sunturai

Unknown detection rules

Every published rule under Unknown, with the source it came from, the licence it carries and the ATT&CK techniques it covers.

146
matching detections

Showing 30 of 146

UnknownMicrosoft Sentinel analytics
Detecting Suspicious PowerShell Command Executions

Spot connections to rarely accessed external domains that are present in your watchlist, which could signify data exfiltration attempts or C2 communication.

T1102
Licence
MIT
Published
Aug 29, 2026
Upstream
deb99c6f-1903-455b-bb2c-0036614110bc
UnknownMicrosoft Sentinel analytics
Match Cyware Intel Watchlist Items With Common Logs

Query to match common security log identifiers with IOCs held by the Cyware Intel watchlist that is created automatically by Cyware

T0853T0863
Licence
MIT
Published
Aug 29, 2026
Upstream
61c99147-b749-4164-80b1-c4bfa4efa704
UnknownMicrosoft Sentinel analytics
Detecting Suspicious PowerShell Command Executions

Query identifies users denied registration for multiple webinars or recordings but successfully registered for at least one event. Threshold variable adjusts number of events user needs to be rejected from.

T1059
Licence
MIT
Published
Aug 29, 2026
Upstream
47559078-dc4c-4de3-96fe-270d4ca95446
UnknownMicrosoft Sentinel analytics
Rundll32 or cmd Executing Application from Explorer - Potential Malware Execution Chain

Identifies when rundll32 or cmd.exe is utilized to launch a malicious DLL or executable from explorer.exe. Indicative of a cmd window or LNK file executing a program or malware due to a user clicking on a file.

T1204.002
Licence
MIT
Published
Aug 29, 2026
Upstream
3bc6e8ef-9e08-4626-89e9-fda87866cc82
UnknownMicrosoft Sentinel analytics
Proxy VBScript Execution via CurrentVersion Registry Key

Identifies VBScript proxy execution through a registry key in \Microsoft\Windows\CurrentVersion.

T1059.005T1218.005
Licence
MIT
Published
Aug 29, 2026
Upstream
3ac1e703-3ed0-45e1-ae1d-0fa60baf99fb
UnknownMicrosoft Sentinel analytics
Prohibited Applications Spawning cmd.exe or powershell.exe

Hunts for commonly utilized Microsoft programs (Word, Excel, Publisher, etc) and other programs known to malicious launch powershell or cmd, such as Internet Explorer, Chrome and Firefox.

T1102
Licence
MIT
Published
Aug 29, 2026
Upstream
fc36d683-385a-4ec2-842d-2982dbed97a4
UnknownMicrosoft Sentinel analytics
Powershell Encoded Command Execution

Looks for valid variations of the -EncodedCommand parameter. Commonly used to encode or obfuscate commands, and not all occurrences are malicious.

T1027T1059.001
Licence
MIT
Published
Aug 29, 2026
Upstream
d2d3bbc2-6e57-4043-ab24-988a6a6c88db
UnknownMicrosoft Sentinel analytics
PowerShell Pastebin Download

Detects PowerShell commands downloading and execute code hosted on Pastebin and other services. This technique has been used by malicious actors to distribute malware, in particular it has been used by the EvilCorp Ransomware variants such as Sodinokibi.

T1102
Licence
MIT
Published
Aug 29, 2026
Upstream
e186a8af-3d4a-4003-93b7-9b199e0b1dd1
UnknownMicrosoft Sentinel analytics
Potential Maldoc Execution Chain Observed

Detect the aftermath of a successfully delivered and executed maldoc (Microsoft Office). Indicates an Office document was opened from an email or download/link, spawned a suspicious execution, and attempted to execute code via common Windows binaries.

T1059T1059.001T1059.004T1059.005T1059.006+4 more
Licence
MIT
Published
Aug 29, 2026
Upstream
b194088b-c846-4c72-a4b7-933627878db4
UnknownMicrosoft Sentinel analytics
Metasploit / Impacket PsExec Process Creation Activity

Meant to detect process creations containing names consistent with the schema used by Metasploit or Impacket's PsExec tool. Metasploit and Impacket's PsExec tooling is used by malicious actors for lateral movement & performing actions on remote systems.

T1569.002
Licence
MIT
Published
Aug 29, 2026
Upstream
37cba0d1-8aa5-4f8f-bb26-25a45475ca9a
UnknownMicrosoft Sentinel analytics
LSASS Memory Dumping using WerFault.exe - Command Identification

Identifies WerFault.exe creating a memory dump of lsass.exe (Local Security Authority Subsystem Service, a process responsible for the enforcement of security policies on Windows systems, which generates and stores credentials in its process memory).

T1003
Licence
MIT
Published
Aug 29, 2026
Upstream
4894a60b-d2ee-4f24-be61-0d0c96a84e63
UnknownMicrosoft Sentinel analytics
Excessive Windows Discovery and Execution Processes - Potential Malware Installation

Utilizes a list of commonly abused LOLB an attacker or malware would execute in quick succession. The presence of multiple executions of the programs within the list can be indicative of an infection or malicious activity occurring on a victim host.

T1016
Licence
MIT
Published
Aug 29, 2026
Upstream
6d1c9f13-e43e-4b52-a443-5799465d573b
UnknownMicrosoft Sentinel analytics
Attempted VBScript Stored in Non-Run CurrentVersion Registry Key Value

Identify potential new registry key name that is a non-autorun and non-run key in the HKLM\Software\Microsoft\Windows\CurrentVersion\ registry key containing VBScript in the key value value.

T1112
Licence
MIT
Published
Aug 29, 2026
Upstream
d7233f14-4705-403e-9db9-e0d677c9506b
UnknownMicrosoft Sentinel analytics
Cybersixgill Actionable alerts

View Cybersixgill Actionable alerts for last 30 days

Licence
MIT
Published
Aug 29, 2026
Upstream
532133dd-a8ed-4062-bf0d-f04dc97bb71a
UnknownMicrosoft Sentinel analytics
Azure Resources Assigned Public IP Addresses

This query identifies instances when public IP addresses are assigned to Azure Resources and show connections to those resources.

T1496
Licence
MIT
Published
Aug 29, 2026
Upstream
8d5996b2-7d4c-4dcf-bb0d-0d7fdf0e2c75
UnknownMicrosoft Sentinel analytics
Azure Key Vault Access Policy Manipulation

This query identifies instances where a user is added and subsequently removed from an Azure Key Vault access policy within a short duration, which could indicate attempts to credential access and persistence.

T1555
Licence
MIT
Published
Aug 29, 2026
Upstream
8eff7055-9138-4edc-b8f0-48ea27e23c3c
UnknownMicrosoft Sentinel analytics
User Granted Access and Grants Access to Other Users

This query identifies when a new user is granted access and starts granting access to other users. This can help you identify rogue or malicious user behavior.

T1078T1098
Licence
MIT
Published
Aug 29, 2026
Upstream
2b6a3882-d601-4298-983b-880f6dc7acdb
UnknownMicrosoft Sentinel analytics
Suspicious Sign-ins to Privileged Account

This query identifies sign-ins from non-compliant or MFA-less devices to privileged accounts using a pre-built watchlist. Microsoft Sentinel offers customizable watchlist templates for your environment.

T1078
Licence
MIT
Published
Aug 29, 2026
Upstream
a73c52f2-b3a5-4fe4-be7d-4d59b8558590
UnknownMicrosoft Sentinel analytics
Sign-ins from Nord VPN Providers

This query tracks sign-ins via Nord VPN using a daily-updated API. Investigate unfamiliar sign-ins from VPNs unless common in your organization. It now includes UEBA logs IdentityInfo and BehaviorAnalytics for context.

T1078
Licence
MIT
Published
Aug 29, 2026
Upstream
cdc9b092-8a16-4559-9e5e-831877e8209a
UnknownMicrosoft Sentinel analytics
Sign-ins From VPS Providers

This query finds successful logons from known VPS providers with suspicious token patterns. It's not exhaustive but covers prevalent providers. Now includes UEBA logs IdentityInfo and BehaviorAnalytics for context.

T1078
Licence
MIT
Published
Aug 29, 2026
Upstream
86490334-5371-40a2-971a-3749c2654954
UnknownMicrosoft Sentinel analytics
Detect Disabled Account Sign-in Attempts by IP Address

This query searches for failed sign-in attempts to disabled accounts summarized by the IP originating IP address.

T1078
Licence
MIT
Published
Aug 29, 2026
Upstream
0cd51b2e-d3b2-4001-8e3f-5cbb604f69b2
UnknownMicrosoft Sentinel analytics
Detect Disabled Account Sign-in Attempts by Account Name

This query searches for failed attempts to sign-in to disabled accounts summarized by account name. This query has also been updated to include UEBA logs IdentityInfo and BehaviorAnalytics for contextual information around the results.

T1078
Licence
MIT
Published
Aug 29, 2026
Upstream
b00f127c-46fa-40bd-9ab6-b266974d29cc
UnknownMicrosoft Sentinel analytics
Application Granted EWS Permissions

This query finds AD applications with EWS permissions to read user mailboxes. Threat actors could misuse these for persistent mailbox access. Ensure these permissions are legitimately granted and necessary.

T1078.004T1114.002
Licence
MIT
Published
Aug 29, 2026
Upstream
c7941212-4ff9-4d2d-b38d-54d78fa087cc
UnknownMicrosoft Sentinel analytics
Claroty - Write and Execute operations

Query searches for operations with Write and Execute accesses.

T1106T1190T1204
Licence
MIT
Published
Aug 29, 2026
Upstream
3882ffbf-6228-4e1f-ab8f-8d79a26da0fb
UnknownMicrosoft Sentinel analytics
Claroty - Network scan sources

Query searches for sources of network scans in Claroty telemetry to identify potentially hostile reconnaissance activity.

T1190T1595T1595.001
Licence
MIT
Published
Aug 29, 2026
Upstream
6c43a50e-2e59-48d9-848b-825f50927bbf
UnknownMicrosoft Sentinel analytics
Claroty - Conflict assets

Query searches for conflicting assets.

T1016T1190T1613
Licence
MIT
Published
Aug 29, 2026
Upstream
8038c683-f4dc-481e-94c6-f906d880b0ec
UnknownMicrosoft Sentinel analytics
Cisco Cloud Security - Requests to uncategorized resources

Shows requests to URL where UrlCategory is not set.

T1071
Licence
MIT
Published
Aug 29, 2026
Upstream
de2ec986-ee24-465f-adf2-b718997074c1
UnknownMicrosoft Sentinel analytics
Cisco Cloud Security - Proxy 'Allowed' to unreliable categories.

Shows allowed requests to URI categories which heavily are used in Initial Access stage by threat actiors and may contain malicious content.

T1189
Licence
MIT
Published
Aug 29, 2026
Upstream
daf2f3cf-0f0d-45c1-b428-3c23d643859b
UnknownMicrosoft Sentinel analytics
Cisco Cloud Security - Possible data exfiltration

A normal user activity consists mostly of downloading data. Uploaded data is usually small unless there is a file/data upload to a website. Calculate the sum of BytesOut per Source-Destination pair over 12/24 hours.

T1020
Licence
MIT
Published
Aug 29, 2026
Upstream
497d7250-87e1-49b1-a096-94f61c7ade9c
UnknownMicrosoft Sentinel analytics
Cisco Cloud Security - Possible connection to C2.

Calculate the count of BytesIn per Source-Destination pair over 12/24 hours. Higher values may indicate beaconing. C2 servers reply with the same data, making BytesIn value the same.

T1071
Licence
MIT
Published
Aug 29, 2026
Upstream
85421f18-2de4-42ff-9ef4-058924dcb1bf