Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,279
- detections
Showing 30 of 11,279
This rule assists in detecting rare user agents, which may indicate web browsing activity by an unconventional process different from the usual ones. The rule specifically searches for UserAgent strings that have not been seen in the past 14 days. This query will perform better when run over summarized data
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 2d50d937-d7f2-4c05-b151-9af7f9ec747e
This query utilizes built-in KQL anomaly detection algorithms to identify anomalous data transfers to public networks. It detects significant deviations from a baseline pattern, allowing the detection of sudden increases in data transferred to unknown public networks, which may indicate data exfiltration attempts. Investigating such anomalies is crucial. The score indicates the degree to which the data transfer deviates from the baseline value. A higher score indicates a greater deviation.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 5965d3e7-8ed0-477c-9b42-e75d9237fab0
Detects any failed event for a particular user.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 2a215222-bfc5-4858-a530-6d4088ebfa15
Detects failed events based on created time.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 175b79ef-0fc3-4b27-b92a-89b2db6c85c2
Detects all events with status failed.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- c3835197-fd07-447e-a0ac-7540d51a1f64
Created to detect new threat events from the data in SailPointIDN_Events.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 2151e8ea-4838-4c74-be12-4d6a950dde7a
Created to detect failed events of particular type from SailPointIDN_Events.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 48bb92e2-bad4-4fd4-9684-26cb188299b7
Create alerts for SailPoint IdentityNow Event Trigger Service.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 08330c3d-487e-4f5e-a539-1e7d06dea786
Triggers an alert for High, Medium, or Low severity FortiNDR events grouped by target device and alert severity.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 1e6a8802-9129-44d4-a4f9-c6010b5725e8
Identifies newly observed execution of SoftPerfect Network Scanner or Advanced IP/Port Scanner on a Windows host. Adversaries commonly use these legitimate scanners during post-compromise discovery to map live hosts, open ports, and reachable systems, then select targets for lateral movement.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 15, 2026
- Upstream
- 64037f09-7bf0-4051-ab51-b6daa1d853c6
Identifies a Windows Installer package (MSI) originating from the internet, which when executed, installs a recognized RMM product. Attackers use RMMs commonly in social engineering campaigns to gain access and control over the victim's system. This rule does not establish that the origin, installer, or RMM product is inherently malicious. It also excludes installations covered by the companion rule "RMM Software Installation from a Commonly Abused Web Service".
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 15, 2026
- Upstream
- 7dd15e54-0e23-4e99-80e7-6651ef7ce9d5
Identifies Windows Installer (MSI) packages that originate from commonly abused web services and install a recognized remote monitoring and management (RMM) product. Adversaries may abuse legitimate RMM software in social engineering campaigns to gain remote access and control over victim systems. This rule does not establish that the origin, installer, or RMM product is inherently malicious.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 15, 2026
- Upstream
- ed626330-f3ac-4568-b4e4-cbc296748320
Detects successful AKS pod exec sessions whose command resembles reverse-shell or bind-shell one-liner patterns, including /dev/tcp, /dev/udp and gawk /inet redirection, interactive invocation of any common shell, the netcat and ncat exec/listener forms, socat command-execution and listener addresses, mkfifo and mknod pipelines, socket idioms across Python, Perl, PHP, Ruby, Lua and Node, and tooling such as gsocket, openssl s_server and xterm.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 15, 2026
- Upstream
- eb56a087-c726-4683-8d49-8c0253ea63cf
#DONT_CORR# 'Identifies credentials harvested by infostealer malware on a compromised device. This exposure may indicate an actively compromised endpoint with associated command-and-control risk.'
- Licence
- MIT License
- Published
- Sep 12, 2026
- Upstream
- ead4deed-9d48-4646-aee0-6b46c2dd1ae6
#DONT_CORR# 'Identifies user accounts exposed with a plaintext password in a third-party data breach. Unremediated exposures of this kind can lead directly to account takeover.'
- Licence
- MIT License
- Published
- Sep 12, 2026
- Upstream
- a25eba0e-ff42-4c97-a379-d76bdb2aa1e3
#DONT_CORR# 'Identifies exposure of identity access material such as session cookies, OAuth tokens, or SSO credentials. This material can grant direct account access without a password, so it bypasses password resets and single-factor controls. Revoking active sessions is the primary containment action.'
- Licence
- MIT License
- Published
- Sep 12, 2026
- Upstream
- cd8ec49c-b654-49be-b040-e552b8eba7c8
Identifies an illicit consent grant where a non-admin user consents to an application requesting high-risk delegated mailbox permissions (Mail.Read, Mail.ReadWrite, Mail.Send or MailboxSettings.ReadWrite) together with offline_access. offline_access returns a long-lived refresh token, so a single successful end-user consent gives an attacker-controlled application durable, silent read/send access to the victim mailbox without re-prompting for MFA.
- Licence
- MIT License
- Published
- Sep 12, 2026
- Upstream
- 43df1e4c-61f8-4ab8-bc86-65eca7ecab9a
Identifies DNS queries to commonly abused Top Level Domains by common LOLBINs or executables running from world writable directories or unsigned binaries. This behavior matches on common malware C2 abusing less formal domain names.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- e516bf56-d51b-43e8-91ec-9e276331f433
Identifies HTTP requests to Azure WireServer (168.63.129.16) for GoalState, certificates, versions, or HostGAPlugin vmSettings that do not use a known guest-agent user agent. These requests retrieve transport certificates and extension protectedSettings, including embedded SAS URLs. Azure Linux Agent, Windows guest agent, and related platform UAs are excluded. Requests with no user agent are also excluded; that pattern is common for the Windows guest agent.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- 359b5925-a625-4803-90d2-19e44a37d98e
This rule monitors for the unusual occurrence of outbound network connections to suspicious webservice domains.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- b07f0fba-0a78-11f0-8311-b66272739ecb
This rule detects when a web server process creates a file with a file extension that does not match the file content based on the file header bytes. This is a common technique used by attackers to bypass security measures and to hide the true nature of the file.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- 82f6fa8d-ea35-4329-b334-f1a557dc58c7
This rule detects when a web server process creates a file with high entropy, where the file extension is a web extension. This is a common indicator of an encrypted or encoded payload being uploaded.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- f2738cad-28ab-4c9e-b7f0-66f3b2775e5f
This rule detects when a web server process creates a file with a double extension, where the real extension is a non-web extension. This is a common technique used by attackers to bypass security measures and to hide the true nature of the file.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- 5fc7e978-4fa0-47e9-a8e0-bad853c8d09b
Files that are placed in the "/etc/init.d/" directory in Unix can be used to start custom applications, services, scripts or commands during start-up. Init.d has been mostly replaced in favor of Systemd. However, the "systemd-sysv-generator" can convert init.d files to service unit files that run at boot. Adversaries may add or alter files located in the "/etc/init.d/" directory to execute malicious code upon boot in order to gain persistence on the system.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- 474fd20e-14cc-49c5-8160-d9ab4ba16c8b
This rule identifies potential fileless ELF execution where a process is launched from an anonymous temporary executable path that appears as "/#<id>" in "process.executable". This pattern may be associated with "O_TMPFILE" and "execveat" with "AT_EMPTY_PATH", which can allow execution without a normal filesystem pathname.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- 6fdd522d-421c-49f5-884e-0f278c388276
Identifies OpenSSL generating a CN=LinuxTransport certificate or decrypting CMS/PKCS7 payloads with a key that is not the Azure Linux Agent certificate under /var/lib/waagent. Adversaries can scrape WireServer certificates, mint a LinuxTransport identity, and decrypt extension protectedSettings with openssl cms -decrypt or smime -decrypt.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- 5bb27863-2da6-4d0d-879a-1efb10479c39
Detects a burst of Microsoft 365 user account lockouts within a short 5-minute window. A high number of IdsLocked login errors across multiple user accounts may indicate brute-force attempts for the same users resulting in lockouts.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- de67f85e-2d43-11f0-b8c9-f661ea17fbcc
Identifies brute-force authentication activity targeting Microsoft 365 user accounts using failed sign-in patterns that match password spraying, credential stuffing, or password guessing behavior. Adversaries may attempt brute-force authentication with credentials obtained from previous breaches, leaks, marketplaces or guessable passwords.
- Licence
- Elastic License 2.0
- Written by
- Elastic +2
- Published
- Sep 12, 2026
- Upstream
- 26f68dba-ce29-497b-8e13-b4fde1db5a2d
Identifies the first time an Azure Storage resource receives an anonymous data-plane read (GetBlob and related Get or List operations). Anonymous requests are used to probe public containers and to test stolen blob URLs before a SAS is appended. First-seen resource ID keeps volume down while still covering WireServer-related probes of status or extension blobs.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- eabaf807-e710-4f0f-8943-8d1b436d834a
Identifies a newly observed NetFlow, IPFIX, or sFlow exporter IP followed by another detection alert with medium-or-higher severity or an elevated risk score, where that exporter IP is the source of the detected activity in the same data stream namespace. This correlation adds behavioral evidence that can help distinguish routine exporter onboarding from a potentially unauthorized or compromised exporter introduced as part of defense evasion.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 12, 2026
- Upstream
- 882c8edc-1e39-4a60-80b2-485491b6c91c
RMM Software Installation from a Commonly Abused Web Service
Identifies Windows Installer (MSI) packages that originate from commonly abused web services and install a recognized remote monitoring and management (RMM) product. Adversaries may abuse legitimate RMM software in social engineering campaigns to gain remote access and control over victim systems. This rule does not establish that the origin, installer, or RMM product is inherently malicious. Origins outside this set are covered by the companion rule "RMM Software Installation from an Internet-Originated MSI".
ATT&CK coverage
What the source says
What fires this without an attack behind it
- Authorized IT or managed service provider deployment of remote monitoring and management software through public, vendor, or software distribution infrastructure can produce this behavior.
References
- https://www.forcepoint.com/blog/x-labs/screenconnect-attack
Unclassified · www.forcepoint.com
- https://www.fortian.com.au/blog/trusted-domains-disposable-infrastructure-tax-season-phishing-on-vercel.html
Unclassified · www.fortian.com.au
- https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399
Security research · www.huntress.com
3 detections cite this - https://www.huntress.com/blog/velociraptor-misuse-part-two-eye-of-the-storm
Security research · www.huntress.com
- https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill
Security research · www.huntress.com
- https://www.levelblue.com/blogs/spiderlabs-blog/beyond-fake-updates-from-application-store-themed-phishing-to-large-scale-distribution-of-screenconnect
Unclassified · www.levelblue.com
- https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution
Unclassified · www.proofpoint.com
- https://www.proofpoint.com/us/blog/threat-insight/remote-monitoring-and-management-rmm-tooling-increasingly-attackers-first-choice
Unclassified · www.proofpoint.com
- https://www.security.com/threat-intelligence/rmm-logmein-attacks
Unclassified · www.security.com
- https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
Unclassified · www.securonix.com
Tagged by the source as
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.