistence mechanisms, scheduled execution, or potential privilege escalation opportunities. The use of crontab -l is also common administrative activity and may require tuning based on the executing user, parent process, and environment.
ATT&CK coverage
Detection requirements
- Log source category
- cisco_isovalent_process_execsysmon_for_linux_eventid_1
What the source says
What fires this without an attack behind it
- Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.