Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,256
detections

Showing 30 of 11,256

LowElastic detection rules
Launch Service Creation and Immediate Loading

An adversary can establish persistence by installing a new launch agent that executes at login by using launchd or launchctl to load a plist into the appropriate directories.

T1543T1543.001T1543.004T1569T1569.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
082e3f8c-6f80-485c-91eb-5b112cb79b28
HighElastic detection rules
Potential Etherhiding C2 via Blockchain Connection

Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware.

T1059T1059.002T1059.004T1059.006T1059.007+3 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
bba8c7d1-172b-435d-9034-02ed9289c628
HighElastic detection rules
Potential EtherHiding C2 via Curl JSON-RPC Request

Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.

T1059T1059.002T1059.004T1102T1102.001+1 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
54285d96-2b7c-4345-890e-3c40e173f099
MediumElastic detection rules
AWS SES Account Email Sending Enabled

Detects when account-level email sending is explicitly enabled in Amazon SES, via the v1 UpdateAccountSendingEnabled API with Enabled: true or the v2 PutAccountSendingAttributes API with SendingEnabled: true. Account-level sending is commonly paused by an administrator, or by automation wired to CloudWatch reputation alarms when bounce or complaint rates rise.

T1608
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
e3f4a5b6-c7d8-9012-cdef-34567890abcd
MediumElastic detection rules
AWS Security Hub Disabled

Detects when AWS Security Hub is disabled in a region. Security Hub aggregates security findings from AWS services (GuardDuty, Inspector, Macie, IAM Access Analyzer) and third-party tools into a single pane of glass. Disabling it suppresses centralized finding aggregation and compliance checks, removing visibility into threats across the account. This action is a documented pre-ransomware and pre-exfiltration defense evasion technique.

T1562T1562.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
c8a2d4f6-1b3e-4a7c-9d5f-8e0b2c6a4d1e
MediumElastic detection rules
AWS Root Console Login Password Spraying

Identifies failed authentication attempts against the AWS Management Console root user from the same source IP address targeting multiple AWS accounts. Password spraying uses few attempts per target across many accounts to avoid lockout, making per-account volume an unreliable signal. This rule detects the cross-account breadth pattern: a single source IP generating root ConsoleLogin failures across two or more distinct AWS accounts.

T1110T1110.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
171d3cdd-0c04-47c2-b392-65719284ae25
MediumSplunk security content
PowerShell 4104 Hunting

The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.

T1003T1059.001T1689
Licence
Apache License 2.0
Written by
Michael Haag +1
Published
Sep 8, 2026
Upstream
d6f2b006-0041-11ec-8885-acde48001122
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map URL to Syslog

Identifies a match in Syslog data from any malicious URL indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
99ae4d06-d352-4926-a1d7-9c28e25b1313
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map File Hash to CommonSecurityLog

Identifies a match in CommonSecurityLog data from any file-hash indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
9c2cef4e-c3a3-4be9-8923-a2f820d4face
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map Domain to DnsEvents

Identifies a match in DnsEvents from any domain-name indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
c6f85aff-4ef0-4fde-b90e-e0ba1a9c3df6
UnknownMicrosoft Sentinel analytics
Malicious Email Campaigns by Recipient URL Clicks

This query ranks malicious inbound email campaigns by the number of URL clicks they attracted and by how many distinct users clicked, rather than by campaign size.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
af3477a3-22f8-45a3-aa01-069d40ba4bd3
UnknownMicrosoft Sentinel analytics
Top 10 sender domains - Admin email submissions (FN)

This query visualises emails submitted by admins as false negatives, summarizing the data by top 10 sender domains of those emails

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
da7eecca-ecb8-4b8e-a111-62d2b48e2e69
UnknownMicrosoft Sentinel analytics
Detect Teams IT Helpdesk Impersonation Msg Phishing & Vishing

This query check Teams IT helpdesk impersonation initial access via Teams chat and voice

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
7c4dad1a-ac02-476b-898d-192d8ef20afb
UnknownMicrosoft Sentinel analytics
Quarantine releases by Detection Types

This query visualises emails released from quarantine and summarizing the result by the original filter verdict

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
23e6d66b-511a-43fd-9863-6924da60319a
UnknownMicrosoft Sentinel analytics
Quarantine Malware Reason

This query visualises the total amount of malware emails that are quarantined, summarized by the detection method

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
c38282e0-5748-467d-95fc-4202b904dbc7
UnknownMicrosoft Sentinel analytics
URL Domains Triggering Microsoft Teams Safety Tips

This query lists the URL domains appearing in Microsoft Teams messages that triggered a safety-tip warning, with each domain's warning rate.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
cbe5f6bc-bf97-434d-a12b-6f137a7effb1
UnknownMicrosoft Sentinel analytics
Top Reporters of Microsoft Teams Calls and Messages

This query lists the users who reported the most Microsoft Teams calls and messages, split by content type, to surface actively targeted people.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
2324aae0-6628-4842-aa36-ae5bf13f3400
UnknownMicrosoft Sentinel analytics
Top Microsoft Teams Senders Removed by Zero-Hour Auto Purge

This query ranks Microsoft Teams senders by how many of their messages were removed after delivery by zero-hour auto purge, split by malware and phish.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
2f28771a-8849-4172-a6d0-1398e902b2d7
UnknownMicrosoft Sentinel analytics
Suspicious Teams Display Name

This query looks for Teams messages from an external user with a suspicious display name.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
02bdbd93-02b7-40e4-9468-d501463e57af
UnknownMicrosoft Sentinel analytics
Suspicious Microsoft Teams Sender Domains Without a Threat Verdict

This query surfaces external Microsoft Teams sender domains that carry no threat verdict yet but are sending low-reputation URLs or unusual volume.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
a0443864-5206-4030-9eb0-a70a7718dbb0
UnknownMicrosoft Sentinel analytics
Suspicious Microsoft Teams Callers by Impersonation-Style Identity

This query surfaces Microsoft Teams callers whose display name or address impersonates IT support, and calls placed from throwaway tenants.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
37f3d0f5-8ac3-46a3-9b27-a4fd082b6348
UnknownMicrosoft Sentinel analytics
Reported Microsoft Teams Calls

This query lists Microsoft Teams calls that users reported to Microsoft, with the reporting user, to surface suspected voice phishing.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
225da6aa-6b34-448d-ab0b-72219d52bd44
UnknownMicrosoft Sentinel analytics
Microsoft Teams Senders Triggering URL Safety Tips

This query lists the Microsoft Teams senders whose messages most often triggered a URL safety-tip warning, with each sender's warning rate.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
23a9ae26-cede-4e3b-8cf0-0d0da7a6930a
UnknownMicrosoft Sentinel analytics
Microsoft Teams Impersonation Identities by Fake Display Name

This query groups Microsoft Teams impersonation detections by the fake display name and sender domain to expose bulk campaigns behind rotating addresses.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
7614cfa2-0fa4-446c-9f03-f0980d67ee20
UnknownMicrosoft Sentinel analytics
Microsoft Teams Calls and Impersonation-Style Calls by Hour of Day

This query compares all Microsoft Teams calls against impersonation-style calls across the 24 hours of the day in UTC.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
55e28f8e-cc6d-4cc9-af24-398a6e2a721d
UnknownMicrosoft Sentinel analytics
Microsoft Teams Call and Message Submissions Over Time

This query trends Microsoft Teams call and message submissions over time, split by content type and by whether a user or an admin reported them.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
ef13dc37-6205-4cea-b969-2b6e0d8ab509
UnknownMicrosoft Sentinel analytics
Low-Reputation URL Domains Shared in Microsoft Teams

This query lists URL domains shared in Microsoft Teams that use top level domains commonly abused for phishing and malware, ranked by message reach.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
d917a922-45ea-46df-a186-5ecc1772644d
UnknownMicrosoft Sentinel analytics
First-Contact External Teams Senders

This query lists external Microsoft Teams senders by the date they were first seen, surfacing recent first-contact senders.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
3c9780f9-1784-48b3-b82e-d1e334c08ed2
UnknownMicrosoft Sentinel analytics
External Microsoft Teams Sender Domain Risk

This query ranks external Microsoft Teams sender domains by threat volume, split by conversation type, with threat rate and low-reputation URL counts.

T1566
Licence
MIT License
Published
Sep 8, 2026
Upstream
4f859dbb-68cf-48d3-812b-7dd19f11e495
MediumElastic detection rules
AWS Service Quota Increase Requested by Rare Identity

Detects the first time an AWS identity requests a service quota increase via the AWS Service Quotas API within a 7-day history window. Service quota increases are submitted to AWS Support and, when approved, raise the limits on EC2 instances, Lambda concurrency, VPC resources, and other services. An adversary who obtains AWS credentials may request quota increases as infrastructure preparation for large-scale cryptomining, DDoS amplification, phishing campaigns, or data exfiltration operations

T1583
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 8, 2026
Upstream
7e1b0654-b6c0-4b1b-ab47-75588533083c
Load more detections

Potential EtherHiding C2 via Curl JSON-RPC Request

Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.

ATT&CK coverage

Detection requirements

Log source category
event_index

What the source says

Tagged by the source as

Data Source: Elastic DefendDomain: EndpointOS: macOSResources: Investigation GuideTactic: Command and ControlTactic: ExecutionUse Case: Threat Detection

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice