Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,223
detections

Showing 30 of 11,223

InformationalSplunk security content
MacOS AppleScript Shell Execution and Compilation

The following analytic detects the use of macOS AppleScript utilities to execute shell commands or compile AppleScript containing shell-command logic. The analytic identifies `osascript` invocations using AppleScript's `do shell script` command, which executes shell commands on the host. It also identifies `osacompile` invocations referencing `do shell script`. `osacompile` compiles AppleScript into a compiled script but does not execute it directly.

T1059.002
Licence
Apache License 2.0
Written by
Radka Viskova +1
Published
Sep 6, 2026
Upstream
ceee1f2b-4b40-4721-b91e-40d1134e9dc4
InformationalSplunk security content
Cisco NVM - Browser Spawned Unix Shell with External Connection

Detects a Unix-based (Linux or macOS) browser process spawning a Unix shell that establishes an outbound connection to an external destination. This browser-to-shell execution chain may indicate malicious browser content, drive-by execution, a compromised website, or abuse of a browser extension on Linux or macOS systems. The behavior may also occur during legitimate development, installation, automation, or enterprise software workflows.

T1059
Licence
Apache License 2.0
Written by
Maria Jose Erquiaga +1
Published
Sep 6, 2026
Upstream
6f2de8d1-9a2d-4c7a-9b8c-3b8a2f7d0e41
MediumSplunk security content
Citrix ADC Exploitation CVE-2023-3519

The following analytic identifies potential exploitation attempts against Citrix ADC related to CVE-2023-3519. It detects POST requests to specific web endpoints associated with this vulnerability by leveraging the Web datamodel. This activity is significant as CVE-2023-3519 involves a SAML processing overflow issue that can lead to memory corruption, posing a high risk.

T1190
Licence
Apache License 2.0
Written by
Michael Haag +1
Published
Sep 5, 2026
Upstream
76ac2dcb-333c-4a77-8ae9-2720cfae47a8
InformationalSplunk security content
Windows Unusual SysWOW64 Process Run System32 Executable

The following analytic detects an unusual process execution pattern where a process running from C:\Windows\SysWOW64\ attempts to execute a binary from C:\Windows\System32\. In a typical Windows environment, 32-bit processes under SysWOW64 should primarily interact with 32-bit binaries within the same directory. However, an execution flow where a 32-bit process spawns a 64-bit binary from System32 can indicate potential process injection, privilege escalation, evasion techniques, or

T1036.009
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 5, 2026
Upstream
e4602172-db86-4315-86df-da66fb40bcde
MediumSplunk security content
Windows TinyCC Shellcode Execution

Detects abuse of Tiny-C-Compiler (TinyCC) for shellcode execution, where tcc.exe is renamed to masquerade as svchost.exe and used to compile and execute C source files containing shellcode. This technique was observed in the Lotus Blossom Chrysalis backdoor campaign, where attackers renamed "tcc.exe" to "svchost.exe", and executed a file named "conf.c" containing Metasploit block_api shellcode with the flags -nostdlib -run.

T1027T1036T1059.003
Licence
Apache License 2.0
Written by
Michael Haag +1
Published
Sep 5, 2026
Upstream
fdb6774e-e465-4912-86e3-63cf9ab91491
MediumSplunk security content
Windows Suspicious Process File Path

The following analytic identifies processes running from file paths not typically associated with legitimate software. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges.

T1036.005T1543
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 5, 2026
Upstream
ecddae4e-3d4b-41e2-b3df-e46a88b38521
InformationalSplunk security content
Windows Process Execution in Temp Dir

The following analytic identifies processes running from %temp% directory file paths. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges.

T1036.005T1543
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 5, 2026
Upstream
f6fbe929-4187-4ba4-901e-8a34be838443
InformationalSplunk security content
Windows Private Keys Discovery

The following analytic identifies processes that retrieve information related to private key files, often used by post-exploitation tools like winpeas. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions that search for private key certificates. This activity is significant as it indicates potential attempts to locate insecurely stored credentials, which adversaries can exploit for privilege escalation, persistence, or remote

T1552.004
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 5, 2026
Upstream
5c1c2877-06c0-40ee-a1a2-db71f1372b5b
MediumSplunk security content
Suspicious wevtutil Usage

The following analytic detects the usage of wevtutil.exe with parameters for clearing event logs such as Application, Security, Setup, Trace, or System. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.

T1685.005
Licence
Apache License 2.0
Written by
David Dorsey +4
Published
Sep 5, 2026
Upstream
2827c0fd-e1be-4868-ae25-59d28e0f9d4f
MediumSplunk security content
PowerShell 4104 Hunting

The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.

T1003T1059.001T1689
Licence
Apache License 2.0
Written by
Michael Haag +1
Published
Sep 5, 2026
Upstream
d6f2b006-0041-11ec-8885-acde48001122
InformationalSplunk security content
MacOS Data Chunking

The following analytic detects suspicious data chunking activities that involve the use of split or dd, potentially indicating an attempt to evade detection by breaking large files into smaller parts. Attackers may use this technique to bypass size-based security controls, facilitating the covert exfiltration of sensitive data. By monitoring for unusual or unauthorized use of these commands, this analytic helps identify potential data exfiltration attempts, allowing security teams to intervene

T1030
Licence
Apache License 2.0
Written by
Raven Tait +1
Published
Sep 5, 2026
Upstream
7f1c8bed-9bd4-40b0-a1df-c262cbade0fc
InformationalSplunk security content
MacOS Account Created

The following analytic detects the creation of a new local user account on a MacOS system. It leverages osquery logs to identify this activity. Monitoring the creation of local accounts is crucial for a SOC as it can indicate unauthorized access or lateral movement within the network. If confirmed malicious, this activity could allow an attacker to establish persistence, escalate privileges, or gain unauthorized access to sensitive systems and data.

T1136
Licence
Apache License 2.0
Written by
Raven Tait +1
Published
Sep 5, 2026
Upstream
491004ae-694f-453e-b1e0-fc1e65daeea1
InformationalSplunk security content
LOLBAS Rare Network Connection

The following analytic identifies public network connections initiated by Living Off the Land Binaries and Scripts (LOLBAS) that rarely require direct outbound network access. It leverages the Network Traffic data model and focuses on native Windows binaries where any public destination should be investigated and explicitly approved. This activity may indicate proxy execution, process injection, payload download, command-and-control, or other abuse of trusted binaries to evade security controls.

T1105T1218T1567
Licence
Apache License 2.0
Written by
Steven Dick +2
Published
Sep 5, 2026
Upstream
d09b66cc-269b-4675-81b5-a3dabe4f5ac2
InformationalSplunk security content
LOLBAS Network Connection On Uncommon Port

The following analytic identifies Living Off the Land Binaries and Scripts (LOLBAS) that can legitimately initiate public network connections but are communicating over uncommon destination ports. It leverages the Network Traffic data model and applies per-binary common-port exclusions to reduce false positives while preserving suspicious non-standard communication.

T1105T1218T1567
Licence
Apache License 2.0
Written by
Steven Dick +2
Published
Sep 5, 2026
Upstream
a6628e6d-be28-4278-b17d-6b5a32968eea
MediumSplunk security content
Linux Ghostscript Exploitation

The following analytic detects exploitation of Ghostscript causing command execution. This can be used by attackers to abuse file conversion services or embedded LibreOffice documents.

T1059T1068T1204.002T1566
Licence
Apache License 2.0
Written by
Raven Tait +1
Published
Sep 5, 2026
Upstream
580f99d8-a4c8-4ef1-9c84-f355867bca41
MediumSplunk security content
Linux Data Destruction Command

The following analytic detects the execution of a Unix shell command designed to wipe root directories on a Linux host. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on the 'rm' command with the '--no-preserve-root' option. This activity is significant as it indicates potential data destruction attempts, often associated with malware like Awfulshred.

T1485
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 5, 2026
Upstream
b11d3979-b2f7-411b-bb1a-bd00e642173b
MediumSplunk security content
Linux Crontab Enumeration

The following analytic detects the use of the crontab command with the list parameter (-l) to enumerate scheduled tasks configured in the invoking user's crontab on Linux systems. Adversaries may use this information to identify persistence mechanisms, scheduled execution, or potential privilege escalation opportunities. The use of crontab -l is also common administrative activity and may require tuning based on the executing user, parent process, and environment.

T1053.003
Licence
Apache License 2.0
Written by
Teoderick Contreras +3
Published
Sep 5, 2026
Upstream
8ef82980-0e95-43d7-a802-b488b668d14f
InformationalSplunk security content
Jscript Execution Using Cscript App

The following analytic detects the execution of JScript using the cscript.exe process. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry. This behavior is significant because JScript files are typically executed by wscript.exe, making cscript.exe execution unusual and potentially indicative of malicious activity, such as the FIN7 group's tactics.

T1059.007
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 5, 2026
Upstream
002f1e24-146e-11ec-a470-acde48001122
InformationalSplunk security content
Icacls Deny Command

The following analytic detects instances where an adversary modifies security permissions of a file or directory using commands like "icacls.exe", "cacls.exe", or "xcacls.exe" with deny options. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it is commonly used by Advanced Persistent Threats (APTs) and coinminer scripts to evade detection and impede access to critical files.

T1222
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 5, 2026
Upstream
cf8d753e-a8fe-11eb-8f58-acde48001122
MediumSplunk security content
File Download or Read to Pipe Execution

The following analytic detects the use of download or file reading utilities from Windows, Linux or MacOS to download or read the contents of a file from a remote or local source and pipe it directly to a shell for execution. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions. This activity is significant as it is commonly associated with malicious actions like coinminers and exploits such as CVE-2021-44228 in Log4j.

T1105
Licence
Apache License 2.0
Written by
Michael Haag +3
Published
Sep 5, 2026
Upstream
26f86252-1549-45e1-a212-eb26840e86bc
MediumSplunk security content
LOLBAS With Network Traffic

The following analytic identifies the use of Living Off the Land Binaries and Scripts (LOLBAS) with network traffic. It leverages data from the Network Traffic data model to detect when native Windows binaries, often abused by adversaries, initiate network connections. This activity is significant as LOLBAS are frequently used to download malicious payloads, enabling lateral movement, command-and-control, or data exfiltration.

T1105T1218T1567
Licence
Apache License 2.0
Written by
Steven Dick
Published
Sep 5, 2026
Upstream
2820f032-19eb-497e-8642-25b04a880359
MediumSplunk security content
Linux Adding Crontab Using List Parameter

The following analytic detects suspicious modifications to cron jobs on Linux systems using the crontab command with list parameters. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as it may indicate an attempt to establish persistence or execute malicious code on a schedule.

T1053.003
Licence
Apache License 2.0
Written by
Teoderick Contreras +2
Published
Sep 5, 2026
Upstream
52f6d751-1fd4-4c74-a4c9-777ecfeb5c58
HighElastic detection rules
Potential Entra ID PRT Extraction via BrowserCore

Identifies anomalous execution of BrowserCore.exe, the Windows component used by Chromium-based browsers for native messaging with the Web Account Manager (WAM). Adversaries abuse BrowserCore to extract Entra ID Primary Refresh Tokens (PRTs) without interactive browser context, enabling session hijacking. Legitimate BrowserCore launches carry a chrome-extension:// argument from the browser native-messaging host.

T1528T1539
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 5, 2026
Upstream
8f44478a-5b6a-4463-8a0a-3300bf3a62c9
MediumSplunk security content
System User Discovery With Whoami

The following analytic detects the execution of `whoami.exe` without any arguments. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs. This activity is significant because both Red Teams and adversaries use `whoami.exe` to identify the current logged-in user, aiding in situational awareness and Active Directory discovery.

T1033
Licence
Apache License 2.0
Written by
Mauricio Velazco +1
Published
Sep 4, 2026
Upstream
894fc43e-6f50-47d5-a68b-ee9ee23e18f4
MediumSplunk security content
Network Connection Discovery With Arp

The following analytic detects the execution of `arp.exe` with the `-a` flag, which is used to list network connections on a compromised system. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names, command-line executions, and related telemetry. Monitoring this activity is significant because both Red Teams and adversaries use `arp.exe` for situational awareness and Active Directory discovery.

T1049
Licence
Apache License 2.0
Written by
Mauricio Velazco +1
Published
Sep 4, 2026
Upstream
ae008c0f-83bd-4ed4-9350-98d4328e15d2
InformationalSplunk security content
Python Network Traffic During Package Build

The following analytic detects a Python process making an outbound network connection during package installation. Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.

T1059.006T1195.002
Licence
Apache License 2.0
Written by
Onur Mustafa Erdogan +1
Published
Sep 4, 2026
Upstream
03c9c504-2294-44da-8180-beefe1ca8ba8
InformationalSplunk security content
Linux Possible Append Command To Profile Config File

The following analytic detects suspicious command-lines that modify user profile files to automatically execute scripts or executables upon system reboot. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving profile files like ~/.bashrc and /etc/profile. This activity is significant as it indicates potential persistence mechanisms used by adversaries to maintain access to compromised hosts.

T1546.004
Licence
Apache License 2.0
Written by
Teoderick Contreras +1
Published
Sep 4, 2026
Upstream
9c94732a-61af-11ec-91e3-acde48001122
InformationalSplunk security content
Excessive Usage of NSLOOKUP App

The following analytic detects excessive usage of the nslookup application, which may indicate potential DNS exfiltration attempts. It leverages Sysmon EventCode 1 to monitor process executions, specifically focusing on nslookup.exe. The detection identifies outliers by comparing the frequency of nslookup executions against a calculated threshold. This activity is significant as it can reveal attempts by malware or APT groups to exfiltrate data via DNS queries.

T1048
Licence
Apache License 2.0
Written by
Teoderick Contreras +2
Published
Sep 4, 2026
Upstream
0a69fdaa-a2b8-11eb-b16d-acde48001122
Unknown
Anomalous AWS Console Login Without MFA from Uncommon Country

Detect unusual logon times, MFA fatigue, or service principal misuse across hybrid environments. Get visibility into geo-location of events and Threat Intelligence insights. Here''s an example of how you can easily discover Accounts authenticating without MFA and from uncommonly connected countries using UEBA behaviorAnalytics table:

T1078T1110
Licence
MIT License
Published
Sep 4, 2026
High
TacitRed - Repeat Compromise Detection

Detects users who have been compromised multiple times within a 7-day window. This may indicate a persistent threat or inadequate remediation. Ref: https://data443.com/tacitred-attack-surface-intelligence/

T1078
Licence
MIT License
Published
Sep 4, 2026

Cisco NVM - Browser Spawned Unix Shell with External Connection

Detects a Unix-based (Linux or macOS) browser process spawning a Unix shell that establishes an outbound connection to an external destination. This browser-to-shell execution chain may indicate malicious browser content, drive-by execution, a compromised website, or abuse of a browser extension on Linux or macOS systems. The behavior may also occur during legitimate development, installation, automation, or enterprise software workflows.

ATT&CK coverage

Detection requirements

What the source says

What fires this without an attack behind it

  • Legitimate workflows may launch Unix command interpreters from browser contexts, including developer tooling, software installers, SSO helpers, browser extensions, and automation wrappers. Tuning may be required for approved applications, users, and destinations.

Tagged by the source as

Cisco Network Visibility Module AnalyticsEndpointendpointSplunk CloudSplunk EnterpriseSplunk Enterprise Securityendpoint

Detection logic

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice