Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,279
detections

Showing 30 of 11,279

MediumMicrosoft Sentinel analytics
Detect presence of uncommon user agents in web requests (ASIM Web Session)

This rule assists in detecting rare user agents, which may indicate web browsing activity by an unconventional process different from the usual ones. The rule specifically searches for UserAgent strings that have not been seen in the past 14 days. This query will perform better when run over summarized data

T1133T1190
Licence
MIT License
Published
Sep 15, 2026
Upstream
2d50d937-d7f2-4c05-b151-9af7f9ec747e
MediumMicrosoft Sentinel analytics
Detect unauthorized data transfers using timeseries anomaly (ASIM Web Session)

This query utilizes built-in KQL anomaly detection algorithms to identify anomalous data transfers to public networks. It detects significant deviations from a baseline pattern, allowing the detection of sudden increases in data transferred to unknown public networks, which may indicate data exfiltration attempts. Investigating such anomalies is crucial. The score indicates the degree to which the data transfer deviates from the baseline value. A higher score indicates a greater deviation.

T1030
Licence
MIT License
Published
Sep 15, 2026
Upstream
5965d3e7-8ed0-477c-9b42-e75d9237fab0
HighMicrosoft Sentinel analytics
SailPointIdentityNowUserWithFailedEvent

Detects any failed event for a particular user.

T1133
Licence
MIT License
Published
Sep 15, 2026
Upstream
2a215222-bfc5-4858-a530-6d4088ebfa15
HighMicrosoft Sentinel analytics
SailPointIdentityNowFailedEventsBasedOnTime

Detects failed events based on created time.

T1133
Licence
MIT License
Published
Sep 15, 2026
Upstream
175b79ef-0fc3-4b27-b92a-89b2db6c85c2
HighMicrosoft Sentinel analytics
SailPointIdentityNowFailedEvents

Detects all events with status failed.

T1133
Licence
MIT License
Published
Sep 15, 2026
Upstream
c3835197-fd07-447e-a0ac-7540d51a1f64
HighMicrosoft Sentinel analytics
SailPointIdentityNowEventTypeTechnicalName

Created to detect new threat events from the data in SailPointIDN_Events.

T1133
Licence
MIT License
Published
Sep 15, 2026
Upstream
2151e8ea-4838-4c74-be12-4d6a950dde7a
HighMicrosoft Sentinel analytics
SailPointIdentityNowEventType

Created to detect failed events of particular type from SailPointIDN_Events.

T1133
Licence
MIT License
Published
Sep 15, 2026
Upstream
48bb92e2-bad4-4fd4-9684-26cb188299b7
InformationalMicrosoft Sentinel analytics
SailPointIdentityNowAlertForTriggers

Create alerts for SailPoint IdentityNow Event Trigger Service.

T1005T1133
Licence
MIT License
Published
Sep 15, 2026
Upstream
08330c3d-487e-4f5e-a539-1e7d06dea786
HighMicrosoft Sentinel analytics
FortiNDR Cloud - Security Event Detected

Triggers an alert for High, Medium, or Low severity FortiNDR events grouped by target device and alert severity.

T1021T1041T1046T1059T1071+3 more
Licence
MIT License
Published
Sep 15, 2026
Upstream
1e6a8802-9129-44d4-a4f9-c6010b5725e8
MediumElastic detection rules
Newly Seen Commonly Abused Network Scanner

Identifies newly observed execution of SoftPerfect Network Scanner or Advanced IP/Port Scanner on a Windows host. Adversaries commonly use these legitimate scanners during post-compromise discovery to map live hosts, open ports, and reachable systems, then select targets for lateral movement.

T1018T1046
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 15, 2026
Upstream
64037f09-7bf0-4051-ab51-b6daa1d853c6
LowElastic detection rules
RMM Software Installation from an Internet-Originated MSI

Identifies a Windows Installer package (MSI) originating from the internet, which when executed, installs a recognized RMM product. Attackers use RMMs commonly in social engineering campaigns to gain access and control over the victim's system. This rule does not establish that the origin, installer, or RMM product is inherently malicious. It also excludes installations covered by the companion rule "RMM Software Installation from a Commonly Abused Web Service".

T1105T1218T1218.007T1219T1219.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 15, 2026
Upstream
7dd15e54-0e23-4e99-80e7-6651ef7ce9d5
MediumElastic detection rules
RMM Software Installation from a Commonly Abused Web Service

Identifies Windows Installer (MSI) packages that originate from commonly abused web services and install a recognized remote monitoring and management (RMM) product. Adversaries may abuse legitimate RMM software in social engineering campaigns to gain remote access and control over victim systems. This rule does not establish that the origin, installer, or RMM product is inherently malicious.

T1105T1218T1218.007T1219T1219.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 15, 2026
Upstream
ed626330-f3ac-4568-b4e4-cbc296748320
HighElastic detection rules
Azure AKS Pod Exec Potential Reverse Shell

Detects successful AKS pod exec sessions whose command resembles reverse-shell or bind-shell one-liner patterns, including /dev/tcp, /dev/udp and gawk /inet redirection, interactive invocation of any common shell, the netcat and ncat exec/listener forms, socat command-execution and listener addresses, mkfifo and mknod pipelines, socket idioms across Python, Perl, PHP, Ruby, Lua and Node, and tooling such as gsocket, openssl s_server and xterm.

T1059T1095T1609
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 15, 2026
Upstream
eb56a087-c726-4683-8d49-8c0253ea63cf
HighMicrosoft Sentinel analytics
SpyCloud infostealer malware credential exposure

#DONT_CORR# 'Identifies credentials harvested by infostealer malware on a compromised device. This exposure may indicate an actively compromised endpoint with associated command-and-control risk.'

T1071T1555
Licence
MIT License
Published
Sep 12, 2026
Upstream
ead4deed-9d48-4646-aee0-6b46c2dd1ae6
HighMicrosoft Sentinel analytics
SpyCloud plaintext credential exposure detected

#DONT_CORR# 'Identifies user accounts exposed with a plaintext password in a third-party data breach. Unremediated exposures of this kind can lead directly to account takeover.'

T1555
Licence
MIT License
Published
Sep 12, 2026
Upstream
a25eba0e-ff42-4c97-a379-d76bdb2aa1e3
HighMicrosoft Sentinel analytics
SpyCloud identity access record exposure

#DONT_CORR# 'Identifies exposure of identity access material such as session cookies, OAuth tokens, or SSO credentials. This material can grant direct account access without a password, so it bypasses password resets and single-factor controls. Revoking active sessions is the primary containment action.'

T1528T1539T1550
Licence
MIT License
Published
Sep 12, 2026
Upstream
cd8ec49c-b654-49be-b040-e552b8eba7c8
HighMicrosoft Sentinel analytics
End-user consent to app with mailbox and offline access delegated scopes

Identifies an illicit consent grant where a non-admin user consents to an application requesting high-risk delegated mailbox permissions (Mail.Read, Mail.ReadWrite, Mail.Send or MailboxSettings.ReadWrite) together with offline_access. offline_access returns a long-lived refresh token, so a single successful end-user consent gives an attacker-controlled application durable, silent read/send access to the victim mailbox without re-prompting for MFA.

T1528
Licence
MIT License
Published
Sep 12, 2026
Upstream
43df1e4c-61f8-4ab8-bc86-65eca7ecab9a
HighElastic detection rules
Network Activity to a Suspicious Top Level Domain

Identifies DNS queries to commonly abused Top Level Domains by common LOLBINs or executables running from world writable directories or unsigned binaries. This behavior matches on common malware C2 abusing less formal domain names.

T1071T1071.004T1127T1127.001T1218
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
e516bf56-d51b-43e8-91ec-9e276331f433
MediumElastic detection rules
Azure WireServer HTTP Request from Unexpected User Agent

Identifies HTTP requests to Azure WireServer (168.63.129.16) for GoalState, certificates, versions, or HostGAPlugin vmSettings that do not use a known guest-agent user agent. These requests retrieve transport certificates and extension protectedSettings, including embedded SAS URLs. Azure Linux Agent, Windows guest agent, and related platform UAs are excluded. Requests with no user agent are also excluded; that pattern is common for the Windows guest agent.

T1082T1552T1552.005
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
359b5925-a625-4803-90d2-19e44a37d98e
MediumElastic detection rules
Unusual Network Connection to Suspicious Web Service

This rule monitors for the unusual occurrence of outbound network connections to suspicious webservice domains.

T1071T1071.001T1102T1567T1567.002+2 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
b07f0fba-0a78-11f0-8311-b66272739ecb
HighElastic detection rules
Potential Polyglot Bypass File Created by Web Server

This rule detects when a web server process creates a file with a file extension that does not match the file content based on the file header bytes. This is a common technique used by attackers to bypass security measures and to hide the true nature of the file.

T1190T1210T1505T1505.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
82f6fa8d-ea35-4329-b334-f1a557dc58c7
HighElastic detection rules
File with High Entropy Created by Web Server

This rule detects when a web server process creates a file with high entropy, where the file extension is a web extension. This is a common indicator of an encrypted or encoded payload being uploaded.

T1190T1210T1505T1505.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
f2738cad-28ab-4c9e-b7f0-66f3b2775e5f
HighElastic detection rules
File with Suspicious Double Extension Created by Web Server

This rule detects when a web server process creates a file with a double extension, where the real extension is a non-web extension. This is a common technique used by attackers to bypass security measures and to hide the true nature of the file.

T1190T1210T1505T1505.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
5fc7e978-4fa0-47e9-a8e0-bad853c8d09b
LowElastic detection rules
System V Init Script Created

Files that are placed in the "/etc/init.d/" directory in Unix can be used to start custom applications, services, scripts or commands during start-up. Init.d has been mostly replaced in favor of Systemd. However, the "systemd-sysv-generator" can convert init.d files to service unit files that run at boot. Adversaries may add or alter files located in the "/etc/init.d/" directory to execute malicious code upon boot in order to gain persistence on the system.

T1037T1037.004
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
474fd20e-14cc-49c5-8160-d9ab4ba16c8b
HighElastic detection rules
Potential Fileless Execution via O_TMPFILE

This rule identifies potential fileless ELF execution where a process is launched from an anonymous temporary executable path that appears as "/#<id>" in "process.executable". This pattern may be associated with "O_TMPFILE" and "execveat" with "AT_EMPTY_PATH", which can allow execution without a normal filesystem pathname.

T1036T1036.005
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
6fdd522d-421c-49f5-884e-0f278c388276
MediumElastic detection rules
Azure WireServer OpenSSL Certificate Decrypt or LinuxTransport Generation

Identifies OpenSSL generating a CN=LinuxTransport certificate or decrypting CMS/PKCS7 payloads with a key that is not the Azure Linux Agent certificate under /var/lib/waagent. Adversaries can scrape WireServer certificates, mint a LinuxTransport identity, and decrypt extension protectedSettings with openssl cms -decrypt or smime -decrypt.

T1140T1552T1552.005
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
5bb27863-2da6-4d0d-879a-1efb10479c39
MediumElastic detection rules
M365 Identity User Account Lockouts

Detects a burst of Microsoft 365 user account lockouts within a short 5-minute window. A high number of IdsLocked login errors across multiple user accounts may indicate brute-force attempts for the same users resulting in lockouts.

T1078T1078.004T1110T1110.001T1110.003+1 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
de67f85e-2d43-11f0-b8c9-f661ea17fbcc
MediumElastic detection rules
M365 Identity User Brute Force Attempted

Identifies brute-force authentication activity targeting Microsoft 365 user accounts using failed sign-in patterns that match password spraying, credential stuffing, or password guessing behavior. Adversaries may attempt brute-force authentication with credentials obtained from previous breaches, leaks, marketplaces or guessable passwords.

T1110T1110.001T1110.003T1110.004
Licence
Elastic License 2.0
Written by
Elastic +2
Published
Sep 12, 2026
Upstream
26f68dba-ce29-497b-8e13-b4fde1db5a2d
MediumElastic detection rules
Azure Storage Anonymous Blob Access to Unusual Resource

Identifies the first time an Azure Storage resource receives an anonymous data-plane read (GetBlob and related Get or List operations). Anonymous requests are used to probe public containers and to test stolen blob URLs before a SAS is appended. First-seen resource ID keeps volume down while still covering WireServer-related probes of status or extension blobs.

T1530T1580
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
eabaf807-e710-4f0f-8943-8d1b436d834a
HighElastic detection rules
First Seen Network Flow Exporter Followed by Suspicious Source Activity

Identifies a newly observed NetFlow, IPFIX, or sFlow exporter IP followed by another detection alert with medium-or-higher severity or an elevated risk score, where that exporter IP is the source of the detected activity in the same data stream namespace. This correlation adds behavioral evidence that can help distinguish routine exporter onboarding from a potentially unauthorized or compromised exporter introduced as part of defense evasion.

T1562
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 12, 2026
Upstream
882c8edc-1e39-4a60-80b2-485491b6c91c
Load more detections

RMM Software Installation from a Commonly Abused Web Service

Identifies Windows Installer (MSI) packages that originate from commonly abused web services and install a recognized remote monitoring and management (RMM) product. Adversaries may abuse legitimate RMM software in social engineering campaigns to gain remote access and control over victim systems. This rule does not establish that the origin, installer, or RMM product is inherently malicious. Origins outside this set are covered by the companion rule "RMM Software Installation from an Internet-Originated MSI".

ATT&CK coverage

What the source says

What fires this without an attack behind it

  • Authorized IT or managed service provider deployment of remote monitoring and management software through public, vendor, or software distribution infrastructure can produce this behavior.

Tagged by the source as

Data Source: Elastic DefendDomain: EndpointOS: WindowsPlatform: WindowsRule Type: ESQLTactic: Command and ControlTactic: Defense EvasionUse Case: Threat Detection

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice