Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,283
detections

Showing 30 of 11,283

MediumMicrosoft Sentinel analytics
Zero Networks Segment - Outbound Block Rules Deleted

Query searches for outbound block rules deleted by non AI.

T1562
Licence
MIT License
Published
Sep 16, 2026
Upstream
d8945c8f-bba4-4e02-ad09-228b067ebcf2
MediumMicrosoft Sentinel analytics
Zero Networks Segment - Inbound Block Rules Deleted

Query searches for inbound block rules deleted by non AI.

T1562
Licence
MIT License
Published
Sep 16, 2026
Upstream
fcbbd670-d4e6-4f3a-9008-d8905e84cf79
MediumMicrosoft Sentinel analytics
Zero Networks Segment - Excessive access to a built-in group by user

A rule was created which granted a user access to a large, built-in, group of assets.

T0866T1210T1570
Licence
MIT License
Published
Sep 16, 2026
Upstream
0e68d210-a8ec-4e13-9f46-61011c020b87
MediumMicrosoft Sentinel analytics
Zero Networks Segment - Excessive access by user

Find users who gained access to the largest number of target assets in the selected time range

T0866T1210T1570
Licence
MIT License
Published
Sep 16, 2026
Upstream
3dd14edf-788d-4f42-868f-28f3208b92a9
MediumMicrosoft Sentinel analytics
Zero Networks Segment - Rare JIT Rule Creation

Identifies when a JIT Rule connection is new or rare by a given account today based on comparison with the previous 14 days. JIT Rule creations are indicated by the Activity Type Id 20

T1021
Licence
MIT License
Published
Sep 16, 2026
Upstream
58688058-68b2-4b39-8009-ac6dc4d81ea1
LowMicrosoft Sentinel analytics
Zero Networks Segment - New API Token created

Detects when a api token has been created.

T1528
Licence
MIT License
Published
Sep 16, 2026
Upstream
603a6b18-b54a-43b7-bb61-d2b0b47d224a
HighMicrosoft Sentinel analytics
Zero Networks Segement - Machine Removed from protection

Detects when a machine is removed from protection.

T1562
Licence
MIT License
Published
Sep 16, 2026
Upstream
a4ce12ca-d01d-460a-b15e-6c74ef328b82
HighElastic detection rules
Persistence via Update Orchestrator Service Hijack

Identifies potential hijacking of the Microsoft Update Orchestrator Service to establish persistence with an integrity level of SYSTEM.

T1068T1543T1543.003T1574T1574.011
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
265db8f5-fc73-4d0d-b434-6483b56372e2
LowElastic detection rules
Whoami Process Activity

Identifies suspicious use of whoami.exe which displays user, group, and privileges information for the user who is currently logged on to the local system.

T1033T1069
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
ef862985-3f13-4262-a686-5f357bbb9bc2
MediumElastic detection rules
Newly Seen Commonly Abused Network Scanner

Identifies newly observed execution of SoftPerfect Network Scanner or Advanced IP/Port Scanner on a Windows host. Adversaries commonly use these legitimate scanners during post-compromise discovery to map live hosts, open ports, and reachable systems, then select targets for lateral movement.

T1018T1046
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
64037f09-7bf0-4051-ab51-b6daa1d853c6
HighElastic detection rules
Proxy Execution via Console Window Host

Identifies abuse of the Console Window Host (conhost.exe) to execute commands via proxy. This behavior is used as a defense evasion technique to blend-in malicious activity with legitimate Windows software.

T1059T1059.001T1059.003T1202
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
fcd16fe8-eb29-42b3-8aee-6c9ad777a2f6
HighElastic detection rules
Protected Storage Service Access via SMB

Identifies remote access to the Windows Protected Storage Service through the IPC$ share. Attackers may abuse this named pipe to interact with the Protected Storage Service and extract sensitive credentials, certificates, or DPAPI backup keys.

T1021T1021.002T1552T1552.004T1555
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
9bed06f5-0c32-488a-9353-d565fc9d1573
LowElastic detection rules
RMM Software Installation from an Internet-Originated MSI

Identifies a Windows Installer package (MSI) originating from the internet, which when executed, installs a recognized RMM product. Attackers use RMMs commonly in social engineering campaigns to gain access and control over the victim's system. This rule does not establish that the origin, installer, or RMM product is inherently malicious. It also excludes installations covered by the companion rule "RMM Software Installation from a Commonly Abused Web Service".

T1105T1218T1218.007T1219T1219.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
7dd15e54-0e23-4e99-80e7-6651ef7ce9d5
MediumElastic detection rules
RMM Software Installation from a Commonly Abused Web Service

Identifies Windows Installer (MSI) packages that originate from commonly abused web services and install a recognized remote monitoring and management (RMM) product. Adversaries may abuse legitimate RMM software in social engineering campaigns to gain remote access and control over victim systems. This rule does not establish that the origin, installer, or RMM product is inherently malicious.

T1105T1218T1218.007T1219T1219.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
ed626330-f3ac-4568-b4e4-cbc296748320
MediumElastic detection rules
Remote Management Access Launch After MSI Install

Detects an MSI installer execution followed by the execution of commonly abused Remote Management Software like ScreenConnect. This behavior may indicate abuse where an attacker triggers an MSI install then connects via a guest link with a known session key.

T1219T1219.002
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
1b5e9d4a-7c2f-4e8b-a3d6-0f9c8e2b1a4d
MediumElastic detection rules
Potential Linux Hack Tool Launched

Monitors for the execution of different processes that might be used by attackers for malicious intent. An alert from this rule should be investigated further, as hack tools are commonly used by blue teamers and system administrators as well.

T1046T1057T1082T1110T1110.001+5 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
1df1152b-610a-4f48-9d7a-504f6ee5d9da
LowElastic detection rules
Linux Firewall Rule Creation or Modification

Adversaries may create or modify Linux firewall rules with DROP, ACCEPT, or REJECT actions to affect how a host receives or sends network traffic. This activity may be used to bypass security controls, block defensive tooling, or gain unauthorized access to the network.

T1562T1562.004
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
c7395bb9-9b71-49e6-aeb4-dc70b8229b97
MediumElastic detection rules
Potential Fileless Execution via Unusual memfd Create Call

This rule detects a memfd_create syscall event on Linux where the combination of host and process lineage (parent executable and executable path) has not been seen before. This can indicate fileless execution using memfd-backed executables.

T1055T1055.009T1106T1620
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
42663c0e-572e-4459-bf61-476a81d6aab1
LowElastic detection rules
Unusual DNS Request to Suspicious Top Level Domain

This rule detects unusual DNS queries to commonly abused top level domains. Malware authors may use these domains to host command and control infrastructure, exfiltrate data, or to download payloads for later execution.

T1071T1071.004T1090T1090.002T1102+8 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
44a2de72-fe41-4558-b7ec-3e42de5f0432
HighElastic detection rules
M365 Teams Rogue Help Desk Chat Created

Identifies a one-on-one Microsoft Teams chat created by a user from a foreign tenant whose display name, member profile, or email local-part resembles IT help desk or Microsoft security staff. Adversaries abuse cross-tenant Teams external access to impersonate support personnel and socially engineer victims into granting remote access or disclosing credentials.

T1566T1566.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
e8e7b6b6-78b0-4015-97fe-c2f28468e0d4
HighElastic detection rules
Potential Successful SSH Brute Force Attack via macOS Security Events

Identifies a burst of failed inbound SSH authentication attempts on a macOS host followed shortly by a successful SSH authentication on the same host, using sshd authentication messages collected by the macOS Security Events integration. A successful login immediately after repeated failures indicates that a password brute force or password spraying attack against an exposed SSH service has likely succeeded.

T1078T1078.003T1110T1110.001T1110.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
f5898b1e-3071-4597-b066-43d298c7b415
LowElastic detection rules
Potential SSH Brute Force Detected via macOS Security Events

Identifies a high number of failed inbound SSH authentication attempts on a macOS host within a short time window, using sshd authentication messages collected by the macOS Security Events integration. Adversaries may perform password brute force or password spraying against exposed SSH services to obtain unauthorized access.

T1110T1110.001T1110.003T1133
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
3751cc17-6e7e-4356-86d5-c8f44aab9a28
HighElastic detection rules
AWS Lateral Movement from Kubernetes SA via AssumeRoleWithWebIdentity

Detects when credentials issued through `AssumeRoleWithWebIdentity` for a Kubernetes service account identity are later used for several distinct AWS control-plane actions on the same session access key. Workloads that use EKS IAM Roles for Service Accounts routinely exchange a projected service-account token for short-lived IAM credentials; this rule highlights sessions where that exchange is followed by a spread of sensitive APIs—reconnaissance, secrets and parameter access, IAM changes, or

T1021T1021.007T1526T1550T1550.001+2 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
a1b2c3d4-e5f6-4789-a0b1-c2d3e4f5a6b7
HighElastic detection rules
AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN

Detects successful `AssumeRoleWithWebIdentity` where the caller identity is a Kubernetes service account and the source autonomous system organization is present but not `Amazon.com, Inc.` EKS workloads that obtain IAM credentials via IAM Roles for Service Accounts (IRSA) normally reach STS from AWS-managed or AWS-associated networks; the same identity from a clearly external ASN can indicate a stolen or misused projected service-account token being exchanged for IAM credentials off-cluster.

T1078T1078.004
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
ae32268b-bfd0-4c35-b002-13461b5830ca
MediumElastic detection rules
Potential Data Exfiltration Through Curl

Detects the use of curl to upload files to an internet server. Threat actors often will collect and exfiltrate data on a system to their C2 server for review. Many threat actors have been observed using curl to upload the collected data. Use of curl in this way, while not inherently malicious, should be considered highly abnormal and suspicious activity.

T1048T1048.001T1048.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
be70614d-4295-473c-a953-582aef41c865
MediumElastic detection rules
Web Server Cloud Metadata SSRF Request

Detects HTTP requests to web servers whose URL or query string references cloud instance metadata endpoints or equivalent encoded variants. Attackers exploit server-side request forgery (SSRF) vulnerabilities in web applications to reach link-local metadata services on AWS, GCP, Azure, and similar cloud providers and harvest temporary credentials, tokens, or instance details.

T1190T1552T1552.005
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 16, 2026
Upstream
8670bf41-cb64-4d65-a0d6-78af17cf8f30
MediumMicrosoft Sentinel analytics
Detect presence of uncommon user agents in web requests (ASIM Web Session)

This rule assists in detecting rare user agents, which may indicate web browsing activity by an unconventional process different from the usual ones. The rule specifically searches for UserAgent strings that have not been seen in the past 14 days. This query will perform better when run over summarized data

T1133T1190
Licence
MIT License
Published
Sep 15, 2026
Upstream
2d50d937-d7f2-4c05-b151-9af7f9ec747e
MediumMicrosoft Sentinel analytics
Detect unauthorized data transfers using timeseries anomaly (ASIM Web Session)

This query utilizes built-in KQL anomaly detection algorithms to identify anomalous data transfers to public networks. It detects significant deviations from a baseline pattern, allowing the detection of sudden increases in data transferred to unknown public networks, which may indicate data exfiltration attempts. Investigating such anomalies is crucial. The score indicates the degree to which the data transfer deviates from the baseline value. A higher score indicates a greater deviation.

T1030
Licence
MIT License
Published
Sep 15, 2026
Upstream
5965d3e7-8ed0-477c-9b42-e75d9237fab0
HighMicrosoft Sentinel analytics
SailPointIdentityNowUserWithFailedEvent

Detects any failed event for a particular user.

T1133
Licence
MIT License
Published
Sep 15, 2026
Upstream
2a215222-bfc5-4858-a530-6d4088ebfa15
HighMicrosoft Sentinel analytics
SailPointIdentityNowFailedEventsBasedOnTime

Detects failed events based on created time.

T1133
Licence
MIT License
Published
Sep 15, 2026
Upstream
175b79ef-0fc3-4b27-b92a-89b2db6c85c2
Load more detections

Potential Successful SSH Brute Force Attack via macOS Security Events

Identifies a burst of failed inbound SSH authentication attempts on a macOS host followed shortly by a successful SSH authentication on the same host, using sshd authentication messages collected by the macOS Security Events integration. A successful login immediately after repeated failures indicates that a password brute force or password spraying attack against an exposed SSH service has likely succeeded.

ATT&CK coverage

Detection requirements

Log source category
event_index

What the source says

Tagged by the source as

Data Source: macOS Security EventsOS: macOSResources: Investigation GuideTactic: Credential AccessTactic: Initial AccessUse Case: Threat Detection

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice