Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 11,326
- detections
Showing 30 of 11,326
Detects Netskope Client devices where the user disabled the Netskope Private Access (NPA) service. All matching client-status events in the 6-hour window are collected into a single alert, grouped per device, so repeated disable events on the same device are reported once. A user disabling Private Access removes zero-trust access controls from the device.
- Licence
- MIT License
- Published
- Sep 26, 2026
- Upstream
- 8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41
Detects Netskope Client devices where the user disabled the Netskope Internet Security (secure web gateway / CASB steering) service. All matching client-status events in the 6-hour window are collected into a single alert, grouped per device, so repeated disable events on the same device are reported once. A user disabling Internet Security bypasses web, threat and data protection policies for that device.
- Licence
- MIT License
- Published
- Sep 26, 2026
- Upstream
- 3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8
Detects Netskope DLP (Data Loss Prevention) alerts raised with high or critical severity. These alerts indicate sensitive data (e.g. PII, source code, financial records) matched a DLP policy during upload, download, or sharing and may represent data exfiltration.
- Licence
- MIT License
- Published
- Sep 26, 2026
- Upstream
- 04e36dfa-05b3-45bd-b39f-28b6fac71337
Indicates the creation and deletion of a scheduled task within a short time interval. Adversaries can use these to proxy malicious execution via the schedule service and perform clean up.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 26, 2026
- Upstream
- 81ff45f8-f8c2-4e28-992e-5a0e8d98e0fe
Identifies suspicious commands written to the Windows Run dialog history (RunMRU) by explorer.exe. Adversaries socially engineer users to copy and paste malicious commands for execution, a pattern commonly seen in Fake CAPTCHA (ClickFix) campaigns. Investigate the process tree for a child of explorer.exe that matches the stored command.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 26, 2026
- Upstream
- 856a31f9-7869-4a5f-aca8-275a77629f19
Identifies an unusual process deleting the Zone.Identifier alternate data stream from an executable or Windows Installer package. Attackers can remove this stream to bypass Mark-of-the-Web protections.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 26, 2026
- Upstream
- 757371cd-5e9e-4adb-bc4e-d81f0ad0ec4d
Detects when a package service such as npm, gems, or a script interpreter makes an outbound network connection to an OAST (Out-of-band Application Security Testing) domain. Threat actors have been using OAST domains to exfiltrate sensitive data from compromised systems via malicious packages.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 26, 2026
- Upstream
- 54214c47-be7c-4f6b-8ef2-78832f9f8f42
Detects potential arbitrary file download using a Microsoft Office application
- Licence
- Detection Rule License 1.1
- Written by
- Nasreddine Bencherchali (Nextron Systems) +2
- Published
- Sep 26, 2026
- Upstream
- 4ae3e30b-b03f-43aa-87e3-b622f4048eed
The following analytic detects instances where Azure AD has blocked a user's attempt to grant consent to a risky or potentially malicious application. This detection leverages Azure AD audit logs, focusing on user consent actions and system-driven blocks. Monitoring these blocked consent attempts is crucial as it highlights potential threats early on, indicating that a user might be targeted or that malicious applications are attempting to infiltrate the organization.
- Licence
- Apache License 2.0
- Written by
- Mauricio Velazco +1
- Published
- Sep 25, 2026
- Upstream
- 06b8ec9a-d3b5-4882-8f16-04b4d10f5eab
The following analytic detects when a user in an Azure AD environment grants consent to an OAuth application. It leverages Azure AD audit logs to identify events where users approve application consents. This activity is significant as it can expose organizational data to third-party applications, a common tactic used by malicious actors to gain unauthorized access. If confirmed malicious, this could lead to unauthorized access to sensitive information and resources.
- Licence
- Apache License 2.0
- Written by
- Mauricio Velazco +1
- Published
- Sep 25, 2026
- Upstream
- 10ec9031-015b-4617-b453-c0c1ab729007
Creates a Microsoft Sentinel incident for each Check Point Exposure Management alert that reaches the argsentdc_CL table as open or acknowledged for the first time. Each result becomes its own alert, and ref_id is surfaced as a Custom Detail so the Exporter, ManualStatusUpdate and InboundStatusSync playbooks can map the incident back to the originating Argos alert. The CCP data connector polls on update_date, so every change to an Argos alert adds a new row for the same ref_id.
- Licence
- MIT License
- Published
- Sep 25, 2026
- Upstream
- 2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36
Detects when no Check Point Exposure Management alerts have been ingested into the argsentdc_CL table for an extended period. This may indicate a failure in the CCP data connector, a misconfigured API token, or network connectivity issues.
- Licence
- MIT License
- Published
- Sep 25, 2026
- Upstream
- 8d3b9c7e-5a2f-4e1d-b6c8-3f9a7e2d1b4c
Detects the use of Dumpert process dumper, which dumps the lsass.exe process memory
- Licence
- Detection Rule License 1.1
- Written by
- Florian Roth (Nextron Systems)
- Published
- Sep 25, 2026
- Upstream
- 2704ab9e-afe2-4854-a3b1-0c0706d03578
Detects Set-Alias or New-Alias cmdlet usage. Which can be use as a mean to obfuscate PowerShell scripts
- Licence
- Detection Rule License 1.1
- Written by
- frack113
- Published
- Sep 25, 2026
- Upstream
- 96cd126d-f970-49c4-848a-da3a09f55c55
Detects execution of netcat with the "-e" or "-c" flags followed by common shells, which are commonly used to spawn reverse shells.
- Licence
- Detection Rule License 1.1
- Written by
- @d4ns4n_ +1
- Published
- Sep 25, 2026
- Upstream
- 7f734ed0-4f47-46c0-837f-6ee62505abd9
Detects the creation or modification of the main "/etc/sudoers" file or files within the "/etc/sudoers.d/" directory on Linux systems. Adversaries may alter sudoers configuration to execute commands with elevated privileges without supplying a password.
- Licence
- Detection Rule License 1.1
- Written by
- Nasreddine Bencherchali (Nextron Systems)
- Published
- Sep 25, 2026
- Upstream
- ddb26b76-4447-4807-871f-1b035b2bfa5d
Detects Google Workspace login activity that's classified as suspicious by Google.
- Licence
- Detection Rule License 1.1
- Written by
- Tom Kluter
- Published
- Sep 25, 2026
- Upstream
- 38360161-76c4-4283-842e-efcf997dafc8
Primary ownership is the highest administrative authority in an Anthropic organization, covering billing, membership, and organization-wide settings. Transferring ownership to an attacker-controlled account can lock out the legitimate administrator from recovery paths that depend on the original owner. Attackers often do this after role escalation so defenders cannot reverse earlier privilege changes through normal administration.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- b39aa7b1-b77a-4bd0-84fc-b638ccb29224
Detects when a Claude project owner or editor role is granted through a `role_assignment_granted` event. Project owners and editors can access project chats, artifacts, and knowledge bases that may hold sensitive data. An attacker with organization access can grant these roles to persist access to high-value project content without holding organization admin privileges.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- 28a17de8-c18e-4672-8953-2c2716a3f7b4
Sending an organization user invite creates a path for a new member to join the Anthropic tenant with a chosen role. An adversary who compromises an administrator or admin API key can invite a mailbox they control and accept the invite to gain durable access. Invites may target internal corporate addresses or external domains; this rule does not distinguish them because invite events do not carry verified organization domains for reliable comparison.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- 5fd313e8-c61c-4737-88f7-b452a2f25a3b
Verified organization domains control which email addresses can join or be pulled into an Anthropic tenant. Verifying, claiming, adding, or removing a domain changes the tenant boundary and can pull in attacker-controlled mailboxes or push out legitimate corporate domains. These events are infrequent and affect organization-wide membership trust.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- fb3b43e2-0358-4bd0-b8b6-569d7c2baed1
Detects the first successful creation of a Model Context Protocol (MCP) server integration name in an Anthropic organization within the rule history window. MCP servers add external data pathways into Claude and can expose organizational data to third-party infrastructure. This is a New Terms rule keyed on `organization.id` and `anthropic.audit.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- e3acc6d4-cd6e-4748-baeb-1c57a0f37635
Compliance-scoped API keys read organization audit activity and compliance data. Once an attacker has administrative access, creating one gives them programmatic read of chats, files, and membership without an interactive session. This is separate from admin API key creation, which covers organization administration rather than compliance read scopes.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- b8c429a1-67f3-448c-a960-951807dd2cd8
The organization admin role controls organization settings, integrations, membership, and security configuration in Anthropic Claude for Enterprise. Membership role changes are reported as `claude_user_role_updated` with `anthropic.audit.current_role`. An attacker can promote a compromised or newly invited account to org admin to turn initial access into durable control-plane access.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- f280afaf-332a-40c9-9213-8e2e717ed320
Admin API keys grant programmatic access to organization and compliance APIs outside an interactive browser session. An attacker who creates one after compromise can automate role grants, exports, and logging changes without holding a user session that would time out under SSO. The key also survives password resets and IdP lockout if defenders revoke the interactive account but miss the API credential.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- 4051e709-03b6-4782-aae3-e58dde33642b
Detects successful Anthropic magic link or SSO sign-ins for the same user email from source IP addresses whose query-time geo-locations (via IP_LOCATION) are separated by at least 1,000 km, with implied travel faster than 800 km/h, within a 24-hour window. That pattern can indicate account sharing, VPN or proxy egress mismatches, or an adversary authenticating from a geography far from the legitimate user's baseline.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- e89e4744-039e-4290-9835-63ea42fe531e
Organization deletion and bulk delete remove tenant data, projects, and member access in a single administrative action. An attacker can use this to break AI-assisted workflows as an impact technique, to extort the organization, or to destroy evidence after finishing a data export. Once deletion progresses, recovery options shrink and earlier exfiltration activity is harder to reconstruct from the tenant itself.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- 11347993-e71f-4659-a903-e9a0e8bd55de
Extra usage spend limits cap Anthropic organizational spend beyond included usage. Deleting a spend limit removes that cap and can enable unrestricted API or Claude consumption. An attacker who already has administrative or API access can delete the limit to burn budget, run large automated workloads, or stage resource abuse without the previous guardrail.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- 9a944f66-417d-4dee-83a2-afd3f7980212
Detects an unusually high number of Claude chat creation events for the same user email within a 24-hour period. Burst chat creation can indicate automated LLM abuse, resource hijacking to burn organizational quotas, or scripted workflows used to stage many parallel conversations for data processing or prompt-injection campaigns.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- 854d9932-93c3-42d4-bab0-7723a91df397
Admin API keys grant programmatic access to organization and compliance APIs. An attacker can delete legitimate admin API keys to break security monitoring or integrations, or to cover tracks after creating replacement credentials they control. Deletion without a nearby rotation event points more at sabotage than routine key hygiene.
- Licence
- Elastic License 2.0
- Written by
- Elastic
- Published
- Sep 24, 2026
- Upstream
- 590b6961-e9d5-4ca9-ade0-978c1755a944
Anthropic Primary Owner Transferred
Primary ownership is the highest administrative authority in an Anthropic organization, covering billing, membership, and organization-wide settings. Transferring ownership to an attacker-controlled account can lock out the legitimate administrator from recovery paths that depend on the original owner. Attackers often do this after role escalation so defenders cannot reverse earlier privilege changes through normal administration.
ATT&CK coverage
What the source says
What fires this without an attack behind it
- Organizations transfer primary ownership during reorganizations, administrator departures, or vendor transitions. Verify both the previous and new owner with internal stakeholders before treating the event as malicious.
References
- https://platform.claude.com/docs/en/api/compliance/activities/list
Unclassified · platform.claude.com
Tagged by the source as
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.