Sunturai

Detection catalogue

Explore published rules with transparent provenance, licensing, and ATT&CK mappings.

11,326
detections

Showing 30 of 11,326

MediumMicrosoft Sentinel analytics
Netskope Client - Private Access disabled by user

Detects Netskope Client devices where the user disabled the Netskope Private Access (NPA) service. All matching client-status events in the 6-hour window are collected into a single alert, grouped per device, so repeated disable events on the same device are reported once. A user disabling Private Access removes zero-trust access controls from the device.

T1562
Licence
MIT License
Published
Sep 26, 2026
Upstream
8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41
MediumMicrosoft Sentinel analytics
Netskope Client - Internet Security disabled by user

Detects Netskope Client devices where the user disabled the Netskope Internet Security (secure web gateway / CASB steering) service. All matching client-status events in the 6-hour window are collected into a single alert, grouped per device, so repeated disable events on the same device are reported once. A user disabling Internet Security bypasses web, threat and data protection policies for that device.

T1562
Licence
MIT License
Published
Sep 26, 2026
Upstream
3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8
HighMicrosoft Sentinel analytics
Netskope - High Severity DLP Alert

Detects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity. These alerts indicate sensitive data (e.g. PII, source code, financial records) matched a DLP policy during upload, download, or sharing and may represent data exfiltration.

T1005T1567
Licence
MIT License
Published
Sep 26, 2026
Upstream
04e36dfa-05b3-45bd-b39f-28b6fac71337
MediumElastic detection rules
Temporarily Scheduled Task Creation

Indicates the creation and deletion of a scheduled task within a short time interval. Adversaries can use these to proxy malicious execution via the schedule service and perform clean up.

T1053T1053.005
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 26, 2026
Upstream
81ff45f8-f8c2-4e28-992e-5a0e8d98e0fe
HighElastic detection rules
Potential ClickFix Command via Windows Run Dialog

Identifies suspicious commands written to the Windows Run dialog history (RunMRU) by explorer.exe. Adversaries socially engineer users to copy and paste malicious commands for execution, a pattern commonly seen in Fake CAPTCHA (ClickFix) campaigns. Investigate the process tree for a child of explorer.exe that matches the stored command.

T1059T1059.001T1059.003T1105T1204+5 more
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 26, 2026
Upstream
856a31f9-7869-4a5f-aca8-275a77629f19
LowElastic detection rules
Mark-of-the-Web Removal by an Unusual Process

Identifies an unusual process deleting the Zone.Identifier alternate data stream from an executable or Windows Installer package. Attackers can remove this stream to bypass Mark-of-the-Web protections.

T1553T1553.005
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 26, 2026
Upstream
757371cd-5e9e-4adb-bc4e-d81f0ad0ec4d
HighElastic detection rules
Network Connection to OAST Domain via Script Interpreter

Detects when a package service such as npm, gems, or a script interpreter makes an outbound network connection to an OAST (Out-of-band Application Security Testing) domain. Threat actors have been using OAST domains to exfiltrate sensitive data from compromised systems via malicious packages.

T1059T1102T1195T1195.001T1567
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 26, 2026
Upstream
54214c47-be7c-4f6b-8ef2-78832f9f8f42
HighSigmaHQ
Potential Arbitrary File Download Using Office Application

Detects potential arbitrary file download using a Microsoft Office application

T1202
Licence
Detection Rule License 1.1
Written by
Nasreddine Bencherchali (Nextron Systems) +2
Published
Sep 26, 2026
Upstream
4ae3e30b-b03f-43aa-87e3-b622f4048eed
MediumSplunk security content
Azure AD User Consent Blocked for Risky Application

The following analytic detects instances where Azure AD has blocked a user's attempt to grant consent to a risky or potentially malicious application. This detection leverages Azure AD audit logs, focusing on user consent actions and system-driven blocks. Monitoring these blocked consent attempts is crucial as it highlights potential threats early on, indicating that a user might be targeted or that malicious applications are attempting to infiltrate the organization.

T1528
Licence
Apache License 2.0
Written by
Mauricio Velazco +1
Published
Sep 25, 2026
Upstream
06b8ec9a-d3b5-4882-8f16-04b4d10f5eab
MediumSplunk security content
Azure AD OAuth Application Consent Granted By User

The following analytic detects when a user in an Azure AD environment grants consent to an OAuth application. It leverages Azure AD audit logs to identify events where users approve application consents. This activity is significant as it can expose organizational data to third-party applications, a common tactic used by malicious actors to gain unauthorized access. If confirmed malicious, this could lead to unauthorized access to sensitive information and resources.

T1528
Licence
Apache License 2.0
Written by
Mauricio Velazco +1
Published
Sep 25, 2026
Upstream
10ec9031-015b-4617-b453-c0c1ab729007
MediumMicrosoft Sentinel analytics
Check Point Exposure Management - Argos alerts to incidents

Creates a Microsoft Sentinel incident for each Check Point Exposure Management alert that reaches the argsentdc_CL table as open or acknowledged for the first time. Each result becomes its own alert, and ref_id is surfaced as a Custom Detail so the Exporter, ManualStatusUpdate and InboundStatusSync playbooks can map the incident back to the originating Argos alert. The CCP data connector polls on update_date, so every change to an Argos alert adds a new row for the same ref_id.

T1036T1566
Licence
MIT License
Published
Sep 25, 2026
Upstream
2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36
MediumMicrosoft Sentinel analytics
Check Point Exposure Management - Alert Ingestion Anomaly

Detects when no Check Point Exposure Management alerts have been ingested into the argsentdc_CL table for an extended period. This may indicate a failure in the CCP data connector, a misconfigured API token, or network connectivity issues.

T1562
Licence
MIT License
Published
Sep 25, 2026
Upstream
8d3b9c7e-5a2f-4e1d-b6c8-3f9a7e2d1b4c
CriticalSigmaHQ
HackTool - Dumpert Process Dumper Execution

Detects the use of Dumpert process dumper, which dumps the lsass.exe process memory

T1003.001
Licence
Detection Rule License 1.1
Written by
Florian Roth (Nextron Systems)
Published
Sep 25, 2026
Upstream
2704ab9e-afe2-4854-a3b1-0c0706d03578
LowSigmaHQ
Potential PowerShell Obfuscation Using Alias Cmdlets

Detects Set-Alias or New-Alias cmdlet usage. Which can be use as a mean to obfuscate PowerShell scripts

T1027T1059.001
Licence
Detection Rule License 1.1
Written by
frack113
Published
Sep 25, 2026
Upstream
96cd126d-f970-49c4-848a-da3a09f55c55
HighSigmaHQ
Potential Netcat Reverse Shell Execution

Detects execution of netcat with the "-e" or "-c" flags followed by common shells, which are commonly used to spawn reverse shells.

T1059
Licence
Detection Rule License 1.1
Written by
@d4ns4n_ +1
Published
Sep 25, 2026
Upstream
7f734ed0-4f47-46c0-837f-6ee62505abd9
MediumSigmaHQ
Persistence Via Sudoers Files

Detects the creation or modification of the main "/etc/sudoers" file or files within the "/etc/sudoers.d/" directory on Linux systems. Adversaries may alter sudoers configuration to execute commands with elevated privileges without supplying a password.

T1548.003
Licence
Detection Rule License 1.1
Written by
Nasreddine Bencherchali (Nextron Systems)
Published
Sep 25, 2026
Upstream
ddb26b76-4447-4807-871f-1b035b2bfa5d
MediumSigmaHQ
Suspicious Login Activity Classified By Google

Detects Google Workspace login activity that's classified as suspicious by Google.

T1078.004
Licence
Detection Rule License 1.1
Written by
Tom Kluter
Published
Sep 25, 2026
Upstream
38360161-76c4-4283-842e-efcf997dafc8
HighElastic detection rules
Anthropic Primary Owner Transferred

Primary ownership is the highest administrative authority in an Anthropic organization, covering billing, membership, and organization-wide settings. Transferring ownership to an attacker-controlled account can lock out the legitimate administrator from recovery paths that depend on the original owner. Attackers often do this after role escalation so defenders cannot reverse earlier privilege changes through normal administration.

T1098T1098.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
b39aa7b1-b77a-4bd0-84fc-b638ccb29224
MediumElastic detection rules
Anthropic Sensitive Claude Project Role Assigned to User

Detects when a Claude project owner or editor role is granted through a `role_assignment_granted` event. Project owners and editors can access project chats, artifacts, and knowledge bases that may hold sensitive data. An attacker with organization access can grant these roles to persist access to high-value project content without holding organization admin privileges.

T1098T1098.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
28a17de8-c18e-4672-8953-2c2716a3f7b4
MediumElastic detection rules
Anthropic Organization User Invite Sent

Sending an organization user invite creates a path for a new member to join the Anthropic tenant with a chosen role. An adversary who compromises an administrator or admin API key can invite a mailbox they control and accept the invite to gain durable access. Invites may target internal corporate addresses or external domains; this rule does not distinguish them because invite events do not carry verified organization domains for reliable comparison.

T1136T1136.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
5fd313e8-c61c-4737-88f7-b452a2f25a3b
HighElastic detection rules
Anthropic Organization Domain Boundary Changed

Verified organization domains control which email addresses can join or be pulled into an Anthropic tenant. Verifying, claiming, adding, or removing a domain changes the tenant boundary and can pull in attacker-controlled mailboxes or push out legitimate corporate domains. These events are infrequent and affect organization-wide membership trust.

T1098
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
fb3b43e2-0358-4bd0-b8b6-569d7c2baed1
MediumElastic detection rules
Anthropic MCP Server Created

Detects the first successful creation of a Model Context Protocol (MCP) server integration name in an Anthropic organization within the rule history window. MCP servers add external data pathways into Claude and can expose organizational data to third-party infrastructure. This is a New Terms rule keyed on `organization.id` and `anthropic.audit.

T1176
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
e3acc6d4-cd6e-4748-baeb-1c57a0f37635
HighElastic detection rules
Anthropic Compliance API Key Created

Compliance-scoped API keys read organization audit activity and compliance data. Once an attacker has administrative access, creating one gives them programmatic read of chats, files, and membership without an interactive session. This is separate from admin API key creation, which covers organization administration rather than compliance read scopes.

T1098T1098.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
b8c429a1-67f3-448c-a960-951807dd2cd8
HighElastic detection rules
Anthropic Admin Role Assigned to User

The organization admin role controls organization settings, integrations, membership, and security configuration in Anthropic Claude for Enterprise. Membership role changes are reported as `claude_user_role_updated` with `anthropic.audit.current_role`. An attacker can promote a compromised or newly invited account to org admin to turn initial access into durable control-plane access.

T1098T1098.003
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
f280afaf-332a-40c9-9213-8e2e717ed320
MediumElastic detection rules
Anthropic Admin API Key Created

Admin API keys grant programmatic access to organization and compliance APIs outside an interactive browser session. An attacker who creates one after compromise can automate role grants, exports, and logging changes without holding a user session that would time out under SSO. The key also survives password resets and IdP lockout if defenders revoke the interactive account but miss the API credential.

T1098T1098.001
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
4051e709-03b6-4782-aae3-e58dde33642b
HighElastic detection rules
Anthropic Impossible Travel Login

Detects successful Anthropic magic link or SSO sign-ins for the same user email from source IP addresses whose query-time geo-locations (via IP_LOCATION) are separated by at least 1,000 km, with implied travel faster than 800 km/h, within a 24-hour window. That pattern can indicate account sharing, VPN or proxy egress mismatches, or an adversary authenticating from a geography far from the legitimate user's baseline.

T1078T1078.004
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
e89e4744-039e-4290-9835-63ea42fe531e
CriticalElastic detection rules
Anthropic Organization Deletion

Organization deletion and bulk delete remove tenant data, projects, and member access in a single administrative action. An attacker can use this to break AI-assisted workflows as an impact technique, to extort the organization, or to destroy evidence after finishing a data export. Once deletion progresses, recovery options shrink and earlier exfiltration activity is harder to reconstruct from the tenant itself.

T1485T1531
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
11347993-e71f-4659-a903-e9a0e8bd55de
MediumElastic detection rules
Anthropic Extra Usage Spend Limit Deleted

Extra usage spend limits cap Anthropic organizational spend beyond included usage. Deleting a spend limit removes that cap and can enable unrestricted API or Claude consumption. An attacker who already has administrative or API access can delete the limit to burn budget, run large automated workloads, or stage resource abuse without the previous guardrail.

T1496
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
9a944f66-417d-4dee-83a2-afd3f7980212
MediumElastic detection rules
Anthropic Excessive Chat Creation

Detects an unusually high number of Claude chat creation events for the same user email within a 24-hour period. Burst chat creation can indicate automated LLM abuse, resource hijacking to burn organizational quotas, or scripted workflows used to stage many parallel conversations for data processing or prompt-injection campaigns.

T1496
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
854d9932-93c3-42d4-bab0-7723a91df397
MediumElastic detection rules
Anthropic Admin API Key Deleted

Admin API keys grant programmatic access to organization and compliance APIs. An attacker can delete legitimate admin API keys to break security monitoring or integrations, or to cover tracks after creating replacement credentials they control. Deletion without a nearby rotation event points more at sabotage than routine key hygiene.

T1531
Licence
Elastic License 2.0
Written by
Elastic
Published
Sep 24, 2026
Upstream
590b6961-e9d5-4ca9-ade0-978c1755a944
Load more detections

Anthropic Multiple Authentication Failures

Detects at least five failed Anthropic authentication events for the same user email within one hour. Failures are matched by authentication category and failure outcome (for example magic-link or SSO login failures). That pattern fits repeated guessing, stale magic link abuse, or automated login attempts against one account.

ATT&CK coverage

What the source says

What fires this without an attack behind it

  • A user repeatedly clicking an expired or invalid magic link from the same browser session can produce several failures before requesting a new link or signing in successfully.
  • IdP or SSO cutover testing against a pilot account can generate a short burst of failed attempts for one email during maintenance windows.

References

Tagged by the source as

Data Source: Anthropic Audit LogsDomain: GenAIDomain: IdentityPlatform: AnthropicResources: Investigation GuideRule Type: ES|QLTactic: Credential AccessUse Case: Identity and Access AuditUse Case: Threat DetectionUse Case: UEBA

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice