sunturai

Microsoft Sentinel analytics detection rules

Every published rule under Microsoft Sentinel analytics, with the source it came from, the licence it carries and the ATT&CK techniques it covers.

1,055
matching detections

Showing 30 of 1,055

HighMicrosoft Sentinel analytics
D3 Smart SOAR - High or critical severity incident detected

Identifies when a D3 Smart SOAR incident with High or Critical severity is ingested. This helps security teams prioritize response to the most impactful incidents reported by D3 Smart SOAR.

T1499
Licence
MIT
Published
Aug 29, 2026
Upstream
48ef0be4-8240-4a03-bbb9-320b562d6ce4
UnknownMicrosoft Sentinel analytics
Detecting Suspicious PowerShell Command Executions

Spot connections to rarely accessed external domains that are present in your watchlist, which could signify data exfiltration attempts or C2 communication.

T1102
Licence
MIT
Published
Aug 29, 2026
Upstream
deb99c6f-1903-455b-bb2c-0036614110bc
UnknownMicrosoft Sentinel analytics
Match Cyware Intel Watchlist Items With Common Logs

Query to match common security log identifiers with IOCs held by the Cyware Intel watchlist that is created automatically by Cyware

T0853T0863
Licence
MIT
Published
Aug 29, 2026
Upstream
61c99147-b749-4164-80b1-c4bfa4efa704
UnknownMicrosoft Sentinel analytics
Detecting Suspicious PowerShell Command Executions

Query identifies users denied registration for multiple webinars or recordings but successfully registered for at least one event. Threshold variable adjusts number of events user needs to be rejected from.

T1059
Licence
MIT
Published
Aug 29, 2026
Upstream
47559078-dc4c-4de3-96fe-270d4ca95446
HighMicrosoft Sentinel analytics
Cyren High-Risk URL Indicators

Detects high-risk URL indicators (risk score >= 80) from Cyren malware URL threat intelligence feeds in the last 24 hours. These URLs are associated with malware distribution, phishing campaigns, or other malicious content hosting.

T1189T1566
Licence
MIT
Published
Aug 29, 2026
Upstream
6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7
HighMicrosoft Sentinel analytics
Cyren High-Risk IP Indicators

Detects high-risk IP indicators (risk score >= 80) from Cyren threat intelligence feeds in the last 24 hours. These IPs are associated with malicious activity such as malware distribution, phishing, or botnet command and control.

T1071T1568
Licence
MIT
Published
Aug 29, 2026
Upstream
5d7e8b3a-1f2c-4e5d-9a0b-c1d2e3f4a5b6
MediumMicrosoft Sentinel analytics
Cyren Feed Outage Detection

Detects when the Cyren threat intelligence feed has not ingested any data for 6 or more hours. This may indicate a connectivity issue with the data connector, API authentication problems, or upstream service disruption.

T1562
Licence
MIT
Published
Aug 29, 2026
Upstream
7f9a0d5c-3b4c-6d7e-1f2a-e3f4a5b6c7d8
HighMicrosoft Sentinel analytics
Cynerio - Suspicious Connection to External Address

Suspicious Connection to External Address

T0866
Licence
MIT
Published
Aug 29, 2026
Upstream
c0756978-baa6-4239-9174-bac1b1ca1a6a
MediumMicrosoft Sentinel analytics
Cynerio - Medical device scanning

Medical device is scanned with vulnerability scanner

T0866
Licence
MIT
Published
Aug 29, 2026
Upstream
211e9f49-3fca-4598-bc6e-e2c28d86e72c
HighMicrosoft Sentinel analytics
Cynerio - IoT - Weak password

User signed in using weak credentials

T1552
Licence
MIT
Published
Aug 29, 2026
Upstream
65db1346-6435-4079-bbf4-9a7113c98054
HighMicrosoft Sentinel analytics
Cynerio - Exploitation Attempt of IoT device

Exploitation Attempt of IoT device - Attack detection

T0866
Licence
MIT
Published
Aug 29, 2026
Upstream
3d853a88-92d2-4aec-a680-2bf7bb560c56
HighMicrosoft Sentinel analytics
Cynerio - IoT - Default password

User signed in using default credentials

T1552
Licence
MIT
Published
Aug 29, 2026
Upstream
84e0ea1f-766d-4775-836a-c0c9cca05085
MediumMicrosoft Sentinel analytics
CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule

This rule detects medium severity attack surface-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 50 or higher, excluding those categorized as 'ASSET_VULNERABILITY', and generates alerts for assets that may be at risk.

T1003T1021.002T1059T1068T1133+5 more
Licence
MIT
Published
Aug 29, 2026
Upstream
4c1b282b-62f1-4783-bf40-94c44f0ae630
HighMicrosoft Sentinel analytics
CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert

This rule detects high severity attack surface-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 80 or higher, excluding those categorized as 'ASSET_VULNERABILITY', and generates alerts for assets that may be at risk.

T1003T1021.002T1059T1068T1133+5 more
Licence
MIT
Published
Aug 29, 2026
Upstream
6cc62c46-dd44-46d7-8681-8422f780eabd
MediumMicrosoft Sentinel analytics
CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert

This rule detects medium severity asset-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 50 or higher, excluding those categorized as 'ATTACK_SURFACE_VULNERABILITY', and generates alerts for assets that may be at risk.

T1003T1021.002T1059T1068T1133+5 more
Licence
MIT
Published
Aug 29, 2026
Upstream
6306f2d9-34a3-409a-850d-175b7bdd1ab1
HighMicrosoft Sentinel analytics
CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert

This rule detects high severity asset-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 80 or higher, excluding those categorized as 'ATTACK_SURFACE_VULNERABILITY', and generates alerts for assets that may be at risk.

T1003T1021.002T1059T1068T1133+5 more
Licence
MIT
Published
Aug 29, 2026
Upstream
123fad02-6d9e-439e-8241-7a2fffa7e0a5
MediumMicrosoft Sentinel analytics
CYFIRMA - Social and Public Exposure - Source Code Exposure on Public Repositories Rule

This rule triggers when CYFIRMA detects source code related to internal or enterprise domains exposed on public platforms like GitHub. Such exposure may lead to intellectual property leakage or help adversaries understand internal systems, increasing the risk of targeted attacks.

T1082T1587.001T1606.001
Licence
MIT
Published
Aug 29, 2026
Upstream
28e315a3-725d-4261-a6c2-e597d51541f4
HighMicrosoft Sentinel analytics
CYFIRMA - Social and Public Exposure - Source Code Exposure on Public Repositories Rule

This rule triggers when CYFIRMA detects source code related to internal or enterprise domains exposed on public platforms like GitHub. Such exposure may lead to intellectual property leakage or help adversaries understand internal systems, increasing the risk of targeted attacks.

T1082T1587.001T1606.001
Licence
MIT
Published
Aug 29, 2026
Upstream
42e6f16a-7773-44cc-8668-8f648bd1aa4f
MediumMicrosoft Sentinel analytics
CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule

This rule detects medium-severity social threat alerts from CYFIRMA related to impersonation, fake profiles, or malicious activities on social platforms that may target executives, brands, or employees. These threats can result in reputational damage, phishing, or social engineering attacks. Immediate investigation and takedown are recommended to minimize risk.

T1491T1566T1582T1585.001T1593
Licence
MIT
Published
Aug 29, 2026
Upstream
b8149f2f-54da-4f7b-98e1-c01ca47e1e55
HighMicrosoft Sentinel analytics
CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule

This rule detects high-severity social threat alerts from CYFIRMA related to impersonation, fake profiles, or malicious activities on social platforms that may target executives, brands, or employees. These threats can result in reputational damage, phishing, or social engineering attacks. Immediate investigation and takedown are recommended to minimize risk.

T1491T1566T1582T1585.001T1593
Licence
MIT
Published
Aug 29, 2026
Upstream
4fe04459-13f1-4ff7-9b7c-f9be0c2aad6d
MediumMicrosoft Sentinel analytics
CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule

This analytics rule detects high severity alerts from CYFIRMA indicating exposure of Personally Identifiable Information (PII) or Confidential Information (CII) in public or unsecured sources. Such leaks may include email addresses, credentials, phone numbers, or other sensitive personal or organizational data. These exposures can lead to identity theft, phishing, credential compromise, or regulatory non-compliance.

T1003T1078T1213T1537
Licence
MIT
Published
Aug 29, 2026
Upstream
b484f224-687f-4406-af8a-ff019f9f2c24
HighMicrosoft Sentinel analytics
CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule

This analytics rule detects high severity alerts from CYFIRMA indicating exposure of Personally Identifiable Information (PII) or Confidential Information (CII) in public or unsecured sources. Such leaks may include email addresses, credentials, phone numbers, or other sensitive personal or organizational data. These exposures can lead to identity theft, phishing, credential compromise, or regulatory non-compliance.

T1003T1078T1213T1537
Licence
MIT
Published
Aug 29, 2026
Upstream
52d71822-41e4-4c21-b36f-400294f2b43a
MediumMicrosoft Sentinel analytics
CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule

This rule detects Medium-severity alerts from CYFIRMA regarding exposure of confidential files or forms linked to internal or client-related information, publicly accessible on platforms. These exposures could lead to data leakage, compliance violations, or targeted attacks.

T1189T1213T1567.002T1593
Licence
MIT
Published
Aug 29, 2026
Upstream
a2984be5-8d69-4139-b98f-e89c9c421c27
HighMicrosoft Sentinel analytics
CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule

This rule detects high-severity alerts from CYFIRMA regarding exposure of confidential files or forms linked to internal or client-related information, publicly accessible on platforms. These exposures could lead to data leakage, compliance violations, or targeted attacks.

T1189T1213T1567.002T1593
Licence
MIT
Published
Aug 29, 2026
Upstream
67e9c4aa-a2fa-4e4e-9272-1a8da41475c6
MediumMicrosoft Sentinel analytics
CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule

This analytics rule detects high-severity ransomware threats targeting the organization, as reported by CYFIRMA's Dark Web and Data Breach Intelligence feeds. The alert is generated when threat actors post, claim, or associate ransomware activity with corporate domains, brands, or subsidiaries, indicating a potential data breach, extortion attempt, or unauthorized access.

T1566.001T1566.002T1566.003
Licence
MIT
Published
Aug 29, 2026
Upstream
d5f9a6fe-7fd2-488c-8690-0ca24fba43dc
HighMicrosoft Sentinel analytics
CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule

This analytics rule detects high-severity ransomware threats targeting the organization, as reported by CYFIRMA's Dark Web and Data Breach Intelligence feeds. The alert is generated when threat actors post, claim, or associate ransomware activity with corporate domains, brands, or subsidiaries, indicating a potential data breach, extortion attempt, or unauthorized access.

T1566.001T1566.002T1566.003
Licence
MIT
Published
Aug 29, 2026
Upstream
ed1aabc1-e1c1-42f4-abac-fd5637730f13
MediumMicrosoft Sentinel analytics
CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule

Detects phishing campaigns targeting enterprise domains, as identified through CYFIRMA's Data Breach and Dark Web Monitoring. These alerts may include malicious URLs used for credential harvesting, domain impersonation, or social engineering. Immediate triage and takedown actions are recommended.

T1566.001T1566.002T1566.003
Licence
MIT
Published
Aug 29, 2026
Upstream
00c7b41c-ddeb-4c49-acd7-2f7897e27fb4
HighMicrosoft Sentinel analytics
CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule

Detects phishing campaigns targeting enterprise domains, as identified through CYFIRMA's Data Breach and Dark Web Monitoring. These alerts may include malicious URLs used for credential harvesting, domain impersonation, or social engineering. Immediate triage and takedown actions are recommended.

T1566.001T1566.002T1566.003
Licence
MIT
Published
Aug 29, 2026
Upstream
17cce4fc-9b4c-4eef-a4c7-083b44545e6e
MediumMicrosoft Sentinel analytics
CYFIRMA - Data Breach and Web Monitoring - Dark Web Medium Rule

Detects critical alerts from CYFIRMA related to sensitive data or credentials leaked on dark web forums. These events often indicate unauthorized access or compromise of enterprise systems, cloud environments, or identity platforms. Immediate investigation is required to assess breach scope and initiate mitigation, including credential resets, access reviews, and threat actor tracking.

T1048T1119T1212T1486T1552.001+1 more
Licence
MIT
Published
Aug 29, 2026
Upstream
c0afeda7-4832-49a6-8d03-a5d137d513b5
HighMicrosoft Sentinel analytics
CYFIRMA - Data Breach and Web Monitoring - Dark Web High Rule

Detects critical alerts from CYFIRMA related to sensitive data or credentials leaked on dark web forums. These events often indicate unauthorized access or compromise of enterprise systems, cloud environments, or identity platforms. Immediate investigation is required to assess breach scope and initiate mitigation, including credential resets, access reviews, and threat actor tracking.

T1048T1119T1212T1486T1552.001+1 more
Licence
MIT
Published
Aug 29, 2026
Upstream
c3f1f55b-7e54-4416-8afc-7d7876b29b0f