Unknown detection rules
Every published rule under Unknown, with the source it came from, the licence it carries and the ATT&CK techniques it covers.
- 146
- matching detections
Showing 30 of 146
Spot connections to rarely accessed external domains that are present in your watchlist, which could signify data exfiltration attempts or C2 communication.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- deb99c6f-1903-455b-bb2c-0036614110bc
Query to match common security log identifiers with IOCs held by the Cyware Intel watchlist that is created automatically by Cyware
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 61c99147-b749-4164-80b1-c4bfa4efa704
Query identifies users denied registration for multiple webinars or recordings but successfully registered for at least one event. Threshold variable adjusts number of events user needs to be rejected from.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 47559078-dc4c-4de3-96fe-270d4ca95446
Identifies when rundll32 or cmd.exe is utilized to launch a malicious DLL or executable from explorer.exe. Indicative of a cmd window or LNK file executing a program or malware due to a user clicking on a file.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 3bc6e8ef-9e08-4626-89e9-fda87866cc82
Identifies VBScript proxy execution through a registry key in \Microsoft\Windows\CurrentVersion.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 3ac1e703-3ed0-45e1-ae1d-0fa60baf99fb
Hunts for commonly utilized Microsoft programs (Word, Excel, Publisher, etc) and other programs known to malicious launch powershell or cmd, such as Internet Explorer, Chrome and Firefox.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- fc36d683-385a-4ec2-842d-2982dbed97a4
Looks for valid variations of the -EncodedCommand parameter. Commonly used to encode or obfuscate commands, and not all occurrences are malicious.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- d2d3bbc2-6e57-4043-ab24-988a6a6c88db
Detects PowerShell commands downloading and execute code hosted on Pastebin and other services. This technique has been used by malicious actors to distribute malware, in particular it has been used by the EvilCorp Ransomware variants such as Sodinokibi.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- e186a8af-3d4a-4003-93b7-9b199e0b1dd1
Detect the aftermath of a successfully delivered and executed maldoc (Microsoft Office). Indicates an Office document was opened from an email or download/link, spawned a suspicious execution, and attempted to execute code via common Windows binaries.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- b194088b-c846-4c72-a4b7-933627878db4
Meant to detect process creations containing names consistent with the schema used by Metasploit or Impacket's PsExec tool. Metasploit and Impacket's PsExec tooling is used by malicious actors for lateral movement & performing actions on remote systems.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 37cba0d1-8aa5-4f8f-bb26-25a45475ca9a
Identifies WerFault.exe creating a memory dump of lsass.exe (Local Security Authority Subsystem Service, a process responsible for the enforcement of security policies on Windows systems, which generates and stores credentials in its process memory).
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 4894a60b-d2ee-4f24-be61-0d0c96a84e63
Utilizes a list of commonly abused LOLB an attacker or malware would execute in quick succession. The presence of multiple executions of the programs within the list can be indicative of an infection or malicious activity occurring on a victim host.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 6d1c9f13-e43e-4b52-a443-5799465d573b
Identify potential new registry key name that is a non-autorun and non-run key in the HKLM\Software\Microsoft\Windows\CurrentVersion\ registry key containing VBScript in the key value value.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- d7233f14-4705-403e-9db9-e0d677c9506b
View Cybersixgill Actionable alerts for last 30 days
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 532133dd-a8ed-4062-bf0d-f04dc97bb71a
This query identifies instances when public IP addresses are assigned to Azure Resources and show connections to those resources.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 8d5996b2-7d4c-4dcf-bb0d-0d7fdf0e2c75
This query identifies instances where a user is added and subsequently removed from an Azure Key Vault access policy within a short duration, which could indicate attempts to credential access and persistence.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 8eff7055-9138-4edc-b8f0-48ea27e23c3c
This query identifies when a new user is granted access and starts granting access to other users. This can help you identify rogue or malicious user behavior.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 2b6a3882-d601-4298-983b-880f6dc7acdb
This query identifies sign-ins from non-compliant or MFA-less devices to privileged accounts using a pre-built watchlist. Microsoft Sentinel offers customizable watchlist templates for your environment.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- a73c52f2-b3a5-4fe4-be7d-4d59b8558590
This query tracks sign-ins via Nord VPN using a daily-updated API. Investigate unfamiliar sign-ins from VPNs unless common in your organization. It now includes UEBA logs IdentityInfo and BehaviorAnalytics for context.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- cdc9b092-8a16-4559-9e5e-831877e8209a
This query finds successful logons from known VPS providers with suspicious token patterns. It's not exhaustive but covers prevalent providers. Now includes UEBA logs IdentityInfo and BehaviorAnalytics for context.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 86490334-5371-40a2-971a-3749c2654954
This query searches for failed sign-in attempts to disabled accounts summarized by the IP originating IP address.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 0cd51b2e-d3b2-4001-8e3f-5cbb604f69b2
This query searches for failed attempts to sign-in to disabled accounts summarized by account name. This query has also been updated to include UEBA logs IdentityInfo and BehaviorAnalytics for contextual information around the results.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- b00f127c-46fa-40bd-9ab6-b266974d29cc
This query finds AD applications with EWS permissions to read user mailboxes. Threat actors could misuse these for persistent mailbox access. Ensure these permissions are legitimately granted and necessary.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- c7941212-4ff9-4d2d-b38d-54d78fa087cc
Query searches for operations with Write and Execute accesses.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 3882ffbf-6228-4e1f-ab8f-8d79a26da0fb
Query searches for sources of network scans in Claroty telemetry to identify potentially hostile reconnaissance activity.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 6c43a50e-2e59-48d9-848b-825f50927bbf
Query searches for conflicting assets.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 8038c683-f4dc-481e-94c6-f906d880b0ec
Shows requests to URL where UrlCategory is not set.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- de2ec986-ee24-465f-adf2-b718997074c1
Shows allowed requests to URI categories which heavily are used in Initial Access stage by threat actiors and may contain malicious content.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- daf2f3cf-0f0d-45c1-b428-3c23d643859b
A normal user activity consists mostly of downloading data. Uploaded data is usually small unless there is a file/data upload to a website. Calculate the sum of BytesOut per Source-Destination pair over 12/24 hours.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 497d7250-87e1-49b1-a096-94f61c7ade9c
Calculate the count of BytesIn per Source-Destination pair over 12/24 hours. Higher values may indicate beaconing. C2 servers reply with the same data, making BytesIn value the same.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 85421f18-2de4-42ff-9ef4-058924dcb1bf