Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,252
detections

Showing 30 of 11,252

MediumSplunk security content
PowerShell 4104 Hunting

The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.

T1003T1059.001T1689
Licence
Apache License 2.0
Written by
Michael Haag +1
Published
Sep 8, 2026
Upstream
d6f2b006-0041-11ec-8885-acde48001122
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map URL to Syslog

Identifies a match in Syslog data from any malicious URL indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
99ae4d06-d352-4926-a1d7-9c28e25b1313
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map File Hash to CommonSecurityLog

Identifies a match in CommonSecurityLog data from any file-hash indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
9c2cef4e-c3a3-4be9-8923-a2f820d4face
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map Domain to DnsEvents

Identifies a match in DnsEvents from any domain-name indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
c6f85aff-4ef0-4fde-b90e-e0ba1a9c3df6
UnknownMicrosoft Sentinel analytics
Malicious Email Campaigns by Recipient URL Clicks

This query ranks malicious inbound email campaigns by the number of URL clicks they attracted and by how many distinct users clicked, rather than by campaign size.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
af3477a3-22f8-45a3-aa01-069d40ba4bd3
UnknownMicrosoft Sentinel analytics
Top 10 sender domains - Admin email submissions (FN)

This query visualises emails submitted by admins as false negatives, summarizing the data by top 10 sender domains of those emails

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
da7eecca-ecb8-4b8e-a111-62d2b48e2e69
UnknownMicrosoft Sentinel analytics
Detect Teams IT Helpdesk Impersonation Msg Phishing & Vishing

This query check Teams IT helpdesk impersonation initial access via Teams chat and voice

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
7c4dad1a-ac02-476b-898d-192d8ef20afb
UnknownMicrosoft Sentinel analytics
Quarantine releases by Detection Types

This query visualises emails released from quarantine and summarizing the result by the original filter verdict

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
23e6d66b-511a-43fd-9863-6924da60319a
UnknownMicrosoft Sentinel analytics
Quarantine Malware Reason

This query visualises the total amount of malware emails that are quarantined, summarized by the detection method

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
c38282e0-5748-467d-95fc-4202b904dbc7
UnknownMicrosoft Sentinel analytics
URL Domains Triggering Microsoft Teams Safety Tips

This query lists the URL domains appearing in Microsoft Teams messages that triggered a safety-tip warning, with each domain's warning rate.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
cbe5f6bc-bf97-434d-a12b-6f137a7effb1
UnknownMicrosoft Sentinel analytics
Top Reporters of Microsoft Teams Calls and Messages

This query lists the users who reported the most Microsoft Teams calls and messages, split by content type, to surface actively targeted people.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
2324aae0-6628-4842-aa36-ae5bf13f3400
UnknownMicrosoft Sentinel analytics
Top Microsoft Teams Senders Removed by Zero-Hour Auto Purge

This query ranks Microsoft Teams senders by how many of their messages were removed after delivery by zero-hour auto purge, split by malware and phish.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
2f28771a-8849-4172-a6d0-1398e902b2d7
UnknownMicrosoft Sentinel analytics
Suspicious Teams Display Name

This query looks for Teams messages from an external user with a suspicious display name.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
02bdbd93-02b7-40e4-9468-d501463e57af
UnknownMicrosoft Sentinel analytics
Suspicious Microsoft Teams Sender Domains Without a Threat Verdict

This query surfaces external Microsoft Teams sender domains that carry no threat verdict yet but are sending low-reputation URLs or unusual volume.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
a0443864-5206-4030-9eb0-a70a7718dbb0
UnknownMicrosoft Sentinel analytics
Suspicious Microsoft Teams Callers by Impersonation-Style Identity

This query surfaces Microsoft Teams callers whose display name or address impersonates IT support, and calls placed from throwaway tenants.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
37f3d0f5-8ac3-46a3-9b27-a4fd082b6348
UnknownMicrosoft Sentinel analytics
Reported Microsoft Teams Calls

This query lists Microsoft Teams calls that users reported to Microsoft, with the reporting user, to surface suspected voice phishing.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
225da6aa-6b34-448d-ab0b-72219d52bd44
UnknownMicrosoft Sentinel analytics
Microsoft Teams Senders Triggering URL Safety Tips

This query lists the Microsoft Teams senders whose messages most often triggered a URL safety-tip warning, with each sender's warning rate.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
23a9ae26-cede-4e3b-8cf0-0d0da7a6930a
UnknownMicrosoft Sentinel analytics
Microsoft Teams Impersonation Identities by Fake Display Name

This query groups Microsoft Teams impersonation detections by the fake display name and sender domain to expose bulk campaigns behind rotating addresses.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
7614cfa2-0fa4-446c-9f03-f0980d67ee20
UnknownMicrosoft Sentinel analytics
Microsoft Teams Calls and Impersonation-Style Calls by Hour of Day

This query compares all Microsoft Teams calls against impersonation-style calls across the 24 hours of the day in UTC.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
55e28f8e-cc6d-4cc9-af24-398a6e2a721d
UnknownMicrosoft Sentinel analytics
Microsoft Teams Call and Message Submissions Over Time

This query trends Microsoft Teams call and message submissions over time, split by content type and by whether a user or an admin reported them.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
ef13dc37-6205-4cea-b969-2b6e0d8ab509
UnknownMicrosoft Sentinel analytics
Low-Reputation URL Domains Shared in Microsoft Teams

This query lists URL domains shared in Microsoft Teams that use top level domains commonly abused for phishing and malware, ranked by message reach.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
d917a922-45ea-46df-a186-5ecc1772644d
UnknownMicrosoft Sentinel analytics
First-Contact External Teams Senders

This query lists external Microsoft Teams senders by the date they were first seen, surfacing recent first-contact senders.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
3c9780f9-1784-48b3-b82e-d1e334c08ed2
UnknownMicrosoft Sentinel analytics
External Microsoft Teams Sender Domain Risk

This query ranks external Microsoft Teams sender domains by threat volume, split by conversation type, with threat rate and low-reputation URL counts.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
4f859dbb-68cf-48d3-812b-7dd19f11e495
MediumElastic detection rules
AWS Service Quota Increase Requested by Rare Identity

Detects the first time an AWS identity requests a service quota increase via the AWS Service Quotas API within a 7-day history window. Service quota increases are submitted to AWS Support and, when approved, raise the limits on EC2 instances, Lambda concurrency, VPC resources, and other services. An adversary who obtains AWS credentials may request quota increases as infrastructure preparation for large-scale cryptomining, DDoS amplification, phishing campaigns, or data exfiltration operations

T1583
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 8, 2026
Upstream
7e1b0654-b6c0-4b1b-ab47-75588533083c
MediumElastic detection rules
AWS Organizations Delegated Administrator Registered

Detects when an AWS member account is registered as a delegated administrator for an AWS service via the RegisterDelegatedAdministrator API. Delegated administrators receive service-level administrative access across the entire organization without being the management account. An attacker who compromises a principal with organizations permissions can abuse overly permissive managed policies to register a member account they control as a delegated administrator, then use that privileged access

T1098T1098.003T1484
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 8, 2026
Upstream
ad8ca41c-8e3d-49cd-b130-42af09d1eb42
HighElastic detection rules
AWS S3 Bucket MFA Delete Disabled

Detects when MFA Delete is disabled on an Amazon S3 bucket. MFA Delete is an additional layer of security for versioned S3 buckets that requires multi-factor authentication to permanently delete object versions or disable versioning. When MFA Delete is disabled, an adversary with S3 write access and a compromised long-term access key can permanently delete object versions, a critical step in ransomware attacks that target S3 versioning as a backup mechanism.

T1490
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 8, 2026
Upstream
b8654454-2757-41b4-ae1a-69b3be704c28
LowElastic detection rules
AWS SES Enumeration via Long-Term Access Key

Detects enumeration of Amazon Simple Email Service (SES) resources using long-term IAM access keys (AKIA* prefix). Long-term access keys are associated with IAM users and are the credential type most commonly exfiltrated from repositories, configuration files, and environment variables. An adversary who obtains a long-term key may enumerate SES to discover verified email identities, sending quotas, and DKIM/MAIL FROM domain configurations as a precursor to phishing or spam campaigns launched

T1526
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 8, 2026
Upstream
8d05971b-5858-4b72-b09a-17e3cee0af54
LowElastic detection rules
AWS Backup Resource Enumeration via Long-Term Access Key

Detects enumeration of AWS Backup resources using long-term IAM access keys (AKIA* prefix). AWS Backup protects EC2 instances, EBS volumes, RDS databases, DynamoDB tables, EFS file systems, and S3 buckets. An adversary who obtains long-term access keys may enumerate backup vaults, backup plans, and protected resources as a precursor to ransomware.

T1526
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 8, 2026
Upstream
e71ae602-bf44-4834-a4ea-b5c87047d426
MediumSplunk security content
Windows SCCM Smsexec Spawned a Suspicious Child Process

The following analytic detects shells, scripting engines, and common post-exploitation utilities spawned as child processes of smsexec.exe. smsexec.exe is the core SCCM SMS Executive service process and has no legitimate reason to launch interactive shells or scripting interpreters. An attacker who plants a malicious adsource.dll in the SCCMProvider bin\X64 directory will obtain code execution in the SCCM service context, typically resulting in a SYSTEM-level child process being spawned under

T1068T1574.001
Licence
Apache License 2.0
Written by
Raven Tait +1
Published
Sep 7, 2026
Upstream
72091a05-3008-4330-b43e-f5e070134ec1
MediumSplunk security content
Windows SCCM Adsource DLL Was Planted In SMS Provider Directory

The following analytic detects the creation or modification of adsource.dll or other staging files with the name adsource_*.dll within the SCCM SMS Provider bin directory, consistent with exploitation of CVE-2026-47301. This abuses a DLL side-loading vulnerability in the Microsoft Configuration Manager SMS Provider component. An attacker can plant a malicious adsource.

T1574.002
Licence
Apache License 2.0
Written by
Raven Tait +1
Published
Sep 7, 2026
Upstream
4f55b07b-7aeb-47f4-a234-b222a902276b
Load more detections

URL Domains Triggering Microsoft Teams Safety Tips

This query lists the URL domains appearing in Microsoft Teams messages that triggered a safety-tip warning, with each domain's warning rate.

ATT&CK coverage

Detection requirements

Log source product
microsoftthreatprotection
Log source service
messageeventsmessageurlinfo

What the source says

Tagged by the source as

InitialAccess

Detection logic

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice