Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,283
- detections
Showing 30 of 11,283
Query searches for outbound block rules deleted by non AI.
- Licence
- MIT License
- Published
- Sep 16, 2026
- Upstream
- d8945c8f-bba4-4e02-ad09-228b067ebcf2
Query searches for inbound block rules deleted by non AI.
- Licence
- MIT License
- Published
- Sep 16, 2026
- Upstream
- fcbbd670-d4e6-4f3a-9008-d8905e84cf79
A rule was created which granted a user access to a large, built-in, group of assets.
- Licence
- MIT License
- Published
- Sep 16, 2026
- Upstream
- 0e68d210-a8ec-4e13-9f46-61011c020b87
Find users who gained access to the largest number of target assets in the selected time range
- Licence
- MIT License
- Published
- Sep 16, 2026
- Upstream
- 3dd14edf-788d-4f42-868f-28f3208b92a9
Identifies when a JIT Rule connection is new or rare by a given account today based on comparison with the previous 14 days. JIT Rule creations are indicated by the Activity Type Id 20
- Licence
- MIT License
- Published
- Sep 16, 2026
- Upstream
- 58688058-68b2-4b39-8009-ac6dc4d81ea1
Detects when a api token has been created.
- Licence
- MIT License
- Published
- Sep 16, 2026
- Upstream
- 603a6b18-b54a-43b7-bb61-d2b0b47d224a
Detects when a machine is removed from protection.
- Licence
- MIT License
- Published
- Sep 16, 2026
- Upstream
- a4ce12ca-d01d-460a-b15e-6c74ef328b82
Identifies potential hijacking of the Microsoft Update Orchestrator Service to establish persistence with an integrity level of SYSTEM.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 265db8f5-fc73-4d0d-b434-6483b56372e2
Identifies suspicious use of whoami.exe which displays user, group, and privileges information for the user who is currently logged on to the local system.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- ef862985-3f13-4262-a686-5f357bbb9bc2
Identifies newly observed execution of SoftPerfect Network Scanner or Advanced IP/Port Scanner on a Windows host. Adversaries commonly use these legitimate scanners during post-compromise discovery to map live hosts, open ports, and reachable systems, then select targets for lateral movement.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 64037f09-7bf0-4051-ab51-b6daa1d853c6
Identifies abuse of the Console Window Host (conhost.exe) to execute commands via proxy. This behavior is used as a defense evasion technique to blend-in malicious activity with legitimate Windows software.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- fcd16fe8-eb29-42b3-8aee-6c9ad777a2f6
Identifies remote access to the Windows Protected Storage Service through the IPC$ share. Attackers may abuse this named pipe to interact with the Protected Storage Service and extract sensitive credentials, certificates, or DPAPI backup keys.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 9bed06f5-0c32-488a-9353-d565fc9d1573
Identifies a Windows Installer package (MSI) originating from the internet, which when executed, installs a recognized RMM product. Attackers use RMMs commonly in social engineering campaigns to gain access and control over the victim's system. This rule does not establish that the origin, installer, or RMM product is inherently malicious. It also excludes installations covered by the companion rule "RMM Software Installation from a Commonly Abused Web Service".
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 7dd15e54-0e23-4e99-80e7-6651ef7ce9d5
Identifies Windows Installer (MSI) packages that originate from commonly abused web services and install a recognized remote monitoring and management (RMM) product. Adversaries may abuse legitimate RMM software in social engineering campaigns to gain remote access and control over victim systems. This rule does not establish that the origin, installer, or RMM product is inherently malicious.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- ed626330-f3ac-4568-b4e4-cbc296748320
Detects an MSI installer execution followed by the execution of commonly abused Remote Management Software like ScreenConnect. This behavior may indicate abuse where an attacker triggers an MSI install then connects via a guest link with a known session key.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 1b5e9d4a-7c2f-4e8b-a3d6-0f9c8e2b1a4d
Monitors for the execution of different processes that might be used by attackers for malicious intent. An alert from this rule should be investigated further, as hack tools are commonly used by blue teamers and system administrators as well.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 1df1152b-610a-4f48-9d7a-504f6ee5d9da
Adversaries may create or modify Linux firewall rules with DROP, ACCEPT, or REJECT actions to affect how a host receives or sends network traffic. This activity may be used to bypass security controls, block defensive tooling, or gain unauthorized access to the network.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- c7395bb9-9b71-49e6-aeb4-dc70b8229b97
This rule detects a memfd_create syscall event on Linux where the combination of host and process lineage (parent executable and executable path) has not been seen before. This can indicate fileless execution using memfd-backed executables.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 42663c0e-572e-4459-bf61-476a81d6aab1
This rule detects unusual DNS queries to commonly abused top level domains. Malware authors may use these domains to host command and control infrastructure, exfiltrate data, or to download payloads for later execution.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 44a2de72-fe41-4558-b7ec-3e42de5f0432
Identifies a one-on-one Microsoft Teams chat created by a user from a foreign tenant whose display name, member profile, or email local-part resembles IT help desk or Microsoft security staff. Adversaries abuse cross-tenant Teams external access to impersonate support personnel and socially engineer victims into granting remote access or disclosing credentials.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- e8e7b6b6-78b0-4015-97fe-c2f28468e0d4
Identifies a burst of failed inbound SSH authentication attempts on a macOS host followed shortly by a successful SSH authentication on the same host, using sshd authentication messages collected by the macOS Security Events integration. A successful login immediately after repeated failures indicates that a password brute force or password spraying attack against an exposed SSH service has likely succeeded.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- f5898b1e-3071-4597-b066-43d298c7b415
Identifies a high number of failed inbound SSH authentication attempts on a macOS host within a short time window, using sshd authentication messages collected by the macOS Security Events integration. Adversaries may perform password brute force or password spraying against exposed SSH services to obtain unauthorized access.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 3751cc17-6e7e-4356-86d5-c8f44aab9a28
Detects when credentials issued through `AssumeRoleWithWebIdentity` for a Kubernetes service account identity are later used for several distinct AWS control-plane actions on the same session access key. Workloads that use EKS IAM Roles for Service Accounts routinely exchange a projected service-account token for short-lived IAM credentials; this rule highlights sessions where that exchange is followed by a spread of sensitive APIs—reconnaissance, secrets and parameter access, IAM changes, or
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- a1b2c3d4-e5f6-4789-a0b1-c2d3e4f5a6b7
Detects successful `AssumeRoleWithWebIdentity` where the caller identity is a Kubernetes service account and the source autonomous system organization is present but not `Amazon.com, Inc.` EKS workloads that obtain IAM credentials via IAM Roles for Service Accounts (IRSA) normally reach STS from AWS-managed or AWS-associated networks; the same identity from a clearly external ASN can indicate a stolen or misused projected service-account token being exchanged for IAM credentials off-cluster.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- ae32268b-bfd0-4c35-b002-13461b5830ca
Detects the use of curl to upload files to an internet server. Threat actors often will collect and exfiltrate data on a system to their C2 server for review. Many threat actors have been observed using curl to upload the collected data. Use of curl in this way, while not inherently malicious, should be considered highly abnormal and suspicious activity.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- be70614d-4295-473c-a953-582aef41c865
Detects HTTP requests to web servers whose URL or query string references cloud instance metadata endpoints or equivalent encoded variants. Attackers exploit server-side request forgery (SSRF) vulnerabilities in web applications to reach link-local metadata services on AWS, GCP, Azure, and similar cloud providers and harvest temporary credentials, tokens, or instance details.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 16, 2026
- Upstream
- 8670bf41-cb64-4d65-a0d6-78af17cf8f30
This rule assists in detecting rare user agents, which may indicate web browsing activity by an unconventional process different from the usual ones. The rule specifically searches for UserAgent strings that have not been seen in the past 14 days. This query will perform better when run over summarized data
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 2d50d937-d7f2-4c05-b151-9af7f9ec747e
This query utilizes built-in KQL anomaly detection algorithms to identify anomalous data transfers to public networks. It detects significant deviations from a baseline pattern, allowing the detection of sudden increases in data transferred to unknown public networks, which may indicate data exfiltration attempts. Investigating such anomalies is crucial. The score indicates the degree to which the data transfer deviates from the baseline value. A higher score indicates a greater deviation.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 5965d3e7-8ed0-477c-9b42-e75d9237fab0
Detects any failed event for a particular user.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 2a215222-bfc5-4858-a530-6d4088ebfa15
Detects failed events based on created time.
- Licence
- MIT License
- Published
- Sep 15, 2026
- Upstream
- 175b79ef-0fc3-4b27-b92a-89b2db6c85c2
Potential SSH Brute Force Detected via macOS Security Events
Identifies a high number of failed inbound SSH authentication attempts on a macOS host within a short time window, using sshd authentication messages collected by the macOS Security Events integration. Adversaries may perform password brute force or password spraying against exposed SSH services to obtain unauthorized access.
ATT&CK coverage
What the source says
References
- https://themittenmac.com/detecting-ssh-activity-via-process-monitoring/
Unclassified · themittenmac.com
Tagged by the source as
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.