Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,256
- detections
Showing 30 of 11,256
An adversary can establish persistence by installing a new launch agent that executes at login by using launchd or launchctl to load a plist into the appropriate directories.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- 082e3f8c-6f80-485c-91eb-5b112cb79b28
Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- bba8c7d1-172b-435d-9034-02ed9289c628
Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- 54285d96-2b7c-4345-890e-3c40e173f099
Detects when account-level email sending is explicitly enabled in Amazon SES, via the v1 UpdateAccountSendingEnabled API with Enabled: true or the v2 PutAccountSendingAttributes API with SendingEnabled: true. Account-level sending is commonly paused by an administrator, or by automation wired to CloudWatch reputation alarms when bounce or complaint rates rise.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- e3f4a5b6-c7d8-9012-cdef-34567890abcd
Detects when AWS Security Hub is disabled in a region. Security Hub aggregates security findings from AWS services (GuardDuty, Inspector, Macie, IAM Access Analyzer) and third-party tools into a single pane of glass. Disabling it suppresses centralized finding aggregation and compliance checks, removing visibility into threats across the account. This action is a documented pre-ransomware and pre-exfiltration defense evasion technique.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- c8a2d4f6-1b3e-4a7c-9d5f-8e0b2c6a4d1e
Identifies failed authentication attempts against the AWS Management Console root user from the same source IP address targeting multiple AWS accounts. Password spraying uses few attempts per target across many accounts to avoid lockout, making per-account volume an unreliable signal. This rule detects the cross-account breadth pattern: a single source IP generating root ConsoleLogin failures across two or more distinct AWS accounts.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 9, 2026
- Upstream
- 171d3cdd-0c04-47c2-b392-65719284ae25
The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.
- Licence
- Apache License 2.0
- Written by
- Michael Haag +1
- Published
- Sep 8, 2026
- Upstream
- d6f2b006-0041-11ec-8885-acde48001122
Identifies a match in Syslog data from any malicious URL indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 99ae4d06-d352-4926-a1d7-9c28e25b1313
Identifies a match in CommonSecurityLog data from any file-hash indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 9c2cef4e-c3a3-4be9-8923-a2f820d4face
Identifies a match in DnsEvents from any domain-name indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- c6f85aff-4ef0-4fde-b90e-e0ba1a9c3df6
This query ranks malicious inbound email campaigns by the number of URL clicks they attracted and by how many distinct users clicked, rather than by campaign size.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- af3477a3-22f8-45a3-aa01-069d40ba4bd3
This query visualises emails submitted by admins as false negatives, summarizing the data by top 10 sender domains of those emails
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- da7eecca-ecb8-4b8e-a111-62d2b48e2e69
This query check Teams IT helpdesk impersonation initial access via Teams chat and voice
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 7c4dad1a-ac02-476b-898d-192d8ef20afb
This query visualises emails released from quarantine and summarizing the result by the original filter verdict
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 23e6d66b-511a-43fd-9863-6924da60319a
This query visualises the total amount of malware emails that are quarantined, summarized by the detection method
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- c38282e0-5748-467d-95fc-4202b904dbc7
This query lists the URL domains appearing in Microsoft Teams messages that triggered a safety-tip warning, with each domain's warning rate.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- cbe5f6bc-bf97-434d-a12b-6f137a7effb1
This query lists the users who reported the most Microsoft Teams calls and messages, split by content type, to surface actively targeted people.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 2324aae0-6628-4842-aa36-ae5bf13f3400
This query ranks Microsoft Teams senders by how many of their messages were removed after delivery by zero-hour auto purge, split by malware and phish.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 2f28771a-8849-4172-a6d0-1398e902b2d7
This query looks for Teams messages from an external user with a suspicious display name.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 02bdbd93-02b7-40e4-9468-d501463e57af
This query surfaces external Microsoft Teams sender domains that carry no threat verdict yet but are sending low-reputation URLs or unusual volume.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- a0443864-5206-4030-9eb0-a70a7718dbb0
This query surfaces Microsoft Teams callers whose display name or address impersonates IT support, and calls placed from throwaway tenants.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 37f3d0f5-8ac3-46a3-9b27-a4fd082b6348
This query lists Microsoft Teams calls that users reported to Microsoft, with the reporting user, to surface suspected voice phishing.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 225da6aa-6b34-448d-ab0b-72219d52bd44
This query lists the Microsoft Teams senders whose messages most often triggered a URL safety-tip warning, with each sender's warning rate.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 23a9ae26-cede-4e3b-8cf0-0d0da7a6930a
This query groups Microsoft Teams impersonation detections by the fake display name and sender domain to expose bulk campaigns behind rotating addresses.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 7614cfa2-0fa4-446c-9f03-f0980d67ee20
This query compares all Microsoft Teams calls against impersonation-style calls across the 24 hours of the day in UTC.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 55e28f8e-cc6d-4cc9-af24-398a6e2a721d
This query trends Microsoft Teams call and message submissions over time, split by content type and by whether a user or an admin reported them.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- ef13dc37-6205-4cea-b969-2b6e0d8ab509
This query lists URL domains shared in Microsoft Teams that use top level domains commonly abused for phishing and malware, ranked by message reach.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- d917a922-45ea-46df-a186-5ecc1772644d
This query lists external Microsoft Teams senders by the date they were first seen, surfacing recent first-contact senders.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 3c9780f9-1784-48b3-b82e-d1e334c08ed2
This query ranks external Microsoft Teams sender domains by threat volume, split by conversation type, with threat rate and low-reputation URL counts.
- Licence
- MIT License
- Published
- Sep 8, 2026
- Upstream
- 4f859dbb-68cf-48d3-812b-7dd19f11e495
Detects the first time an AWS identity requests a service quota increase via the AWS Service Quotas API within a 7-day history window. Service quota increases are submitted to AWS Support and, when approved, raise the limits on EC2 instances, Lambda concurrency, VPC resources, and other services. An adversary who obtains AWS credentials may request quota increases as infrastructure preparation for large-scale cryptomining, DDoS amplification, phishing campaigns, or data exfiltration operations
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 8, 2026
- Upstream
- 7e1b0654-b6c0-4b1b-ab47-75588533083c
AWS SES Account Email Sending Enabled
Detects when account-level email sending is explicitly enabled in Amazon SES, via the v1 UpdateAccountSendingEnabled API with Enabled: true or the v2 PutAccountSendingAttributes API with SendingEnabled: true. Account-level sending is commonly paused by an administrator, or by automation wired to CloudWatch reputation alarms when bounce or complaint rates rise. An attacker who compromises an AWS account may re-enable sending to restore a paused capability as part of phishing infrastructure setup, allowing bulk email under the victim organization's trusted sending domain. Neither API can resume sending that AWS itself has paused.
ATT&CK coverage
Detection requirements
- Log source category
- event_index
What the source says
What fires this without an attack behind it
- SES account sending may be legitimately re-enabled by an administrator after a sending pause for bounce/complaint rate investigation or maintenance. Validate against a change management record or scheduled maintenance window. This API is rarely called in normal operations.
References
- https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_PutAccountSendingAttributes.html
Product documentation · docs.aws.amazon.com
- https://docs.aws.amazon.com/ses/latest/APIReference/API_UpdateAccountSendingEnabled.html
Product documentation · docs.aws.amazon.com
- https://permiso.io/blog/s/aws-ses-pionage-detecting-ses-abuse/
Unclassified · permiso.io
- https://www.rapid7.com/blog/post/dr-threat-actors-aws-workmail-phishing-campaigns/
Unclassified · www.rapid7.com
Tagged by the source as
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.