Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,263
detections

Showing 30 of 11,263

MediumElastic detection rules
AzCopy or Azure Storage Explorer Usage on Unusual Host

Identifies the first time, in a historical window, a host runs AzCopy copy or sync to Azure Blob, Data Lake, or File storage, or starts Azure Storage Explorer. These Microsoft utilities are legitimate data-transfer tools; ransomware and cloud-ransomware operators drop portable copies and use SAS-authenticated jobs to pull data from victim storage and push it to attacker-controlled accounts.

T1059T1059.009T1530T1567T1567.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
7265f4fa-4839-4399-924c-a91f1e45d76c
MediumElastic detection rules
Abnormally Large DNS Response

Specially crafted DNS requests can manipulate a known overflow vulnerability in some Windows DNS servers, resulting in Remote Code Execution (RCE) or a Denial of Service (DoS) from crashing the service.

T1210T1499T1499.004
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
11013227-0301-4a8c-b150-4db924484475
HighElastic detection rules
RPC (Remote Procedure Call) to the Internet

This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.

T1021T1021.003T1190
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
32923416-763a-4531-bb35-f33b9232ecdb
LowElastic detection rules
Potential SYN-Based Port Scan Detected

This rule identifies a potential SYN-Based port scan. A SYN port scan is a technique employed by attackers to scan a target network for open ports by sending SYN packets to multiple ports and observing the response. Attackers use this method to identify potential entry points or services that may be vulnerable to exploitation, allowing them to launch targeted attacks or gain unauthorized access to the system or network, compromising its security and potentially leading to data breaches or

T1046T1595T1595.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
bbaa96b9-f36c-4898-ace2-581acb00a409
LowElastic detection rules
Potential Network Scan Detected

This rule identifies a potential port scan from an internal IP address. A port scan is a method utilized by attackers to systematically scan a target system for open ports, allowing them to identify available services and potential vulnerabilities. By mapping out the open ports, attackers can gather critical information to plan and execute targeted attacks, gaining unauthorized access, compromising security, and potentially leading to data breaches, unauthorized control, or further exploitation

T1046T1595T1595.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
0171f283-ade7-4f87-9521-ac346c68cc9b
LowElastic detection rules
Newly Observed IPSEC NAT Traversal Peer

This rule identifies outbound IPSEC NAT Traversal (NAT-T) traffic to an external destination IP that was not observed during the previous 5 days. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal encapsulates IPSEC ESP traffic in UDP and, once a NAT device is detected, both peers float to UDP port 4500 for the tunnel data channel.

T1095T1572T1573
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
a9cb3641-ff4b-4cdc-a063-b4b8d02a67c7
MediumElastic detection rules
Accepted Default Telnet Port Connection

This rule detects network events that may indicate the use of Telnet traffic. Telnet is commonly used by system administrators to remotely control older or embedded systems using the command line shell. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. As a plain-text protocol, it may also expose usernames and passwords to anyone capable of observing the traffic.

T1021T1071T1133T1190
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
34fde489-94b0-4500-a76f-b8a157cf9269
HighElastic detection rules
Entra ID Deviceless Windows Hello Sign-in Followed by Device Registration

Identifies a Microsoft Entra ID device registration by the same user within 15 minutes of a phishing-resistant, device-bound credential (Windows Hello for Business, FIDO2 security key, or passkey) signing in with no device identifier. In the "borrowing Windows Hello keys" technique, an adversary reuses a WHfB/NGC key or passkey away from its bound device to mint device-agnostic tokens, then uses those tokens to register an attacker-controlled device and obtain a Primary Refresh Token (PRT) for

T1098T1098.005T1550
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
62848597-595c-4cc3-8d24-6c47a5fee9a9
LowElastic detection rules
Entra ID Windows Hello for Business Credential Registered

Identifies the first-seen registration of a Windows Hello for Business (WHfB) credential for a Microsoft Entra ID user from a given source ASN in a tenant, based on a prefixed historic window. Enrollment is commonly part of legitimate onboarding or passwordless rollout and is not inherently malicious. Adversaries who have obtained a token that satisfies fresh (NGC) multi-factor authentication, for example by borrowing an existing WHfB key or passkey, can also enroll their own WHfB credential to

T1098T1098.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
8c6f8cca-f730-4cdd-93a7-d65f087a4116
MediumElastic detection rules
Entra ID Windows Hello or Passkey Sign-in from Unregistered Device

Identifies a Microsoft Entra ID sign-in that is satisfied by a phishing-resistant, device-bound credential (Windows Hello for Business, FIDO2 security key, or passkey) while carrying no device identifier. Windows Hello for Business (WHfB) and passkey credentials are bound to a device's TPM, so a genuine sign-in with one of these methods is normally accompanied by the registered device it lives on. A WHfB or passkey assertion that authenticates with an empty `device_detail.

T1078T1078.004T1550
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
763b0a74-2961-4396-bb4b-8cd850e1ebe4
HighElastic detection rules
Entra ID Device-Bound PRT from Unusual Device IP

Detects a first-party FOCI tooling client (Azure CLI, PowerShell, VS Code, Graph CLI, Azure AD PowerShell, or Visual Studio) redeeming a device-bound Primary Refresh Token (PRT) for Microsoft Graph, SharePoint/OneDrive, or Exchange Online from a source IP that has not been seen with that deviceid. Replay events are limited to compliant or Intune-managed devices.

T1078T1078.004T1528T1539T1550+1 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
9e8d9bb5-6d3a-4431-a0d0-8d0475e726a4
HighElastic detection rules
Entra ID Device-Bound PRT Replay via First-Party App from Unusual IP

Detects a first-party FOCI tooling client (Azure CLI, PowerShell, VS Code, Graph CLI, Azure AD PowerShell, or Visual Studio) redeeming a device-bound Primary Refresh Token (PRT) for Microsoft Graph, SharePoint/OneDrive, or Exchange Online from an IP that is not among that user and device's Windows Sign-In or WAM addresses. Replay events are limited to compliant or Intune-managed devices: the stolen cookie keeps the workstation deviceid, so compliant-device Conditional Access can succeed off-box.

T1078T1078.004T1528T1539T1550+1 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
6a9fdaab-b50f-408d-b4da-54719f256d41
MediumElastic detection rules
Suricata and Elastic Defend Network Correlation

This detection correlates Suricata alerts with Elastic Defend network events to identify the source process performing the network activity.

T1046T1071T1571
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 11, 2026
Upstream
9edd000e-cbd1-4d6a-be72-2197b5625a05
UnknownMicrosoft Sentinel analytics
Connection to Unpopular Website Detected (ASIM DNS Solution)

This query lists DNS queries not found in the top 1 million queries in the past 14 days. Please note: To enhance performance, this query uses summarized data if available. The Hunting query also depends on the "**DNSEssentialsCustomParser**" Parser, so please make sure it is installed and configured before you use this Hunting query.

T1095
Licence
MIT License
Published
Sep 10, 2026
Upstream
83e70a34-d96f-419d-815b-43d1499e88ed
UnknownMicrosoft Sentinel analytics
[Anomaly] Anomalous Increase in DNS activity by clients (ASIM DNS Solution)

Checks for an anomalous increase in DNS activity per client in the last 24 hours as compared to the last 14 days. Please note: To enhance performance, this query uses summarized data if available. The Hunting query also depends on the "**DNSEssentialsCustomParser**" Parser, so please make sure it is installed and configured before you use this Hunting query.

T1008T1048T1568
Licence
MIT License
Published
Sep 10, 2026
Upstream
50f0cdfb-8b01-4eca-823d-2bbe6b8a5b95
MediumMicrosoft Sentinel analytics
Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution)

This rule makes use of the series decompose anomaly method to detect clients with a high NXDomain response count, which could be indicative of a DGA (cycling through possible C2 domains where most C2s are not live). An alert is generated when new IP address DNS activity is identified as an outlier when compared to the baseline, indicating a recurring pattern. It utilizes [ASIM](https://aka.ms/AboutASIM) normalization and is applied to any source that supports the ASIM DNS schema.

T1008T1568
Licence
MIT License
Published
Sep 10, 2026
Upstream
01191239-274e-43c9-b154-3a042692af06
MediumMicrosoft Sentinel analytics
Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution)

This rule makes use of the series decompose anomaly method to generate an alert when multiple clients report errors for the same DNS query. This rule monitors DNS traffic over a period of 14 days to detect possible similar C2 communication originating from different clients. It utilizes [ASIM](https://aka.ms/AboutASIM) normalization and is applied to any source that supports the ASIM DNS schema.

T1008T1568T1573
Licence
MIT License
Published
Sep 10, 2026
Upstream
cf687598-5a2c-46f8-81c8-06b15ed489b1
MediumMicrosoft Sentinel analytics
Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution)

This rule makes use of the series decompose anomaly method to generate an alert when client requests excessive amount of DNS queries to non-existent domains. This helps in identifying possible C2 communications. It utilizes [ASIM](https://aka.ms/AboutASIM) normalization and is applied to any source that supports the ASIM DNS schema. The rule also depends on the "**DNSEssentialsCustomParser**" Parser, so please make sure it is installed and configured before you use this Rule.

T1008T1568
Licence
MIT License
Published
Sep 10, 2026
Upstream
02f23312-1a33-4390-8b80-f7cd4df4dea0
MediumElastic detection rules
M365 OneDrive/SharePoint Excessive File Downloads

Identifies when an excessive number of files are downloaded from OneDrive or SharePoint by an authorized user or application in a short period of time. This may indicate a potential data exfiltration event, especially if the downloads are performed using OAuth authentication which could suggest an OAuth phishing attack such as Device Code Authentication phishing.

T1020T1530T1567
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 10, 2026
Upstream
0e524fa6-eed3-11ef-82b4-f661ea17fbce
MediumSplunk security content
Windows Content Copied from Browser was Executed

The following analytic correlates modifications to the Windows RunMRU registry key with clipboard content changes initiated by browsers. It aims to detect ClickFix scenarios in which commands copied from a browser are subsequently executed on the Windows system through the Run dialog box.

T1059.001T1059.003T1202
Licence
Apache License 2.0
Written by
Onur Mustafa Erdogan +1
Published
Sep 9, 2026
Upstream
5d1fdbcb-5ed9-4190-85c8-7f9026450a0b
LowElastic detection rules
Launch Service Creation and Immediate Loading

An adversary can establish persistence by installing a new launch agent that executes at login by using launchd or launchctl to load a plist into the appropriate directories.

T1543T1543.001T1543.004T1569T1569.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
082e3f8c-6f80-485c-91eb-5b112cb79b28
HighElastic detection rules
Potential Etherhiding C2 via Blockchain Connection

Detects when a scripting interpreter makes an outbound network connection to an Ethereum blockchain endpoint for command and control purposes. Adversaries may leverage Ethereum blockchain infrastructure as a covert C2 channel to receive commands and exfiltrate data, as observed in campaigns like SleepyDuck malware.

T1059T1059.002T1059.004T1059.006T1059.007+3 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
bba8c7d1-172b-435d-9034-02ed9289c628
HighElastic detection rules
Potential EtherHiding C2 via Curl JSON-RPC Request

Detects when curl or nscurl is spawned by a shell or osascript to make a JSON-RPC request to a blockchain endpoint for command and control purposes. Adversaries may leverage blockchain smart contracts as a covert C2 channel to retrieve commands or payload staging information, as observed in ClickFix campaigns.

T1059T1059.002T1059.004T1102T1102.001+1 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
54285d96-2b7c-4345-890e-3c40e173f099
MediumElastic detection rules
AWS SES Account Email Sending Enabled

Detects when account-level email sending is explicitly enabled in Amazon SES, via the v1 UpdateAccountSendingEnabled API with Enabled: true or the v2 PutAccountSendingAttributes API with SendingEnabled: true. Account-level sending is commonly paused by an administrator, or by automation wired to CloudWatch reputation alarms when bounce or complaint rates rise.

T1608
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
e3f4a5b6-c7d8-9012-cdef-34567890abcd
MediumElastic detection rules
AWS Security Hub Disabled

Detects when AWS Security Hub is disabled in a region. Security Hub aggregates security findings from AWS services (GuardDuty, Inspector, Macie, IAM Access Analyzer) and third-party tools into a single pane of glass. Disabling it suppresses centralized finding aggregation and compliance checks, removing visibility into threats across the account. This action is a documented pre-ransomware and pre-exfiltration defense evasion technique.

T1562T1562.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
c8a2d4f6-1b3e-4a7c-9d5f-8e0b2c6a4d1e
MediumElastic detection rules
AWS Root Console Login Password Spraying

Identifies failed authentication attempts against the AWS Management Console root user from the same source IP address targeting multiple AWS accounts. Password spraying uses few attempts per target across many accounts to avoid lockout, making per-account volume an unreliable signal. This rule detects the cross-account breadth pattern: a single source IP generating root ConsoleLogin failures across two or more distinct AWS accounts.

T1110T1110.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 9, 2026
Upstream
171d3cdd-0c04-47c2-b392-65719284ae25
MediumSplunk security content
PowerShell 4104 Hunting

The following analytic identifies suspicious PowerShell execution using Script Block Logging (EventCode 4104). It leverages specific patterns and keywords within the ScriptBlockText field to detect potentially malicious activities. This detection is significant for SOC analysts as PowerShell is commonly used by attackers for various malicious purposes, including code execution, privilege escalation, and persistence.

T1003T1059.001T1689
Licence
Apache License 2.0
Written by
Michael Haag +1
Published
Sep 8, 2026
Upstream
d6f2b006-0041-11ec-8885-acde48001122
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map URL to Syslog

Identifies a match in Syslog data from any malicious URL indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
99ae4d06-d352-4926-a1d7-9c28e25b1313
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map File Hash to CommonSecurityLog

Identifies a match in CommonSecurityLog data from any file-hash indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
9c2cef4e-c3a3-4be9-8923-a2f820d4face
MediumMicrosoft Sentinel analytics
PRODAFT USTA - TI map Domain to DnsEvents

Identifies a match in DnsEvents from any domain-name indicator ingested from PRODAFT USTA IoC Threat Intelligence (SourceSystem starting with "PRODAFT USTA").

T1071
Licence
MIT License
Published
Sep 8, 2026
Upstream
c6f85aff-4ef0-4fde-b90e-e0ba1a9c3df6
Load more detections

Entra ID Deviceless Windows Hello Sign-in Followed by Device Registration

Identifies a Microsoft Entra ID device registration by the same user within 15 minutes of a phishing-resistant, device-bound credential (Windows Hello for Business, FIDO2 security key, or passkey) signing in with no device identifier. In the "borrowing Windows Hello keys" technique, an adversary reuses a WHfB/NGC key or passkey away from its bound device to mint device-agnostic tokens, then uses those tokens to register an attacker-controlled device and obtain a Primary Refresh Token (PRT) for long-lived persistence. Timing is taken from the authentication step on the sign-in, not the sign-in document timestamp, because Entra can emit the sign-in record after the Register device audit event. This chain is distinct from device-code-flow phishing kits.

ATT&CK coverage

What the source says

What fires this without an attack behind it

  • A user completing initial passwordless enrollment and registering their first device in the same session can match. Validate against expected onboarding and the device's provenance (managed/compliant, expected name, expected source).
  • Authorized red team or research engagements that borrow a WHfB/passkey and register a device will match. Document the engagement and add scoped exceptions for the involved principals or source addresses.

Tagged by the source as

Data Source: AzureData Source: Microsoft Entra IDData Source: Microsoft Entra ID Audit LogsData Source: Microsoft Entra ID Sign-in LogsDomain: CloudDomain: IdentityPlatform: Entra IDResources: Investigation GuideRule Type: ESQLTactic: Defense EvasionTactic: PersistenceUse Case: Threat Detection

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice