Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,252
- detections
Showing 30 of 11,252
The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.
- Licence
- Apache License 2.0
- Written by
- Michael Haag +1
- Published
- Sep 8, 2026
- Upstream
- d6f2b006-0041-11ec-8885-acde48001122
Identifies a match in Syslog data from any malicious URL indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 99ae4d06-d352-4926-a1d7-9c28e25b1313
Identifies a match in CommonSecurityLog data from any file-hash indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 9c2cef4e-c3a3-4be9-8923-a2f820d4face
Identifies a match in DnsEvents from any domain-name indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- c6f85aff-4ef0-4fde-b90e-e0ba1a9c3df6
This query ranks malicious inbound email campaigns by the number of URL clicks they attracted and by how many distinct users clicked, rather than by campaign size.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- af3477a3-22f8-45a3-aa01-069d40ba4bd3
This query visualises emails submitted by admins as false negatives, summarizing the data by top 10 sender domains of those emails
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- da7eecca-ecb8-4b8e-a111-62d2b48e2e69
This query check Teams IT helpdesk impersonation initial access via Teams chat and voice
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 7c4dad1a-ac02-476b-898d-192d8ef20afb
This query visualises emails released from quarantine and summarizing the result by the original filter verdict
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 23e6d66b-511a-43fd-9863-6924da60319a
This query visualises the total amount of malware emails that are quarantined, summarized by the detection method
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- c38282e0-5748-467d-95fc-4202b904dbc7
This query lists the URL domains appearing in Microsoft Teams messages that triggered a safety-tip warning, with each domain's warning rate.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- cbe5f6bc-bf97-434d-a12b-6f137a7effb1
This query lists the users who reported the most Microsoft Teams calls and messages, split by content type, to surface actively targeted people.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 2324aae0-6628-4842-aa36-ae5bf13f3400
This query ranks Microsoft Teams senders by how many of their messages were removed after delivery by zero-hour auto purge, split by malware and phish.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 2f28771a-8849-4172-a6d0-1398e902b2d7
This query looks for Teams messages from an external user with a suspicious display name.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 02bdbd93-02b7-40e4-9468-d501463e57af
This query surfaces external Microsoft Teams sender domains that carry no threat verdict yet but are sending low-reputation URLs or unusual volume.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- a0443864-5206-4030-9eb0-a70a7718dbb0
This query surfaces Microsoft Teams callers whose display name or address impersonates IT support, and calls placed from throwaway tenants.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 37f3d0f5-8ac3-46a3-9b27-a4fd082b6348
This query lists Microsoft Teams calls that users reported to Microsoft, with the reporting user, to surface suspected voice phishing.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 225da6aa-6b34-448d-ab0b-72219d52bd44
This query lists the Microsoft Teams senders whose messages most often triggered a URL safety-tip warning, with each sender's warning rate.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 23a9ae26-cede-4e3b-8cf0-0d0da7a6930a
This query groups Microsoft Teams impersonation detections by the fake display name and sender domain to expose bulk campaigns behind rotating addresses.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 7614cfa2-0fa4-446c-9f03-f0980d67ee20
This query compares all Microsoft Teams calls against impersonation-style calls across the 24 hours of the day in UTC.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 55e28f8e-cc6d-4cc9-af24-398a6e2a721d
This query trends Microsoft Teams call and message submissions over time, split by content type and by whether a user or an admin reported them.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- ef13dc37-6205-4cea-b969-2b6e0d8ab509
This query lists URL domains shared in Microsoft Teams that use top level domains commonly abused for phishing and malware, ranked by message reach.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- d917a922-45ea-46df-a186-5ecc1772644d
This query lists external Microsoft Teams senders by the date they were first seen, surfacing recent first-contact senders.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 3c9780f9-1784-48b3-b82e-d1e334c08ed2
This query ranks external Microsoft Teams sender domains by threat volume, split by conversation type, with threat rate and low-reputation URL counts.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 4f859dbb-68cf-48d3-812b-7dd19f11e495
Detects the first time an AWS identity requests a service quota increase via the AWS Service Quotas API within a 7-day history window. Service quota increases are submitted to AWS Support and, when approved, raise the limits on EC2 instances, Lambda concurrency, VPC resources, and other services. An adversary who obtains AWS credentials may request quota increases as infrastructure preparation for large-scale cryptomining, DDoS amplification, phishing campaigns, or data exfiltration operations
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 8, 2026
- Upstream
- 7e1b0654-b6c0-4b1b-ab47-75588533083c
Detects when an AWS member account is registered as a delegated administrator for an AWS service via the RegisterDelegatedAdministrator API. Delegated administrators receive service-level administrative access across the entire organization without being the management account. An attacker who compromises a principal with organizations permissions can abuse overly permissive managed policies to register a member account they control as a delegated administrator, then use that privileged access
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 8, 2026
- Upstream
- ad8ca41c-8e3d-49cd-b130-42af09d1eb42
Detects when MFA Delete is disabled on an Amazon S3 bucket. MFA Delete is an additional layer of security for versioned S3 buckets that requires multi-factor authentication to permanently delete object versions or disable versioning. When MFA Delete is disabled, an adversary with S3 write access and a compromised long-term access key can permanently delete object versions, a critical step in ransomware attacks that target S3 versioning as a backup mechanism.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 8, 2026
- Upstream
- b8654454-2757-41b4-ae1a-69b3be704c28
Detects enumeration of Amazon Simple Email Service (SES) resources using long-term IAM access keys (AKIA* prefix). Long-term access keys are associated with IAM users and are the credential type most commonly exfiltrated from repositories, configuration files, and environment variables. An adversary who obtains a long-term key may enumerate SES to discover verified email identities, sending quotas, and DKIM/MAIL FROM domain configurations as a precursor to phishing or spam campaigns launched
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 8, 2026
- Upstream
- 8d05971b-5858-4b72-b09a-17e3cee0af54
Detects enumeration of AWS Backup resources using long-term IAM access keys (AKIA* prefix). AWS Backup protects EC2 instances, EBS volumes, RDS databases, DynamoDB tables, EFS file systems, and S3 buckets. An adversary who obtains long-term access keys may enumerate backup vaults, backup plans, and protected resources as a precursor to ransomware.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 8, 2026
- Upstream
- e71ae602-bf44-4834-a4ea-b5c87047d426
The following analytic detects shells, scripting engines, and common post-exploitation utilities spawned as child processes of smsexec.exe. smsexec.exe is the core SCCM SMS Executive service process and has no legitimate reason to launch interactive shells or scripting interpreters. An attacker who plants a malicious adsource.dll in the SCCMProvider bin\X64 directory will obtain code execution in the SCCM service context, typically resulting in a SYSTEM-level child process being spawned under
- Licence
- Apache License 2.0
- Written by
- Raven Tait +1
- Published
- Sep 7, 2026
- Upstream
- 72091a05-3008-4330-b43e-f5e070134ec1
The following analytic detects the creation or modification of adsource.dll or other staging files with the name adsource_*.dll within the SCCM SMS Provider bin directory, consistent with exploitation of CVE-2026-47301. This abuses a DLL side-loading vulnerability in the Microsoft Configuration Manager SMS Provider component. An attacker can plant a malicious adsource.
- Licence
- Apache License 2.0
- Written by
- Raven Tait +1
- Published
- Sep 7, 2026
- Upstream
- 4f55b07b-7aeb-47f4-a234-b222a902276b
Top Reporters of Microsoft Teams Calls and Messages
This query lists the users who reported the most Microsoft Teams calls and messages, split by content type, to surface actively targeted people.
ATT&CK coverage
Detection requirements
- Log source product
- microsoftthreatprotection
- Log source service
- cloudappevents