Search field:"CommandLine" for all 3415 flagged values with their contributing rules.
Indicator catalog
Two or more production detection rules across Sigma, Elastic, Splunk, Kusto (Sentinel + Defender XDR), and Chronicle (SecOps) flag these 15361 value patterns: process names, file paths, registry keys, and other tokens that rule authors treat as suspicious. Rules from at least two vendors flag 1720 of them; the community-validated IOCs appear below. The catalog unifies field names across vendors ( Values flagged by detection rules from two or more vendors: the highest-confidence IOCs to detect on. The 100 strongest by rule count appear below, grouped by field.Image covers process.executable, NewProcessName, etc.); the eq: / match: / ends_with: prefix shows the operator a rule uses to check a value. Each field below expands to its most-flagged values; for exhaustive lookup, the site search supports field: / value: / kind: operators.Corroborated indicators 100 of 1720
Field Kind Value Vendors Rules aws::errorCodeis_null 3 vendors 66 rules aws::errorMessageis_null 2 vendors 48 rules aws::eventSourceeq iam.amazonaws.com3 vendors 28 rules CommandLinecontains http4 vendors 52 rules CommandLinecontains add4 vendors 34 rules CommandLinecontains delete4 vendors 31 rules CommandLinecontains create3 vendors 29 rules CommandLinecontains \appdata\local\temp\2 vendors 28 rules CommandLinecontains rundll323 vendors 26 rules cs-methodeq post2 vendors 54 rules cs-methodeq get2 vendors 49 rules dest_ipis_not_null 3 vendors 31 rules Detailseq 0x000000012 vendors 61 rules Detailseq 0x000000002 vendors 41 rules Detailseq dword (0x00000001)2 vendors 40 rules Detailseq dword (0x00000000)2 vendors 38 rules Detailsis_not_null 3 vendors 89 rules event.kindeq alert2 vendors 38 rules EventIDeq 46883 vendors 317 rules EventIDeq 13 vendors 241 rules EventIDeq 51363 vendors 45 rules EventIDeq 73 vendors 41 rules EventIDeq 46632 vendors 35 rules EventIDeq 46244 vendors 29 rules EventIDeq 112 vendors 26 rules EventTypeeq exec2 vendors 576 rules EventTypeeq open2 vendors 52 rules Imageends_with \powershell.exe2 vendors 179 rules Imageends_with \pwsh.exe2 vendors 165 rules Imageends_with \certutil.exe2 vendors 44 rules Imageis_not_null 2 vendors 151 rules Imagestarts_with /tmp/2 vendors 58 rules Imagestarts_with /var/tmp/2 vendors 56 rules Imagestarts_with /dev/shm/2 vendors 53 rules IntegrityLeveleq System4 vendors 30 rules LogonTypeeq Network4 vendors 41 rules OriginalFileNameeq powershell.exe3 vendors 138 rules OriginalFileNameeq pwsh.dll3 vendors 112 rules OriginalFileNameeq cmd.exe3 vendors 81 rules OriginalFileNameeq wmic.exe3 vendors 80 rules OriginalFileNameeq rundll32.exe3 vendors 78 rules OriginalFileNameeq powershell_ise.exe3 vendors 51 rules OriginalFileNameeq net1.exe3 vendors 44 rules OriginalFileNameeq reg.exe3 vendors 43 rules OriginalFileNameeq mshta.exe3 vendors 40 rules OriginalFileNameeq wscript.exe2 vendors 38 rules OriginalFileNameeq regsvr32.exe3 vendors 37 rules OriginalFileNameeq cscript.exe2 vendors 32 rules OriginalFileNameeq net.exe3 vendors 31 rules OriginalFileNameeq schtasks.exe3 vendors 31 rules OriginalFileNameeq certutil.exe3 vendors 30 rules OriginalFileNameeq sc.exe3 vendors 30 rules parent_process_nameeq explorer.exe2 vendors 51 rules parent_process_nameeq powershell.exe3 vendors 39 rules parent_process_nameeq cmd.exe3 vendors 36 rules parent_process_nameeq excel.exe2 vendors 28 rules process_nameeq powershell.exe2 vendors 184 rules process_nameeq rundll32.exe2 vendors 126 rules process_nameeq cmd.exe2 vendors 121 rules process_nameeq mshta.exe2 vendors 84 rules process_nameeq wscript.exe2 vendors 83 rules process_nameeq pwsh.exe2 vendors 77 rules process_nameeq regsvr32.exe2 vendors 73 rules process_nameeq cscript.exe2 vendors 67 rules process_nameeq wmic.exe2 vendors 66 rules process_nameeq powershell_ise.exe2 vendors 52 rules process_nameeq msiexec.exe2 vendors 46 rules process_nameeq certutil.exe2 vendors 44 rules process_nameeq msbuild.exe2 vendors 39 rules process_nameeq net1.exe2 vendors 39 rules process_nameeq installutil.exe2 vendors 37 rules process_nameeq curl.exe2 vendors 34 rules process_nameeq sc.exe2 vendors 32 rules process_nameeq schtasks.exe2 vendors 30 rules process_nameeq curl2 vendors 29 rules process_nameeq net.exe2 vendors 28 rules process_nameeq reg.exe2 vendors 27 rules process_nameeq regasm.exe2 vendors 26 rules process_namein bash2 vendors 202 rules process_namein sh2 vendors 197 rules process_namein zsh2 vendors 196 rules process_namein dash2 vendors 170 rules process_namein fish2 vendors 163 rules process_namein ksh2 vendors 163 rules process_namein csh2 vendors 159 rules process_namein tcsh2 vendors 156 rules process_namein curl2 vendors 89 rules process_namein wget2 vendors 46 rules process_namein powershell.exe3 vendors 36 rules process_namein wscript.exe3 vendors 33 rules process_namein cscript.exe3 vendors 29 rules process_namein cat2 vendors 27 rules process_namein cmd.exe3 vendors 27 rules process_nameis_not_null 2 vendors 33 rules Protocoleq tcp2 vendors 26 rules src_ipis_not_null 3 vendors 82 rules typeeq execve2 vendors 37 rules typeeq syscall2 vendors 27 rules useris_not_null 3 vendors 40 rules verbeq create4 vendors 53 rules
CommandLine 3415 values
process_name 1380 values
Search field:"process_name" for all 1380 flagged values with their contributing rules.
process.args 959 values
Search field:"process.args" for all 959 flagged values with their contributing rules.
Image 699 values
Search field:"Image" for all 699 flagged values with their contributing rules.
TargetFilename 465 values
Search field:"TargetFilename" for all 465 flagged values with their contributing rules.
parent_process_name 411 values
Search field:"parent_process_name" for all 411 flagged values with their contributing rules.
QueryName 316 values
Search field:"QueryName" for all 316 flagged values with their contributing rules.
EventType 253 values
Search field:"EventType" for all 253 flagged values with their contributing rules.
OriginalFileName 240 values
Search field:"OriginalFileName" for all 240 flagged values with their contributing rules.
subject.subject 217 values
Search field:"subject.subject" for all 217 flagged values with their contributing rules.
TargetObject 199 values
Search field:"TargetObject" for all 199 flagged values with their contributing rules.
ParentImage 163 values
Search field:"ParentImage" for all 163 flagged values with their contributing rules.
EventID 162 values
Search field:"EventID" for all 162 flagged values with their contributing rules.
body.current_thread.text 152 values
Search field:"body.current_thread.text" for all 152 flagged values with their contributing rules.
Hashes 150 values
Search field:"Hashes" for all 150 flagged values with their contributing rules.
file_name 146 values
Search field:"file_name" for all 146 flagged values with their contributing rules.
ScriptBlockText 141 values
Search field:"ScriptBlockText" for all 141 flagged values with their contributing rules.
ImageLoaded 136 values
Search field:"ImageLoaded" for all 136 flagged values with their contributing rules.
Details 131 values
Search field:"Details" for all 131 flagged values with their contributing rules.
file.extension 123 values
Search field:"file.extension" for all 123 flagged values with their contributing rules.
DestinationHostname 117 values
Search field:"DestinationHostname" for all 117 flagged values with their contributing rules.
HttpUserAgentOriginal 112 values
Search field:"HttpUserAgentOriginal" for all 112 flagged values with their contributing rules.
aws::eventName 110 values
Search field:"aws::eventName" for all 110 flagged values with their contributing rules.
Signature 107 values
Search field:"Signature" for all 107 flagged values with their contributing rules.
ParentCommandLine 103 values
Search field:"ParentCommandLine" for all 103 flagged values with their contributing rules.
process.parent.args 94 values
Search field:"process.parent.args" for all 94 flagged values with their contributing rules.
Action 84 values
Search field:"Action" for all 84 flagged values with their contributing rules.
sender.display_name 84 values
Search field:"sender.display_name" for all 84 flagged values with their contributing rules.
dll.name 83 values
Search field:"dll.name" for all 83 flagged values with their contributing rules.
Name 73 values
Search field:"Name" for all 73 flagged values with their contributing rules.
Domain 72 values
Search field:"Domain" for all 72 flagged values with their contributing rules.
process.thread.Ext.call_stack_summary 71 values
Search field:"process.thread.Ext.call_stack_summary" for all 71 flagged values with their contributing rules.
client_ip 66 values
Search field:"client_ip" for all 66 flagged values with their contributing rules.
file.name 63 values
Search field:"file.name" for all 63 flagged values with their contributing rules.
Provider_Name 62 values
Search field:"Provider_Name" for all 62 flagged values with their contributing rules.
body.html.raw 62 values
Search field:"body.html.raw" for all 62 flagged values with their contributing rules.
sourcetype 54 values
Search field:"sourcetype" for all 54 flagged values with their contributing rules.
AlertName 54 values
Search field:"AlertName" for all 54 flagged values with their contributing rules.
DestinationPort 53 values
Search field:"DestinationPort" for all 53 flagged values with their contributing rules.
EventData 49 values
Search field:"EventData" for all 49 flagged values with their contributing rules.
UrlOriginal 49 values
Search field:"UrlOriginal" for all 49 flagged values with their contributing rules.
data_stream.dataset 46 values
Search field:"data_stream.dataset" for all 46 flagged values with their contributing rules.
beta.ocr(file.message_screenshot()).text 46 values
Search field:"beta.ocr(file.message_screenshot()).text" for all 46 flagged values with their contributing rules.
action 44 values
Search field:"action" for all 44 flagged values with their contributing rules.
OperationName 44 values
Search field:"OperationName" for all 44 flagged values with their contributing rules.
body.html.inner_text 43 values
Search field:"body.html.inner_text" for all 43 flagged values with their contributing rules.
src_ip 41 values
Search field:"src_ip" for all 41 flagged values with their contributing rules.
m365::ApplicationId 40 values
Search field:"m365::ApplicationId" for all 40 flagged values with their contributing rules.
azure_ad::app_id 38 values
Search field:"azure_ad::app_id" for all 38 flagged values with their contributing rules.
Operation 37 values
Search field:"Operation" for all 37 flagged values with their contributing rules.
Contents 37 values
Search field:"Contents" for all 37 flagged values with their contributing rules.
user 36 values
Search field:"user" for all 36 flagged values with their contributing rules.
signature_id 36 values
Search field:"signature_id" for all 36 flagged values with their contributing rules.
GrantedAccess 35 values
Search field:"GrantedAccess" for all 35 flagged values with their contributing rules.
type 34 values
Search field:"type" for all 34 flagged values with their contributing rules.
ServiceName 34 values
Search field:"ServiceName" for all 34 flagged values with their contributing rules.
process.Ext.api.name 34 values
Search field:"process.Ext.api.name" for all 34 flagged values with their contributing rules.
CurrentDirectory 34 values
Search field:"CurrentDirectory" for all 34 flagged values with their contributing rules.
ActionType 33 values
Search field:"ActionType" for all 33 flagged values with their contributing rules.
registry_value_name 29 values
Search field:"registry_value_name" for all 29 flagged values with their contributing rules.
dest_hostname 28 values
Search field:"dest_hostname" for all 28 flagged values with their contributing rules.
TargetImage 26 values
Search field:"TargetImage" for all 26 flagged values with their contributing rules.
TaskName 26 values
Search field:"TaskName" for all 26 flagged values with their contributing rules.
event.category 24 values
Search field:"event.category" for all 24 flagged values with their contributing rules.
UrlCategory 23 values
Search field:"UrlCategory" for all 23 flagged values with their contributing rules.
aws::eventSource 21 values
Search field:"aws::eventSource" for all 21 flagged values with their contributing rules.
displayName 21 values
Search field:"displayName" for all 21 flagged values with their contributing rules.
FilePath 21 values
Search field:"FilePath" for all 21 flagged values with their contributing rules.
azure_ad::result_type 21 values
Search field:"azure_ad::result_type" for all 21 flagged values with their contributing rules.
query_text 21 values
Search field:"query_text" for all 21 flagged values with their contributing rules.
Category 20 values
Search field:"Category" for all 20 flagged values with their contributing rules.
process.Ext.api.behaviors 19 values
Search field:"process.Ext.api.behaviors" for all 19 flagged values with their contributing rules.
aceAccessRights 19 values
Search field:"aceAccessRights" for all 19 flagged values with their contributing rules.
dest_ip 18 values
Search field:"dest_ip" for all 18 flagged values with their contributing rules.
aws::userAgent 18 values
Search field:"aws::userAgent" for all 18 flagged values with their contributing rules.
kubernetes.audit.objectRef.resource 18 values
Search field:"kubernetes.audit.objectRef.resource" for all 18 flagged values with their contributing rules.
Status 18 values
Search field:"Status" for all 18 flagged values with their contributing rules.
Properties 18 values
Search field:"Properties" for all 18 flagged values with their contributing rules.
operationName 18 values
Search field:"operationName" for all 18 flagged values with their contributing rules.
ImagePath 18 values
Search field:"ImagePath" for all 18 flagged values with their contributing rules.
fe 18 values
Search field:"fe" for all 18 flagged values with their contributing rules.
event.type 17 values
Search field:"event.type" for all 17 flagged values with their contributing rules.
user.id 17 values
Search field:"user.id" for all 17 flagged values with their contributing rules.
c-uri-extension 17 values
Search field:"c-uri-extension" for all 17 flagged values with their contributing rules.
network.http.user_agent 17 values
Search field:"network.http.user_agent" for all 17 flagged values with their contributing rules.
process.parent.working_directory 17 values
Search field:"process.parent.working_directory" for all 17 flagged values with their contributing rules.
file.Ext.header_bytes 16 values
Search field:"file.Ext.header_bytes" for all 16 flagged values with their contributing rules.
Severity 16 values
Search field:"Severity" for all 16 flagged values with their contributing rules.
sender.email.domain.tld 16 values
Search field:"sender.email.domain.tld" for all 16 flagged values with their contributing rules.
eventType 16 values
Search field:"eventType" for all 16 flagged values with their contributing rules.
Payload 15 values
Search field:"Payload" for all 15 flagged values with their contributing rules.
process.args_count 14 values
Search field:"process.args_count" for all 14 flagged values with their contributing rules.
data.type 14 values
Search field:"data.type" for all 14 flagged values with their contributing rules.
azure_ad::activity_display_name 14 values
Search field:"azure_ad::activity_display_name" for all 14 flagged values with their contributing rules.
verb 13 values
Search field:"verb" for all 13 flagged values with their contributing rules.
objectRef.resource 13 values
Search field:"objectRef.resource" for all 13 flagged values with their contributing rules.
DeviceVendor 13 values
Search field:"DeviceVendor" for all 13 flagged values with their contributing rules.
message 13 values
Search field:"message" for all 13 flagged values with their contributing rules.
cs-uri-query 13 values
Search field:"cs-uri-query" for all 13 flagged values with their contributing rules.
process.parent.thread.Ext.call_stack_summary 13 values
Search field:"process.parent.thread.Ext.call_stack_summary" for all 13 flagged values with their contributing rules.
registry_path 13 values
Search field:"registry_path" for all 13 flagged values with their contributing rules.
event.parameters{}.multiValue{} 13 values
Search field:"event.parameters{}.multiValue{}" for all 13 flagged values with their contributing rules.
process.Ext.effective_parent.name 13 values
Search field:"process.Ext.effective_parent.name" for all 13 flagged values with their contributing rules.
count_ 12 values
Search field:"count_" for all 12 flagged values with their contributing rules.
Message 12 values
Search field:"Message" for all 12 flagged values with their contributing rules.
file.Ext.original.name 12 values
Search field:"file.Ext.original.name" for all 12 flagged values with their contributing rules.
aws::errorCode 11 values
Search field:"aws::errorCode" for all 11 flagged values with their contributing rules.
sender.email.email 11 values
Search field:"sender.email.email" for all 11 flagged values with their contributing rules.
RelativeTargetName 11 values
Search field:"RelativeTargetName" for all 11 flagged values with their contributing rules.
okta::eventType 11 values
Search field:"okta::eventType" for all 11 flagged values with their contributing rules.
ActivityType 11 values
Search field:"ActivityType" for all 11 flagged values with their contributing rules.
BodyContainsWords 11 values
Search field:"BodyContainsWords" for all 11 flagged values with their contributing rules.
SubjectContainsWords 11 values
Search field:"SubjectContainsWords" for all 11 flagged values with their contributing rules.
SubjectOrBodyContainsWords 11 values
Search field:"SubjectOrBodyContainsWords" for all 11 flagged values with their contributing rules.
SyslogMessage 11 values
Search field:"SyslogMessage" for all 11 flagged values with their contributing rules.
actionName 11 values
Search field:"actionName" for all 11 flagged values with their contributing rules.
AttributeValue 11 values
Search field:"AttributeValue" for all 11 flagged values with their contributing rules.
body.links 10 values
Search field:"body.links" for all 10 flagged values with their contributing rules.
count 10 values
Search field:"count" for all 10 flagged values with their contributing rules.
ObjectType 10 values
Search field:"ObjectType" for all 10 flagged values with their contributing rules.
aws::userIdentity.type 10 values
Search field:"aws::userIdentity.type" for all 10 flagged values with their contributing rules.
DeviceProduct 10 values
Search field:"DeviceProduct" for all 10 flagged values with their contributing rules.
sender.email.domain.root_domain 10 values
Search field:"sender.email.domain.root_domain" for all 10 flagged values with their contributing rules.
ObjectName 10 values
Search field:"ObjectName" for all 10 flagged values with their contributing rules.
ServiceFileName 10 values
Search field:"ServiceFileName" for all 10 flagged values with their contributing rules.
ClientRequestURI 10 values
Search field:"ClientRequestURI" for all 10 flagged values with their contributing rules.
gcp.audit.request.rules.resources 10 values
Search field:"gcp.audit.request.rules.resources" for all 10 flagged values with their contributing rules.
ResultType 9 values
Search field:"ResultType" for all 9 flagged values with their contributing rules.
process.thread.Ext.call_stack_final_user_module.name 9 values
Search field:"process.thread.Ext.call_stack_final_user_module.name" for all 9 flagged values with their contributing rules.
DeviceEventClassID 9 values
Search field:"DeviceEventClassID" for all 9 flagged values with their contributing rules.
Product 9 values
Search field:"Product" for all 9 flagged values with their contributing rules.
strings.replace_confusables(body.current_thread.text) 9 values
Search field:"strings.replace_confusables(body.current_thread.text)" for all 9 flagged values with their contributing rules.
Description 9 values
Search field:"Description" for all 9 flagged values with their contributing rules.
DstPortNumber 9 values
Search field:"DstPortNumber" for all 9 flagged values with their contributing rules.
Data 9 values
Search field:"Data" for all 9 flagged values with their contributing rules.
command 9 values
Search field:"command" for all 9 flagged values with their contributing rules.
gcp.audit.request.rules.verbs 9 values
Search field:"gcp.audit.request.rules.verbs" for all 9 flagged values with their contributing rules.
kibana.alert.rule.rule_id 9 values
Search field:"kibana.alert.rule.rule_id" for all 9 flagged values with their contributing rules.
profile.by_sender 8 values
Search field:"profile.by_sender" for all 8 flagged values with their contributing rules.
attachments 8 values
Search field:"attachments" for all 8 flagged values with their contributing rules.
process.Ext.token.integrity_level_name 8 values
Search field:"process.Ext.token.integrity_level_name" for all 8 flagged values with their contributing rules.
kubernetes.audit.verb 8 values
Search field:"kubernetes.audit.verb" for all 8 flagged values with their contributing rules.
event.dataset 8 values
Search field:"event.dataset" for all 8 flagged values with their contributing rules.
source.as.number 8 values
Search field:"source.as.number" for all 8 flagged values with their contributing rules.
process.Ext.api.parameters.protection 8 values
Search field:"process.Ext.api.parameters.protection" for all 8 flagged values with their contributing rules.
AADOperationType 8 values
Search field:"AADOperationType" for all 8 flagged values with their contributing rules.
event_type 8 values
Search field:"event_type" for all 8 flagged values with their contributing rules.
c-useragent 8 values
Search field:"c-useragent" for all 8 flagged values with their contributing rules.
name 8 values
Search field:"name" for all 8 flagged values with their contributing rules.
subject 8 values
Search field:"subject" for all 8 flagged values with their contributing rules.
LogonType 7 values
Search field:"LogonType" for all 7 flagged values with their contributing rules.
IntegrityLevel 7 values
Search field:"IntegrityLevel" for all 7 flagged values with their contributing rules.
IndicatorType 7 values
Search field:"IndicatorType" for all 7 flagged values with their contributing rules.
Url 7 values
Search field:"Url" for all 7 flagged values with their contributing rules.
Type 7 values
Search field:"Type" for all 7 flagged values with their contributing rules.
Codename 7 values
Search field:"Codename" for all 7 flagged values with their contributing rules.
AttributeLDAPDisplayName 7 values
Search field:"AttributeLDAPDisplayName" for all 7 flagged values with their contributing rules.
Roles 7 values
Search field:"Roles" for all 7 flagged values with their contributing rules.
GlobalPrevalence 7 values
Search field:"GlobalPrevalence" for all 7 flagged values with their contributing rules.
process.thread.Ext.call_stack_final_user_module.protection_provenance 7 values
Search field:"process.thread.Ext.call_stack_final_user_module.protection_provenance" for all 7 flagged values with their contributing rules.
aws::requestParameters 7 values
Search field:"aws::requestParameters" for all 7 flagged values with their contributing rules.
file_type 7 values
Search field:"file_type" for all 7 flagged values with their contributing rules.
subject.base 7 values
Search field:"subject.base" for all 7 flagged values with their contributing rules.
action_id 7 values
Search field:"action_id" for all 7 flagged values with their contributing rules.
endgame.event_subtype_full 7 values
Search field:"endgame.event_subtype_full" for all 7 flagged values with their contributing rules.
Initiated 6 values
Search field:"Initiated" for all 6 flagged values with their contributing rules.
process.Ext.relative_file_creation_time 6 values
Search field:"process.Ext.relative_file_creation_time" for all 6 flagged values with their contributing rules.
sc-status 6 values
Search field:"sc-status" for all 6 flagged values with their contributing rules.
profile.by_sender_email 6 values
Search field:"profile.by_sender_email" for all 6 flagged values with their contributing rules.
severity 6 values
Search field:"severity" for all 6 flagged values with their contributing rules.
TargetUserName 6 values
Search field:"TargetUserName" for all 6 flagged values with their contributing rules.
AccessList 6 values
Search field:"AccessList" for all 6 flagged values with their contributing rules.
event_action 6 values
Search field:"event_action" for all 6 flagged values with their contributing rules.
NetworkDirection 6 values
Search field:"NetworkDirection" for all 6 flagged values with their contributing rules.
SourceSystem 6 values
Search field:"SourceSystem" for all 6 flagged values with their contributing rules.
RequestURL 6 values
Search field:"RequestURL" for all 6 flagged values with their contributing rules.
id.applicationName 6 values
Search field:"id.applicationName" for all 6 flagged values with their contributing rules.
m365::Workload 6 values
Search field:"m365::Workload" for all 6 flagged values with their contributing rules.
process.parent.args_count 6 values
Search field:"process.parent.args_count" for all 6 flagged values with their contributing rules.
HttpStatusCode 6 values
Search field:"HttpStatusCode" for all 6 flagged values with their contributing rules.
m365::Target.Type 6 values
Search field:"m365::Target.Type" for all 6 flagged values with their contributing rules.
m365::Parameters 6 values
Search field:"m365::Parameters" for all 6 flagged values with their contributing rules.
SourceImage 6 values
Search field:"SourceImage" for all 6 flagged values with their contributing rules.
TargetSid 6 values
Search field:"TargetSid" for all 6 flagged values with their contributing rules.
azure_ad::operation_name_value 6 values
Search field:"azure_ad::operation_name_value" for all 6 flagged values with their contributing rules.
azure_ad::resource_id 6 values
Search field:"azure_ad::resource_id" for all 6 flagged values with their contributing rules.
Effective_process.name 6 values
Search field:"Effective_process.name" for all 6 flagged values with their contributing rules.
ProductName 6 values
Search field:"ProductName" for all 6 flagged values with their contributing rules.
azure.platformlogs.properties.log.verb 6 values
Search field:"azure.platformlogs.properties.log.verb" for all 6 flagged values with their contributing rules.
process.Ext.effective_parent.executable 6 values
Search field:"process.Ext.effective_parent.executable" for all 6 flagged values with their contributing rules.
protoPayload.methodName 6 values
Search field:"protoPayload.methodName" for all 6 flagged values with their contributing rules.
ClientIPClass 6 values
Search field:"ClientIPClass" for all 6 flagged values with their contributing rules.
ConsentFull 6 values
Search field:"ConsentFull" for all 6 flagged values with their contributing rules.
auditType.category 6 values
Search field:"auditType.category" for all 6 flagged values with their contributing rules.
md5 6 values
Search field:"md5" for all 6 flagged values with their contributing rules.
process.env_vars 6 values
Search field:"process.env_vars" for all 6 flagged values with their contributing rules.
sender.email.local_part 6 values
Search field:"sender.email.local_part" for all 6 flagged values with their contributing rules.
cs-method 5 values
eq: post 54 rules, 2 vendors
- Confluence Exploitation CVE-2019-3398
- CVE-2021-21972 VSphere Exploitation
- CVE-2021-21978 Exploitation Attempt
- CVE-2021-33766 Exchange ProxyToken Exploitation
- CVE-2022-31659 VMware Workspace ONE Access RCE
- CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer AX21
- CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)
- CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver)
eq: get 49 rules, 2 vendors
- Cisco ASA Exploitation Activity - Proxy
- Cross Site Scripting Strings
- CVE-2020-0688 Exchange Exploitation via Web Log
- CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer AX21
- CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
- CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
- CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
- CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
in: get 3 rules
in: post 3 rules
eq: head 2 rules
Workload 5 values
eq: azureactivedirectory 30 rules
T1098, Create Account T1136, Cloud Account T1136.003, Additional Cloud Roles T1098.003, Brute Force T1110, Steal Application Access Token T1528- High Number of Login Failures from a single source
- O365 Add App Role Assignment Grant User
- O365 Added Service Principal
- O365 Admin Consent Bypassed by Service Principal
- O365 Application Available To Other Tenants
- O365 Application Registration Owner Added
- O365 Block User Consent For Risky Apps Disabled
- O365 Concurrent Sessions From Different Ips
eq: exchange 20 rules
T1114, Indicator Removal T1070, Clear Mailbox Data T1070.008, Data Destruction T1485, Account Manipulation T1098, Additional Email Delegate Permissions T1098.002- O365 ApplicationImpersonation Role Assigned
- O365 BEC Email Hiding Rule Created
- O365 Elevated Mailbox Permission Assigned
- O365 Email Hard Delete Excessive Volume
- O365 Email New Inbox Rule Created
- O365 Email Password and Payroll Compromise Behavior
- O365 Email Receive and Hard Delete Takeover Behavior
- O365 Email Security Feature Changed
eq: securitycompliancecenter 8 rules
T1114, Remote Email Collection T1114.002, Phishing T1566, Spearphishing Attachment T1566.001, Spearphishing Link T1566.002, Email Forwarding Rule T1114.003- O365 Compliance Content Search Exported
- O365 Compliance Content Search Started
- O365 Email Access By Security Administrator
- O365 Email Reported By Admin Found Malicious
- O365 Email Reported By User Found Malicious
- O365 Email Suspicious Behavior Alert
- O365 Security And Compliance Alert Triggered
- O365 ZAP Activity Detection
eq: threatintelligence 3 rules, 2 vendors
Protocol 5 values
eq: tcp 26 rules, 2 vendors
T1021, Distributed Component Object Model T1021.003, Inter-Process Communication T1559, Component Object Model T1559.001, System Binary Proxy Execution T1218, Encrypted Channel T1573- Deprecated TLS Version or Weak Cipher Negotiated Externally
- Halfbaked Command and Control Beacon
- Incoming DCOM Lateral Movement via MSHTA
- Incoming DCOM Lateral Movement with MMC
- Incoming DCOM Lateral Movement with ShellBrowserWindow or ShellWindows
- LDAP Search followed by Kerberos Connection
- Possible FIN7 DGA Command and Control Behavior
- Potential Command and Control via Windows Scripts
eq: Kerberos 3 rules
eq: NTLM 3 rules
cross_field_compare: NetworkProtocol 2 rules
graph.metadata.entity_type 5 values
eq: FILE 17 rules
eq: DOMAIN_NAME 10 rules
eq: IP_ADDRESS 10 rules
event.module 5 values
eq: endgame 15 rules
- Adversary Behavior - Detected - Elastic Endgame
- Credential Dumping - Detected - Elastic Endgame
- Credential Dumping - Prevented - Elastic Endgame
- Credential Manipulation - Detected - Elastic Endgame
- Credential Manipulation - Prevented - Elastic Endgame
- Exploit - Detected - Elastic Endgame
- Exploit - Prevented - Elastic Endgame
- Malware - Detected - Elastic Endgame
eq: endpoint 6 rules
eq: threatintel 5 rules
starts_with: ti_ 5 rules
process.Ext.device.product_id 5 values
eq: virtual disk 13 rules
T1047, Command and Scripting Interpreter T1059, PowerShell T1059.001, Windows Command Shell T1059.003, Trusted Developer Utilities Proxy Execution T1127, MSBuild T1127.001- DNS Query to Suspicious Top Level Domain
- GetAsyncKeyState API Call from Suspicious Process
- Potential Crypto Mining Activity
- Potential DLL SideLoad via a Renamed Signed Binary
- Scheduled Task Creation by an Unusual Process
- Suspicious Communication via Mail Protocol
- Suspicious DNS Query from Mounted Virtual Disk
- Suspicious Execution from a Mounted Device
eq: virtual dvd-rom 13 rules
T1047, Command and Scripting Interpreter T1059, PowerShell T1059.001, Windows Command Shell T1059.003, Trusted Developer Utilities Proxy Execution T1127, MSBuild T1127.001- DNS Query to Suspicious Top Level Domain
- GetAsyncKeyState API Call from Suspicious Process
- Potential Crypto Mining Activity
- Potential DLL SideLoad via a Renamed Signed Binary
- Scheduled Task Creation by an Unusual Process
- Suspicious Communication via Mail Protocol
- Suspicious DNS Query from Mounted Virtual Disk
- Suspicious Execution from a Mounted Device
wildcard: Virtual DVD-ROM 8 rules
- Command and Scripting Interpreter from Suspicious Parent
- Persistence via a Process from a Removable or Mounted ISO Device
- Process Creation from Backed RWX Memory
- Process from Archive or Removable Media via Unbacked Code
- Scheduled Task Creation from Suspicious Parent
- Scheduled Task from a Removable or Mounted ISO Device
- Suspicious Vault Files Access via RPC
- Suspicious Windows API Call from Virtual Disk or USB
wildcard: Virtual Disk 8 rules
- Command and Scripting Interpreter from Suspicious Parent
- Persistence via a Process from a Removable or Mounted ISO Device
- Process Creation from Backed RWX Memory
- Process from Archive or Removable Media via Unbacked Code
- Scheduled Task Creation from Suspicious Parent
- Scheduled Task from a Removable or Mounted ISO Device
- Suspicious Vault Files Access via RPC
- Suspicious Windows API Call from Virtual Disk or USB
wildcard: USB * 7 rules
- Command and Scripting Interpreter from Suspicious Parent
- Persistence via a Process from a Removable or Mounted ISO Device
- Process Creation from Backed RWX Memory
- Process from Archive or Removable Media via Unbacked Code
- Scheduled Task Creation from Suspicious Parent
- Scheduled Task from a Removable or Mounted ISO Device
- Suspicious Windows API Call from Virtual Disk or USB
dll.Ext.relative_file_creation_time 5 values
le: 500 11 rules
- DLL Side Loading via a Copied Microsoft Executable
- Image Loaded with Invalid Signature
- Known Desktop Application DLL Search Order Hijack
- Self Injection via AppDomain Manager Assembly
- Suspicious AppDomain Manager Configuration File
- Suspicious Control Panel DLL Loaded by Explorer
- Suspicious Image Load via Windows Scripts
- Unsigned DLL from Suspicious Directory
le: 900 9 rules
- Potential DLL Hijacking via Environment Paths
- Potential Microsoft Outlook Remote Code Execution
- Potential Privilege Escalation via SetWindowsHook DLL Injection
- Service Communication via Mail Protocol
- Suspicious Activity from a Control Panel Applet
- Suspicious API from an Unsigned Service DLL
- Unsigned DLL loaded by DNS Service
- Unsigned DLL loaded by Rundll32 via COM
le: 300 7 rules
lt: 5000 6 rules
process.Ext.api.parameters.size 5 values
ge: 10000 11 rules
- Cross Process API Activity with Truncated Stack
- Evasion via Multiple Memory Section Mapping
- Image Hollow from Unusual Stack
- Network Activity from a Stomped Module
- Potential Injection via NSIS Installer
- Potential Shellcode Injection by a Browser Process
- Self Injection via AppDomain Manager Assembly
- Shellcode Injection via PowerShell
ge: 100000 6 rules
gt: 4096 5 rules
eq: 0 3 rules
dll.Ext.relative_file_name_modify_time 5 values
le: 500 9 rules
- DLL Side Loading via a Copied Microsoft Executable
- Image Loaded with Invalid Signature
- Known Desktop Application DLL Search Order Hijack
- Potential Windows Session Hijacking via CcmExec
- Self Injection via AppDomain Manager Assembly
- Suspicious AppDomain Manager Configuration File
- Suspicious Control Panel DLL Loaded by Explorer
- Unsigned DLL Loaded by a Trusted Process
le: 900 6 rules
lt: 5000 6 rules
le: 3600 3 rules
le: 300 2 rules
client.user.email 5 values
is_not_null: 8 rules
T1552, Container API T1552.007, Account Manipulation T1098, Additional Container Cluster Roles T1098.006, Container and Resource Discovery T1613- GKE Certificate Signing Request Self-Approved
- GKE Endpoint Permission Enumeration
- GKE Multi-Resource Discovery
- GKE Rapid Secret GET Activity Against Multiple Objects
- GKE Secret Access via Unusual User Agent
- GKE Sensitive RBAC Change Followed by Workload Modification
- GKE Service Account Token Created via TokenRequest API
- GKE Unusual Sensitive Workload Modification
is_null: 3 rules
starts_with: system:serviceaccount: 3 rules
eq: system:anonymous 2 rules
eq: system:unauthenticated 2 rules
graph.metadata.product_name 5 values
eq: GCTI Feed 8 rules
- AWS Successful API From Tor Exit Node
- GCP Successful API Call From Tor Exit Node
- GCTI Benign Binaries Contacts Tor Exit Node
- GCTI Remote Access Tools
- GCTI Tor Exit Nodes
- GitHub Personal Access Token Created from Tor IP Address
- Google Safebrowsing File Contacts Tor Exit Node
- VT Relationships File Contacts Tor IP
eq: MISP 6 rules
eq: VirusTotal Relationships 6 rules
eq: Google Safe Browsing 4 rules
eq: WHOISXMLAPI Simple Whois 4 rules
ObjectServer 5 values
eq: security account manager 7 rules
eq: security 5 rules
eq: ds 3 rules
eq: sc manager 2 rules, 2 vendors
ObjectClass 5 values
eq: grouppolicycontainer 6 rules, 2 vendors
eq: user 6 rules, 4 vendors
eq: domaindns 4 rules
eq: dnsnode 3 rules, 2 vendors
eq: computer 2 rules, 2 vendors
ResourceType 5 values
eq: vaults 6 rules
eq: AZUREFIREWALLS 3 rules
eq: PUBLICIPADDRESSES 2 rules
eq: azurefirewalls 2 rules
eq: login 2 rules
network.whois 5 values
func_call: network.whois(sender.email.domain).days_old < 30 6 rules
- BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- BEC: Financial fraud from newly registered sender domain
- Brand impersonation: USPS
- Fake thread with suspicious indicators
- Spam: Link to blob.core.windows.net from new domain (<30d)
- Suspicious newly registered reply-to domain with engaging financial or urgent language
func_call: network.whois(sender.email.domain).days_old <= 30 5 rules
func_call: network.whois(sender.email.domain).days_old <= 90 3 rules
func_call: network.whois(sender.email.domain).days_old < 365 2 rules
func_call: network.whois(sender.email.domain).days_old < 90 2 rules
userAgent 5 values
ne: console.amazonaws.com 6 rules
ne: *.amazonaws.com 5 rules
contains: trufflehog 3 rules, 2 vendors
contains: s3 browser 3 rules
contains: azurehound 2 rules
CallTrace 5 values
contains: unknown 5 rules, 2 vendors
contains: dbgcore.dll 4 rules, 3 vendors
contains: dbghelp.dll 4 rules, 3 vendors
contains: seclogon.dll 2 rules, 2 vendors
contains: |unknown( 2 rules
SubjectUserName 5 values
ends_with: $ 5 rules, 2 vendors
eq: anonymous logon 3 rules, 2 vendors
eq: anonymous 3 rules
regex_match: \/i-.*$ 2 rules
regex_match: ^urn:spo:anon# 2 rules
Computer 5 values
eq: adfs_servers 5 rules
eq: %domain_controllers% 3 rules
contains: <your ca machine name> 2 rules
ne: unknown 2 rules
starts_with: DESKTOP- 2 rules
DestinationPortName 5 values
eq: dns 5 rules
eq: http 5 rules
ne: dns 3 rules
in: http 2 rules
in: tls 2 rules
dll.Ext.device.product_id 5 values
eq: virtual disk 5 rules
eq: virtual dvd-rom 5 rules
wildcard: USB * 4 rules
wildcard: Virtual DVD-ROM 4 rules
File 5 values
in: id_rsa 4 rules
in: passwd 4 rules
in: shadow 4 rules
is_not_null: 3 rules
regex_match: ([a-zA-Z0-9-_]+\.)([a-zA-Z0-9-]+\.[a-zA-Z0-9-]+) 2 rules
TimeGenerated 5 values
cross_field_compare: maxSummarizedTime 4 rules
T1008, Dynamic Resolution T1568, Non-Application Layer Protocol T1095, Encrypted Channel T1573, Data Transfer Size Limits T1030, Network Service Discovery T1046- Anomaly found in Network Session Traffic (ASIM Network Session schema)
- Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution)
- Detect port misuse by anomaly based detection (ASIM Network Session schema)
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution)
cross_field_compare: ValidUntil 2 rules
cross_field_compare: timeframe 2 rules
ge: start 2 rules
object_type 5 values
eq: uva 4 rules
eq: vault 3 rules
eq: account 2 rules
eq: gm 2 rules
target.url 5 values
eq: https://graph.microsoft.com/v1.0/groups 4 rules
eq: https://graph.microsoft.com/beta/rolemanagement/directory/estimateaccess 3 rules
eq: https://graph.microsoft.com/v1.0/applications 2 rules
eq: https://graph.microsoft.com/v1.0/users 2 rules
regex_match: ^https://graph\.microsoft\.com/v1\.0/drives/.*/content$ 2 rules
AuditPolicyChanges 5 values
contains: %%8448 3 rules
contains: %%8450 3 rules
in: %%8448 2 rules
in: %%8448, %%8450 2 rules
in: %%8450 2 rules
a1 5 values
ends_with: .jpg 3 rules
ends_with: .png 3 rules
eq: -sel 2 rules
eq: -selection 2 rules
data.description 5 values
eq: create or update the anomaly detection captcha 3 rules
eq: update brute-force settings 3 rules
eq: update suspicious ip throttling settings 3 rules
eq: Set the Multi-factor Authentication policies 2 rules
eq: Updates risk assessment configs 2 rules
event 5 values
eq: session.command 3 rules
eq: user.login 3 rules
eq: CWS_EVENT 2 rules
in: group.feature_flags.edit 2 rules
in: org.request_access_settings.edit 2 rules
event_count 5 values
gt: 0 3 rules
gt: 2 3 rules
lt: 5 3 rules
gt: 100 2 rules
informationType_s 5 values
eq: Business Information 3 rules
eq: Financial Information 3 rules
eq: HR Information 3 rules
eq: Legal Information 3 rules
eq: Governance Information 2 rules
EventResult 5 values
eq: Blocked 2 rules
eq: Failure 2 rules
eq: Success 2 rules
eq: failed 2 rules
eq: file 2 rules
InterfaceUuid 5 values
eq: 1ff70682-0a51-30e8-076d-740be8cee98b 2 rules
eq: 338cd001-2244-31f1-aaaa-900038001003 2 rules
eq: 378e52b0-c0a9-11cf-822d-00aa0051e40f 2 rules
eq: 4b324fc8-1670-01d3-1278-5a47bf6ee188 2 rules
eq: 86d35949-83c9-4044-b424-db363231fd0c 2 rules
a0 5 values
eq: cp 2 rules
eq: hostname 2 rules
eq: steghide 2 rules
eq: uname 2 rules
eq: xclip 2 rules
o365.audit.Actor.Type 5 values
in: 0 2 rules
in: 10 2 rules
in: 2 2 rules
in: 3 2 rules
strings.replace_confusables(subject.base) 5 values
contains: sendgrid 2 rules
regex_match: (?:\bs\s?e\s?x\b|horny|hook.?up|private room|wanna meet|wants to meet|naked|porn|webcam|nudes?|sexting|erotic|kinky|seduce|adult community|cam shows|local (?:girls?|women|single)|bed partner) 2 rules
regex_match: (?:call|dial|speak to|contact \d|to (?:stop|void|reverse|confirm|secure|verify|unfreeze)) 2 rules
regex_match: \+?(?:[ilo0-9]{1,2})?\s?\(?\d{3}\)?[\s\.\-⋅]{0,5}[ilo0-9]{3}[\s\.\-⋅]{0,5}[ilo0-9]{4} 2 rules
regex_match: \+?(?:[ilo0-9]{1}.)?\(?[ilo0-9]{3}?\)?.[ilo0-9]{3}.?[ilo0-9]{4} 2 rules
recipients.to 4 values
length_compare: 1 71 rules
- Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
- Attachment: EML with QR code redirecting to Cloudflare challenges
- Attachment: Encrypted PDF with credential theft body
- Attachment: Encrypted PDF with credential theft language in EML
- Attachment: PDF with credential theft language and invalid reply-to domain
- Attachment: PDF with localhost IP in EXIF title metadata
- Attachment: PDF with recipient email in link
- Attachment: QR code with recipient targeting and special characters
length_compare: 0 40 rules
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
- Attachment: Adobe image lure in body or attachment with suspicious link
- Attachment: Callback phishing solicitation via image file
- Attachment: Encrypted PDF with credential theft body
- Attachment: Encrypted PDF with credential theft language in EML
- BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
- Brand impersonation: Google Drive fake file share
- Brand impersonation: Hulu
length_compare: 10 2 rules
length_compare: 2 2 rules
responseStatus.code 4 values
starts_with: 2 24 rules
eq: 403 4 rules, 3 vendors
eq: 401 2 rules, 2 vendors
metadata.log_type 4 values
eq: GCP_CLOUDAUDIT 22 rules
T1562, Account Manipulation T1098, Data Destruction T1485, Exfiltration Over Web Service T1567, Transfer Data to Cloud Account T1537, Account Access Removal T1531- GCP Admin Privileged Roles Added To Service Accounts
- GCP BigQuery Datasets Opened To Public
- GCP BigQuery Results Downloaded From Multiple Tables
- GCP Cloud Audit Logging Removed From All Services
- GCP Excessive Permission Denied Events
- GCP Exempt Principals From Audit Log
- GCP Firewall Rule Opened To The World
- GCP Free Gmail Domains Added To IAM Policy
eq: SAP_SECURITY_AUDIT 18 rules
eq: SAP_CHANGE_DOCUMENT 8 rules
- sap change documents sensitive profile assignment
- sap change documents sensitive profile assignment data table
- sap change documents sensitive role assignment
- sap critial role assigned to new user
- sap critical authorization value changed
- sap critical role assigned to new user
- sap sensitive role assignment correlation
- sap sensitive role authorization modification
eq: SAP_HANA_AUDIT 2 rules
status 4 values
eq: success 21 rules, 2 vendors
T1078, Encrypted Channel T1573, Account Manipulation T1098, Disable or Modify System Firewall T1686, Cloud Firewall T1686.001, Cloud Accounts T1078.004eq: SUCCESS 16 rules
eq: 200 3 rules
eq: failure 3 rules
process.Ext.relative_file_name_modify_time 4 values
le: 500 21 rules
T1114, Local Email Collection T1114.001, Inter-Process Communication T1559, Component Object Model T1559.001, Application Layer Protocol T1071, Ingress Tool Transfer T1105- Driver Dropped by Untrusted Executable
- Execution of a DNGUard Protected Program
- Firewall Policy Changed by a Suspicious Process
- Ingress Tool Transfer via PowerShell
- Java Drop followed by network activity
- Java Dropped and Executed With DNS Lookup
- Kernel Driver Registered via NtLoadDriver
- Keystrokes Input Capture from a Managed Application
le: 300 9 rules
- Connection to WebService by an Unsigned Binary
- DNS Query to Suspicious Top Level Domain
- External IP Address Discovery via a Trusted Program
- External IP Address Discovery via Untrusted Program
- Scheduled Task Creation by an Unusual Process
- Suspicious PHP Script Execution
- Suspicious Python Script Interpreter
- Suspicious Shell Extension Handler Registry Modification
le: 1800 6 rules
- Component Object Model Registry Modification by a Low Reputation Process
- Malicious Reputation of Executable Download
- Scheduled Task by a Low Reputation Process
- Scheduled Task from a Browser or Compression Utility Descendant
- Startup Persistence by a Low Reputation Process
- Startup Persistence from a Browser or Compression Utility Descendant
EventLog 4 values
eq: rpcfw 17 rules
eq: microsoft-windows-sysmon/operational 7 rules
eq: Microsoft-Windows-Sysmon/Operational 3 rules
eq: Application 2 rules
SourcePort 4 values
ge: 49152 16 rules
T1021, Use Alternate Authentication Material T1550, Pass the Ticket T1550.003, Steal or Forge Kerberos Tickets T1558, Kerberoasting T1558.003, Remote System Discovery T1018- Incoming DCOM Lateral Movement with MMC
- Kerberos Traffic from Unusual Process
- LDAP Search followed by Kerberos Connection
- Potential Command and Control via Windows Scripts
- Potential Enumeration via Active Directory Web Service
- Potential Privilege Escalation via Rogue WinRM
- Potential Ransomware Note File via SMB
- Potential Remote Execution via IMsiServer
eq: 3389 3 rules
gt: 49151 2 rules
regex_match: (?i)3389|rdp 2 rules
esf.event_type 4 values
eq: 9 15 rules
eq: 17 3 rules
eq: 27 3 rules
serviceName 4 values
eq: accounts 13 rules
eq: ssoConfigBackend 3 rules
eq: workspace 3 rules
eq: deltaSharingAccess 2 rules
ObservableKey 4 values
eq: ipv4-addr:value 12 rules
T1071, Exploit Public-Facing Application T1190, Brute Force T1110, Exfiltration Over C2 Channel T1041, Dynamic Resolution T1568- Google Threat Intelligence - Threat Hunting IP
- HoneyLabs TI Map IP Entity to CommonSecurityLog
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- HoneyLabs TI Map IP Entity to SigninLogs
- Lumen TI IPAddress in CommonSecurityLog
- Lumen TI IPAddress in DeviceEvents
- Lumen TI IPAddress in IdentityLogonEvents
- Lumen TI IPAddress in OfficeActivity
eq: domain-name:value 4 rules
eq: url:value 3 rules
WindowType 4 values
eq: detection 10 rules
- Affected rows stateful anomaly on database
- Credential errors stateful anomaly on database
- Drop attempts stateful anomaly on database
- Execution attempts stateful anomaly on database
- Firewall errors stateful anomaly on database
- Firewall rule manipulation attempts stateful anomaly on database
- OLE object manipulation attempts stateful anomaly on database
- Outgoing connection attempts stateful anomaly on database
eq: training 10 rules
- Affected rows stateful anomaly on database
- Credential errors stateful anomaly on database
- Drop attempts stateful anomaly on database
- Execution attempts stateful anomaly on database
- Firewall errors stateful anomaly on database
- Firewall rule manipulation attempts stateful anomaly on database
- OLE object manipulation attempts stateful anomaly on database
- Outgoing connection attempts stateful anomaly on database
in: detection 10 rules
- Affected rows stateful anomaly on database
- Credential errors stateful anomaly on database
- Drop attempts stateful anomaly on database
- Execution attempts stateful anomaly on database
- Firewall errors stateful anomaly on database
- Firewall rule manipulation attempts stateful anomaly on database
- OLE object manipulation attempts stateful anomaly on database
- Outgoing connection attempts stateful anomaly on database
in: training 10 rules
- Affected rows stateful anomaly on database
- Credential errors stateful anomaly on database
- Drop attempts stateful anomaly on database
- Execution attempts stateful anomaly on database
- Firewall errors stateful anomaly on database
- Firewall rule manipulation attempts stateful anomaly on database
- OLE object manipulation attempts stateful anomaly on database
- Outgoing connection attempts stateful anomaly on database
Esql.event_count 4 values
ge: 10 8 rules
T1580, Cloud Service Discovery T1526, Automated Exfiltration T1020, Data Destruction T1485, Data Manipulation T1565, Stored Data Manipulation T1565.001- AWS EC2 Multi-Region DescribeInstances API Calls
- AWS Service Quotas Multi-Region GetServiceQuota Requests
- Azure Key Vault Excessive Secret or Key Retrieved
- Azure OpenAI Insecure Output Handling
- High Number of Protected Branch Force Pushes by User
- M365 Identity User Account Lockouts
- Potential Denial of Azure OpenAI ML Service
- Potential Linux Local Account Brute Force Detected
lt: 5 3 rules
ge: 100 2 rules
gt: 50 2 rules
AuthenticationPackageName 4 values
eq: ntlm 7 rules, 3 vendors
T1021, SMB/Windows Admin Shares T1021.002, Adversary-in-the-Middle T1557, Name Resolution Poisoning and SMB Relay T1557.001, Account Manipulation T1098, Access Token Manipulation T1134- Potential NTLM Relay Attack against a Computer Account
- Anonymous login (RottenPotatoNG)
- Exchange server impersonation via PrivExchange relay attack
- Metasploit SMB Authentication
- Suspicious anonymous login (domain specified)
- User password change without previous password known - SetNTLM (Mimikatz)
- Potential EternalBlue via Metasploit (Windows Event Log)
eq: kerberos 5 rules, 3 vendors
SourceIP 4 values
is_not_null: 7 rules
- Cisco SDWAN - Monitor Critical IPs
- Fortinet - Beacon pattern detected
- HoneyLabs TI Map IP Entity to CommonSecurityLog
- Palo Alto Threat signatures from Unusual IP addresses
- Threat Essentials - Time series anomaly for data size transferred to public internet
- Time series anomaly detection for total volume of traffic
- Time series anomaly for data size transferred to public internet
cross_field_compare: nextSourceIP 2 rules
eq: IPList 2 rules
eq: suspicious_signins 2 rules
facility 4 values
in: ha_em 7 rules
- Cisco IOS XE Guestshell Activation and Destroy
- Cisco IOS XE Log Clearing Sequence With Optional Loopback Removal
- Cisco IOS XE Reconnaissance Command Activity
- Cisco IOS XE Remote Access Probe Burst
- Cisco IOS XE Request Platform Package Describe Shell Pattern
- Cisco IOS XE Tunnel Interface Configuration
- Cisco IOS XE VTY Access Class Tampering
in: aaa 5 rules
in: parser 3 rules
eq: pm 2 rules
gcp::service_name 4 values
eq: admin.googleapis.com 7 rules
eq: storage.googleapis.com 4 rules
eq: login.googleapis.com 3 rules
eq: cloudkms.googleapis.com 2 rules
kubernetes.audit.stage 4 values
eq: responsecomplete 7 rules
T1098, Additional Container Cluster Roles T1098.006, Valid Accounts T1078, Container Administration Command T1609, Deploy Container T1610- Kubernetes Cluster-Admin Role Binding Created
- Kubernetes Creation or Modification of Sensitive Role
- Kubernetes Forbidden Request from Unusual User Agent
- Kubernetes Pod Creation Using Common Debug or Base Images
- Kubernetes Potential Endpoint Permission Enumeration Attempt Detected
- Kubernetes RBAC Wildcard Elevation on Existing Role
- Kubernetes Unusual Decision by User Agent
in: ResponseComplete 5 rules
in: ResponseStarted 5 rules
eq: ResponseComplete 2 rules
mnemonic 4 values
in: log 7 rules
- Cisco IOS XE Guestshell Activation and Destroy
- Cisco IOS XE Log Clearing Sequence With Optional Loopback Removal
- Cisco IOS XE Reconnaissance Command Activity
- Cisco IOS XE Remote Access Probe Burst
- Cisco IOS XE Request Platform Package Describe Shell Pattern
- Cisco IOS XE Tunnel Interface Configuration
- Cisco IOS XE VTY Access Class Tampering
in: aaa_accounting_message 5 rules
in: cfglog_loggedcmd 3 rules
eq: err_disable 2 rules
SignatureStatus 4 values
eq: trusted 6 rules
eq: unavailable 2 rules, 2 vendors
eq: errorBadDigest 2 rules
TI_ipEntity 4 values
ne: NO_IP 6 rules
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema)
- TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Web Session Events (ASIM Web Session schema)
- TI map IP entity to Web Session Events (ASIM Web Session schema)
eq: ActivityIPs 2 rules
eq: IPs 2 rules
eq: SigninIPs 2 rules
TargetDomainName 4 values
ne: NT AUTHORITY 4 rules
in: contoso 2 rules
in: contoso.local 2 rules
in: put your ad domains here! 2 rules
action_s 4 values
eq: anomalyscoring 4 rules
eq: block 4 rules
eq: Blocked 2 rules
eq: Matched 2 rules
dc_process 4 values
gt: 3 4 rules
lt: 10 4 rules
ge: 1 2 rules
user.effective.id 4 values
eq: 0 4 rules
starts_with: S-1-12- 4 rules
starts_with: S-1-5-21 4 rules
AccessMask 4 values
eq: 0x100 3 rules, 2 vendors
eq: 0x6 3 rules, 2 vendors
eq: 0x40000 2 rules, 2 vendors
AppId 4 values
eq: * 3 rules
eq: 00000003-0000-0000-c000-000000000000 2 rules
eq: FociClientApplications 2 rules
is_not_null: 2 rules
Esql.alerts_count 4 values
le: 5 3 rules
le: 10 2 rules
le: 20 2 rules
le: 50 2 rules
GroupName 4 values
in: privilegedroleadmins 3 rules
in: tenantadmins 3 rules
in: useraccountadmins 3 rules
in: privilegedauthenticationadmins 2 rules
OpNum 4 values
eq: 1 3 rules
eq: 0 2 rules
eq: 12 2 rules
TableName 4 values
is_not_null: 3 rules
eq: BankAccountTable 2 rules
eq: UserInfo 2 rules
ne: select 2 rules
azure_ad::signin_category 4 values
in: noninteractiveusersigninlogs 3 rules
in: signinlogs 3 rules
eq: NonInteractiveUserSignInLogs 2 rules
eq: serviceprincipalsigninlogs 2 rules
kubernetes.audit.user.username 4 values
is_null: 3 rules
starts_with: system:serviceaccount: 3 rules
in: system:anonymous 2 rules
in: system:unauthenticated 2 rules
m365::UserType 4 values
in: 0 3 rules
in: 10 3 rules
in: 2 3 rules
c-uri 4 values
contains: /mgmt/tm/util/bash 2 rules, 2 vendors
contains: /mshtml_c7/ 2 rules
contains: /powershell 2 rules
ends_with: .exe 2 rules
attachedMimeType 4 values
contains: rar 2 rules
contains: tar 2 rules
contains: x-7z-compressed 2 rules
contains: zip 2 rules
auditd.data.syscall 4 values
eq: mprotect 2 rules
eq: socket 2 rules
in: finit_module 2 rules
in: init_module 2 rules
dll.code_signature.status 4 values
eq: errorbaddigest 2 rules
eq: errorexpired 2 rules
eq: errorrevoked 2 rules
eq: erroruntrustedroot 2 rules
file_ext 4 values
in: .bat 2 rules
in: .ps1 2 rules
in: .scr 2 rules
in: .vbs 2 rules
process.executable.name 4 values
in: bash 2 rules
in: csh 2 rules
in: sh 2 rules
in: tcsh 2 rules
event.outcome 3 values
eq: success 369 rules
T1098, Valid Accounts T1078, Disable or Modify Tools T1562, Cloud Accounts T1078.004, Disable or Modify Tools T1562.001, Disable or Modify Cloud Log T1562.008- Access to Browser Credentials from Suspicious Memory
- Account Password Reset Remotely
- Authentication via Unusual PAM Grantor
- AWS Account Closed
- AWS Account Discovery By Rare User
- AWS API Activity from Uncommon S3 Client by Rare User
- AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN
- AWS Backup Recovery Point Deleted
eq: failure 23 rules
T1110, Password Guessing T1110.001, Password Spraying T1110.003, Credential Stuffing T1110.004, Account Manipulation T1098, Permission Groups Discovery T1069- Access Attempt to Non Existing Cryptocurrency Wallet
- AWS Bedrock Unauthorized Foundation Model Access Attempt
- AWS Bedrock Unauthorized Resource-Based Policy Modification Attempt
- AWS IAM Principal Enumeration via UpdateAssumeRolePolicy
- AWS Management Console Brute Force of Root User Identity
- Behavior - Detected - Elastic Defend
- Entra ID Excessive Account Lockouts Detected
- Entra ID Sign-in Brute Force Attempted (Microsoft 365)
process.code_signature.trusted 3 values
eq: false 115 rules
T1059, Unix Shell T1059.004, Credentials from Password Stores T1555, Event Triggered Execution T1546, Application Layer Protocol T1071, Masquerading T1036- Access to Windows Passwords Vault by Unusual Process
- BLF File Creation by an Unusual Process
- Browser Native Messaging Registry Modification
- Clipboard accessed by Unsigned or Untrusted Binary
- Code Editor Untrusted or Unsigned Child Process Execution
- Component Object Model Registry Modification by a Low Reputation Process
- Connection to Common Large Language Model Endpoints
- Crypto Wallet File Access by Unsigned or Untrusted Binary
eq: true 14 rules
- .NET COM object created in non-standard Windows Script Interpreter
- Browser Debugging from Unusual Parent
- DLL Side Loading of a file dropped by Microsoft Office
- DLL Side Loading via a Copied Microsoft Executable
- Ingress Tool Transfer via INET Cache
- Oversized DLL Creation followed by SideLoad
- Potential DLL Search Order Hijacking of an Existing Program
- Potential DLL SideLoad via a Renamed Signed Binary
ne: true 8 rules
- Connection to a Suspicious URL
- File Compressed or Archived into Common Format by Unsigned Process
- Persistence via BITS SetNotifyCmdLine Method
- Potential Decoy Document via User Execution
- Remcos RAT ExePath Registry Modification
- Suspicious Access to Web Browser Credential Stores
- Suspicious Execution from MSSQL Service
- Suspicious Windows Defender Exclusions Added via PowerShell
security_result.action 3 values
eq: ALLOW 102 rules
eq: BLOCK 17 rules
T1110, Valid Accounts T1078, Password Guessing T1110.001, Password Spraying T1110.003, Phishing T1566, Multi-Factor Authentication Request Generation T1621- AWS High Number Of Unknown User Authentication Attempts
- AWS IAM Access Denied Discovery Events
- AWS Successful Login After Multiple Failed Attempts
- AWS Unusual Number Of Failed Authentication Attempts From The Same IP
- GCP Excessive Permission Denied Events
- Hunt for Expired Tokens Attempting to sign-in to Entra ID
- Hunt for Office 365 group creation failures
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One
aws::errorMessage 3 values
is_null: 48 rules, 2 vendors
T1098, Additional Cloud Roles T1098.003, Domain or Tenant Policy Modification T1484, Transfer Data to Cloud Account T1537, Disable or Modify Tools T1562, Data Encrypted for Impact T1486- AWSCloudTrail - Amazon ECR image scanning disabled
- AWSCloudTrail - AWS GuardDuty detector disabled or suspended
- AWSCloudTrail - CloudFormation policy created then used for privilege escalation
- AWSCloudTrail - Created CRUD S3 policy and then privilege escalation
- AWSCloudTrail - Creating keys with encrypt policy without MFA
- AWSCloudTrail - Creation of CRUD DynamoDB policy and then privilege escalation
- AWSCloudTrail - Creation of CRUD KMS policy and then privilege escalation
- AWSCloudTrail - Creation of CRUD Lambda policy and then privilege escalation
eq: failed authentication 4 rules, 2 vendors
is_not_null: 2 rules, 2 vendors
stage 3 values
eq: responsecomplete 46 rules
eq: ResponseComplete 2 rules
is_not_null: 2 rules
process_id 3 values
ne: 4 44 rules
T1550, Pass the Ticket T1550.003, Steal or Forge Kerberos Tickets T1558, Kerberoasting T1558.003, AS-REP Roasting T1558.004, Remote Services T1021- Access Attempt to Non Existing Cryptocurrency Wallet
- Access to Browser Credentials from Suspicious Memory
- Asynchronous Procedure Call from Unusual Module
- BLF File Creation by an Unusual Process
- Delayed Common Language Runtime Load
- DLL Injection via MavInject Utility
- Execution of a File Dropped from Kernel Mode
- Failed Access Attempt to Web Browser Files
eq: 4 19 rules
T1021, SMB/Windows Admin Shares T1021.002, Lateral Tool Transfer T1570, Masquerading T1036, Invalid Code Signature T1036.001, Data Destruction T1485- Driver Dropped by Untrusted Executable
- Execution of a File Dropped from Kernel Mode
- Execution of a File Dropped from SMB
- Execution of a File Dropped from SMB via Services
- Expired or Revoked Driver Loaded
- ImageLoad of a File dropped via SMB
- Incoming Execution via WinRM Remote Shell
- Lateral Movement via Startup Folder
event.kind 3 values
eq: alert 38 rules, 2 vendors
- Adversary Behavior - Detected - Elastic Endgame
- Behavior - Detected - Elastic Defend
- Behavior - Prevented - Elastic Defend
- Container Workload Protection
- Credential Dumping - Detected - Elastic Endgame
- Credential Dumping - Prevented - Elastic Endgame
- Credential Manipulation - Detected - Elastic Endgame
- Credential Manipulation - Prevented - Elastic Endgame
eq: signal 9 rules
- AWS IAM Long-Term Access Key Correlated with Elevated Detection Alerts
- Deprecated - Unusual Discovery Activity by User
- FortiGate SSL VPN Login Followed by SIEM Alert by User
- LLM-Based Attack Chain Triage by Host
- LLM-Based Compromised User Triage by User
- Newly Observed High Severity Suricata Alert
- Potential Buffer Overflow Attack Detected
- Unusual Discovery Signal Alert with Unusual Process Command Line
eq: event 2 rules
graph.metadata.source_type 3 values
eq: GLOBAL_CONTEXT 20 rules
- AWS Successful API From Tor Exit Node
- GCP Successful API Call From Tor Exit Node
- GCTI Benign Binaries Contacts Tor Exit Node
- GCTI Remote Access Tools
- GCTI Tor Exit Nodes
- GitHub Personal Access Token Created from Tor IP Address
- Google Safebrowsing File Contacts Tor Exit Node
- Google Safebrowsing File Process Creation
eq: ENTITY_CONTEXT 10 rules
eq: DERIVED_CONTEXT 9 rules
ConfidenceScore 3 values
ge: 50 18 rules
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
ge: 80 18 rules
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity File Hash Indicators with Block Action Rule
- CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - High severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
lt: 80 18 rules
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
ProviderName 3 values
eq: IoTSecurity 15 rules
- Denial of Service (Microsoft Defender for IoT)
- Excessive Login Attempts (Microsoft Defender for IoT)
- Firmware Updates (Microsoft Defender for IoT)
- High bandwidth in the network (Microsoft Defender for IoT)
- Illegal Function Codes for ICS traffic (Microsoft Defender for IoT)
- Internet Access (Microsoft Defender for IoT)
- Multiple scans in the network (Microsoft Defender for IoT)
- No traffic on Sensor Detected (Microsoft Defender for IoT)
eq: MDATP 7 rules
- Aqua Blizzard AV hits - Feb 2022
- AV detections related to Dev-0530 actors
- AV detections related to Europium actors
- AV detections related to Hive Ransomware
- AV detections related to Zinc actors
- Malicious web application requests linked with Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) alerts
- Microsoft Defender for Endpoint (MDE) signatures for Azure Synapse pipelines and Azure Data Factory
HttpRequestMethod 3 values
eq: get 12 rules
- Apache - Apache 2.4.49 flaw CVE-2021-41773
- Cloudflare - Multiple error requests from single source
- Cloudflare - Multiple error requests from single source
- Cloudflare - Unexpected client request
- Cloudflare - Unexpected client request
- Cloudflare - Unexpected URI
- Cloudflare - Unexpected URI
- Detect potential file enumeration activity (ASIM Web Session)
in: post 12 rules
- Apache - Put suspicious file
- Cisco WSA - Unexpected uploads
- Cloudflare - Unexpected POST requests
- Cloudflare - Unexpected POST requests
- Cloudflare - XSS probing pattern in request
- Cloudflare - XSS probing pattern in request
- Detect potential presence of a malicious file with a double extension (ASIM Web Session)
- Imperva - Forbidden HTTP request method in request
in: put 12 rules
- Apache - Put suspicious file
- Cisco WSA - Unexpected uploads
- Cloudflare - Unexpected POST requests
- Cloudflare - Unexpected POST requests
- Cloudflare - XSS probing pattern in request
- Cloudflare - XSS probing pattern in request
- Detect potential presence of a malicious file with a double extension (ASIM Web Session)
- Imperva - Forbidden HTTP request method in request
body.current_thread.links 3 values
length_compare: 0 12 rules
- Brand impersonation: Bids & Tenders
- Cloud storage impersonation with credential theft indicators
- Extortion / sextortion (untrusted sender)
- Link: BEC with newly registered domains and financial keywords
- Link: Document sharing invitation template
- Link: Multiple HTTP protocols in single URL
- Link: Self-sender with IP geolocation check and suspicious link behavior
- Link: Self-sender with sender org in subject and credential theft indicator
length_compare: 10 9 rules
- Brand impersonation: Bids & Tenders
- Cloud storage impersonation with credential theft indicators
- Job scam with specific salary pattern
- Link abuse: Self-service creation platform link with suspicious recipient behavior
- Link: Multiple HTTP protocols in single URL
- Link: Self-sender with IP geolocation check and suspicious link behavior
- Link: Suspicious recipient with timeout redirect
- Link: Tycoon2FA phishing kit (non-exhaustive)
category 3 values
eq: signinlogs 12 rules
T1586, Cloud Accounts T1586.003, Valid Accounts T1078, Brute Force T1110, Cloud Accounts T1078.004, Password Spraying T1110.003- Azure AD Authentication Failed During MFA Challenge
- Azure AD Device Code Authentication
- Azure AD High Number Of Failed Authentications For User
- Azure AD High Number Of Failed Authentications From Ip
- Azure AD Multiple AppIDs and UserAgents Authentication Spike
- Azure AD Multiple Denied MFA Requests For User
- Azure AD Multiple Failed MFA Requests For User
- Azure AD Multiple Users Failing To Authenticate From Ip
All_Changes.action 3 values
eq: created 11 rules
T1078, Default Accounts T1078.001, Account Manipulation T1098, Device Registration T1098.005- Cloud Compute Instance Created By Previously Unseen User
- Cloud Compute Instance Created In Previously Unused Region
- Cloud Compute Instance Created With Previously Unseen Image
- Cloud Compute Instance Created With Previously Unseen Instance Type
- Cloud Provisioning Activity From Previously Unseen City
- Cloud Provisioning Activity From Previously Unseen Country
- Cloud Provisioning Activity From Previously Unseen IP Address
- Cloud Provisioning Activity From Previously Unseen Region
eq: started 4 rules
EmailSenderAddress 3 values
is_not_null: 11 rules
- Preview - TI map Email entity to Cloud App Events
- ProofpointPOD - Email sender in TI list
- ThreatConnect TI map Email entity to OfficeActivity
- ThreatConnect TI map Email entity to SigninLogs
- TI map Email entity to AzureActivity
- TI map Email entity to EmailEvents
- TI map Email entity to OfficeActivity
- TI map Email entity to PaloAlto CommonSecurityLog
eq: OfficeActivityUPNs 2 rules
eq: SigninUPNs 2 rules
DvcAction 3 values
eq: allowed 8 rules
- Cisco Cloud Security - Connection to non-corporate private network
- Cisco Cloud Security - Request Allowed to harmful/malicious URI category
- Cisco Cloud Security - Request to blocklisted file type
- Cisco Cloud Security - URI contains IP address
- Cisco Umbrella - Connection to non-corporate private network
- Cisco Umbrella - Request Allowed to harmful/malicious URI category
- Cisco Umbrella - Request to blocklisted file type
- Cisco Umbrella - URI contains IP address
eq: open 4 rules
eq: close 2 rules
process.Ext.api.metadata.target_address_name 3 values
eq: Unbacked 8 rules
- Memory Allocation from a High Entropy Module
- Potential Shellcode Fluctuation v1
- Potential Shellcode Injection via a WebShell
- Shellcode API behavior from a signed module
- Shellcode behavior from suspicious RWX provenance
- Shellcode Behavior via .NET Core
- Suspicious File Memory Mapping via Managed .NET
- Suspicious Memory Protection Change via VirtualProtect
starts_with: ? 3 rules
eq: mswsock.dll 2 rules
EventCategory 3 values
eq: firewall 7 rules
in: DKIMConfiguration 2 rules
in: SPFConfiguration 2 rules
execve_command 3 values
in: *find* 7 rules
T1083, Credentials from Password Stores T1555, Password Managers T1555.005, Unsecured Credentials T1552, Private Keys T1552.004- Linux Auditd Database File And Directory Discovery
- Linux Auditd File And Directory Discovery
- Linux Auditd Find Credentials From Password Managers
- Linux Auditd Find Credentials From Password Stores
- Linux Auditd Find Ssh Private Keys
- Linux Auditd Private Keys and Certificate Enumeration
- Linux Auditd Virtual Disk File And Directory Discovery
in: *grep* 7 rules
T1083, Credentials from Password Stores T1555, Password Managers T1555.005, Unsecured Credentials T1552, Private Keys T1552.004- Linux Auditd Database File And Directory Discovery
- Linux Auditd File And Directory Discovery
- Linux Auditd Find Credentials From Password Managers
- Linux Auditd Find Credentials From Password Stores
- Linux Auditd Find Ssh Private Keys
- Linux Auditd Private Keys and Certificate Enumeration
- Linux Auditd Virtual Disk File And Directory Discovery
in: *.key* 2 rules
okta::outcome.result 3 values
eq: SUCCESS 6 rules, 2 vendors
eq: success 4 rules, 2 vendors
sha256 3 values
is_not_null: 6 rules, 2 vendors
contains: sha256hashes 3 rules
eq: c92c158d7c37fea795114fa6491fe5f145ad2f8c08776b18ae79db811e8e36a3 2 rules
azure.platformlogs.category 3 values
in: kube-audit 6 rules
T1557, Steal or Forge Authentication Certificates T1649, Steal Application Access Token T1528, Indicator Removal T1070, Permission Groups Discovery T1069, Cloud Groups T1069.003- Azure AKS Certificate Signing Request Created or Approved
- Azure AKS CoreDNS or Kube-DNS Configuration Modified
- Azure AKS Ephemeral Container Added to Pod
- Azure AKS Kubernetes Events Deleted
- Azure AKS Service Account Token Created via TokenRequest API
- Azure AKS Suspicious Self-Subject Review by Service Account or Node Identity
in: kube-audit-admin 6 rules
T1557, Steal or Forge Authentication Certificates T1649, Steal Application Access Token T1528, Indicator Removal T1070, Permission Groups Discovery T1069, Cloud Groups T1069.003- Azure AKS Certificate Signing Request Created or Approved
- Azure AKS CoreDNS or Kube-DNS Configuration Modified
- Azure AKS Ephemeral Container Added to Pod
- Azure AKS Kubernetes Events Deleted
- Azure AKS Service Account Token Created via TokenRequest API
- Azure AKS Suspicious Self-Subject Review by Service Account or Node Identity
c_process 3 values
graph.metadata.vendor_name 3 values
eq: VirusTotal 6 rules
eq: WHOIS 5 rules
eq: Google Cloud Threat Intelligence 4 rules
http.response.status_code 3 values
eq: 200 6 rules
- Entra ID External Authentication Methods (EAM) Modified
- Inbound Connection to an Unsecure Elasticsearch Node
- Microsoft Graph Request User Impersonation by Unusual Client
- Web Server Local File Inclusion Activity
- Web Server Potential Command Injection Request
- Web Server Potential Remote File Inclusion Activity
in: 303 2 rules
in: 500 2 rules
LogonProcessName 3 values
eq: seclogo 5 rules, 2 vendors
eq: ntlmssp 2 rules
starts_with: Advapi 2 rules
SubjectUserSid 3 values
starts_with: S-1-5-21- 5 rules
eq: s-1-5-18 4 rules, 3 vendors
starts_with: S-1-5-21 2 rules, 2 vendors
additional.fields["msg_1"] 3 values
regex_match: ^AU1$|^AU5$ 5 rules
eq: AU7 3 rules
file.size 3 values
ge: 30000 5 rules
gt: 0 3 rules
ge: 100000000 2 rules
http.request.method 3 values
eq: get 5 rules
eq: post 5 rules
- Potential Toolshell Initial Exploit (CVE-2025-53770 & CVE-2025-53771)
- Potential VIEWSTATE RCE Attempt on SharePoint/IIS
- Splunk Enterprise PostgreSQL Backup-to-Restore Potential RCE Sequence
- Splunk Enterprise PostgreSQL Recovery Endpoint Injection Artifacts
- Web Application Suspicious Activity: POST Request Declined
okta::outcome.reason 3 values
in: invalid_credentials 5 rules
in: locked_out 5 rules
source_count 3 values
ge: 4 5 rules
ge: 2 3 rules
TicketOptions 3 values
eq: 0x40810000 4 rules, 3 vendors
eq: 0x40800000 2 rules
NetworkApplicationProtocol 3 values
eq: smtp 4 rules
in: http 2 rules
in: https 2 rules
appDisplayName 3 values
contains: copilot 4 rules
eq: m365chatclient 4 rules
eq: officeaiappchatcopilot 3 rules
body.plain.raw 3 values
regex_match: [\x{1F300}-\x{1F5FF}\x{1F600}-\x{1F64F}\x{1F680}-\x{1F6FF}\x{1F700}-\x{1F77F}\x{1F780}-\x{1F7FF}\x{1F900}-\x{1F9FF}\x{2600}-\x{26FF}\x{2700}-\x{27BF}\x{2300}-\x{23FF}] 4 rules
is_null: 3 rules
regex_match: ^\s*$ 2 rules
method 3 values
in: post 4 rules
in: put 4 rules
eq: post 2 rules, 2 vendors
response.statusCode 3 values
in: 401 4 rules
in: 403 4 rules
eq: 200 2 rules
result 3 values
eq: exploited 4 rules
eq: true 3 rules
eq: success 2 rules
strings.icontains 3 values
func_call: strings.icontains(body.current_thread.text) 4 rules
func_call: strings.icontains(subject.subject) 4 rules
func_call: strings.icontains(sender.display_name) 3 rules
objectRef.namespace 3 values
in: kube-public 3 rules, 2 vendors
in: kube-system 3 rules, 2 vendors
ne: kube-system 2 rules
Company 3 values
eq: anydesk software gmbh 3 rules
eq: microsoft corporation 2 rules, 2 vendors
eq: logmein, inc. 2 rules
EventMessage 3 values
eq: login 3 rules
contains: behavior monitoring 2 rules
eq: user's password changed 2 rules
TargetUserSid 3 values
eq: s-1-5-7 3 rules
starts_with: S-1-5-21- 3 rules
Total 3 values
gt: 15 3 rules
gt: 25 2 rules
aws::userIdentity.accessKeyId 3 values
starts_with: AKIA 3 rules
is_not_null: 2 rules
group.name 3 values
eq: ACCOUNT 3 rules
eq: LOGIN 2 rules
is_not_null: 2 rules
headers.auth_summary.spf.details.designator 3 values
ends_with: .dropbox.com 3 rules
contains: +srs= 2 rules
ends_with: .intuit.com 2 rules
headers.return_path.domain.domain 3 values
eq: sendgrid.net 3 rules
cross_field_compare: sender.email.domain.domain 2 rules
ne: calendar-server.bounces.google.com 2 rules
responseElements.ConsoleLogin 3 values
eq: Failure 3 rules
eq: Success 2 rules
eq: failure 2 rules
subsystem 3 values
eq: com.apple.sudo 3 rules
eq: com.apple.tcc 3 rules
eq: com.apple.securityd 2 rules
Attributes 3 values
contains: cdc: 2 rules
contains: certificatetemplate: 2 rules
Changes 3 values
in: failure removed 2 rules
in: success removed 2 rules
in: success removed, failure removed 2 rules
EventCategoryType 3 values
in: exchange 2 rules
in: exchangeserver 2 rules
in: gmail 2 rules
EventResultDetails 3 values
in: nxdomain 2 rules
in: refused 2 rules
in: servfail 2 rules
PipeName 3 values
eq: \psexesvc 2 rules
eq: \sdlrpc 2 rules
starts_with: \PSHost 2 rules
SrcGeoCountry 3 values
in: cn 2 rules
in: hk 2 rules
azure.activitylogs.operation_name 3 values
eq: microsoft.compute/snapshots/delete 2 rules
eq: microsoft.kubernetes/connectedclusters/listclusterusercredential/action 2 rules
eq: microsoft.storage/storageaccounts/delete 2 rules
cs-uri-stem 3 values
contains: .jsp 2 rules
contains: /irj/ 2 rules
contains: /oauth/idp/.well-known/openid-configuration 2 rules
dll.Ext.defense_evasions 3 values
eq: process tampering: code integrity violation 2 rules
eq: process tampering: image has been accessed before mapping 2 rules
eq: process tampering: image is writable 2 rules
level 3 values
eq: error 2 rules
in: Critical 2 rules
in: High 2 rules
okta::severity 3 values
eq: High 2 rules
in: critical 2 rules
in: high 2 rules
operation 3 values
eq: rpcaddprintprocessor 2 rules
eq: rpcasyncaddprintprocessor 2 rules
wildcard: REST.*.OBJECT 2 rules
process.Ext.api.parameters.buffer 3 values
contains: http 2 rules
contains: while ( 2 rules
contains: while( 2 rules
process.name.caseless 3 values
in: powershell.exe 2 rules
in: powershell_ise.exe 2 rules
in: pwsh.exe 2 rules
security_result.category_details 3 values
eq: APPLICATION_SETTINGS 2 rules
eq: DELEGATED_ADMIN_SETTINGS 2 rules
eq: USER_SETTINGS 2 rules
target.application 3 values
eq: cloudresourcemanager.googleapis.com 2 rules
eq: iam.amazonaws.com 2 rules
eq: storage.googleapis.com 2 rules
xamzacl 3 values
in: authenticated-read 2 rules
in: public-read 2 rules
in: public-read-write 2 rules
{}.RequiredAppPermissions{}.EntitlementId 3 values
eq: 06b708a9-e830-4db3-a914-8e69da51d44f 2 rules
eq: 9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8 2 rules
eq: dc890d15-9560-4a4c-9b7f-a736ec74ec40 2 rules
process.code_signature.exists 2 values
eq: false 119 rules
T1059, Unix Shell T1059.004, Credentials from Password Stores T1555, Event Triggered Execution T1546, Application Layer Protocol T1071, Unsecured Credentials T1552- Access to Windows Passwords Vault by Unusual Process
- BLF File Creation by an Unusual Process
- Browser Native Messaging Registry Modification
- Clipboard accessed by Unsigned or Untrusted Binary
- Code Editor Untrusted or Unsigned Child Process Execution
- Common Language Runtime Loaded via an Unsigned Module
- Component Object Model Registry Modification by a Low Reputation Process
- Connection to Common Large Language Model Endpoints
resultType 2 values
in: Succeeded 51 rules
in: Success 51 rules
headers.in_reply_to 2 values
is_null: 45 rules
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
- Attachment with auto-executing macro (unsolicited)
- Attachment: Adobe image lure in body or attachment with suspicious link
- Attachment: Callback phishing solicitation via pdf file
- Attachment: EML file contains HTML attachment with login portal indicators
- Attachment: Legal themed message or PDF with suspicious indicators
- Attachment: Microsoft 365 credential phishing
- BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
headers.auth_summary.dmarc.pass 2 values
eq: true 36 rules
- Brand impersonation: Adobe with suspicious language and link
- Brand impersonation: QuickBooks notification from Intuit themed company name
- Callback phishing via Adobe Sign comment
- Callback phishing via DocuSign comment
- Callback phishing via e-signature service
- Callback phishing via Intuit service abuse
- Callback Phishing via Signable E-Signature Request
- Callback phishing via SignFree e-signature request
is_null: 6 rules
- BEC with unusual reply-to or return-path mismatch
- Brand impersonation: Adobe with suspicious language and link
- Brand impersonation: Microsoft with embedded logo and credential theft language
- Display Name Emoji with Financial Symbols
- Extortion / sextortion (untrusted sender)
- Impersonation: Human Resources with link or attachment and engaging language
process.thread.Ext.call_stack_final_user_module.hash.sha256 2 values
is_not_null: 30 rules
- Asynchronous Procedure Call from Unusual Module
- Direct Syscall from Unsigned Module
- Image Hollow from Unusual Stack
- Keystroke Input Capture via RegisterRawInputDevices
- Keystroke Messages Hooking via SetWindowsHookEx
- Keystrokes Input Capture from Suspicious CallStack
- LSASS Memory Read via PPL Bypass
- Memory Allocation from a High Entropy Module
starts_with: ? 3 rules
recipients.cc 2 values
length_compare: 0 27 rules
- Attachment: Callback phishing solicitation via image file
- Body: HTML whitespace stuffing with short initial message
- Brand impersonation: Norton
- Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
- Callback phishing: AOL senders with suspicious HTML template or PDF attachment
- Credential phishing: Generic document sharing
- Credential Phishing: Suspicious language, link, recipients and other indicators
- Free subdomain link with credential theft indicators
length_compare: 1 4 rules
container.id 2 values
wildcard: * 26 rules
T1059, Unix Shell T1059.004, Permission Groups Discovery T1069, Account Discovery T1087, Container Administration Command T1609, Deploy Container T1610- Cloud Credential Search Detected via Defend for Containers
- Container Management Utility Execution Detected via Defend for Containers
- DebugFS Execution Detected via Defend for Containers
- Direct Interactive Kubernetes API Request by Common Utilities
- Direct Interactive Kubernetes API Request by Unusual Utilities
- Direct Kubernetes API Request Detected via Defend for Containers
- DNS Enumeration Detected via Defend for Containers
- Dynamic Linker Modification Detected via Defend for Containers
starts_with: ? 22 rules
- Chroot Execution Detected via Defend for Containers
- Curl SOCKS Proxy Detected via Defend for Containers
- Decoded Payload Piped to Interpreter Detected via Defend for Containers
- Encoded Payload Detected via Defend for Containers
- File Creation and Execution Detected via Defend for Containers
- File Download Detected via Defend for Containers
- File Execution Permission Modification Detected via Defend for Containers
- Modification of Persistence Relevant Files Detected via Defend for Containers
Web.status 2 values
eq: 200 25 rules
- Adobe ColdFusion Access Control Bypass
- Adobe ColdFusion Unauthenticated Arbitrary File Read
- Cisco IOS XE Implant Access
- Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure
- Citrix ADC and Gateway Unauthorized Data Disclosure
- Confluence CVE-2023-22515 Trigger Vulnerability
- Confluence Data Center and Server Privilege Escalation
- ConnectWise ScreenConnect Authentication Bypass
in: 200 2 rules
kubernetes.audit.annotations.authorization_k8s_io/decision 2 values
eq: allow 25 rules
T1098, Additional Container Cluster Roles T1098.006, Deploy Container T1610, Escape to Host T1611, Container Administration Command T1609, Permission Groups Discovery T1069- EKS Authentication Configuration Modified
- Kubernetes Admission Webhook Created or Modified
- Kubernetes Anonymous Request Authorized by Unusual User Agent
- Kubernetes API Request Impersonating Privileged Identity
- Kubernetes Client Certificate Signing Request Created or Approved
- Kubernetes Cluster-Admin Role Binding Created
- Kubernetes Container Created with Excessive Linux Capabilities
- Kubernetes CoreDNS or Kube-DNS Configuration Modified
Resource 2 values
eq: * 23 rules
T1098, Additional Cloud Roles T1098.003, Domain or Tenant Policy Modification T1484- AWSCloudTrail - CloudFormation policy created then used for privilege escalation
- AWSCloudTrail - Created CRUD S3 policy and then privilege escalation
- AWSCloudTrail - Creation of CRUD DynamoDB policy and then privilege escalation
- AWSCloudTrail - Creation of CRUD KMS policy and then privilege escalation
- AWSCloudTrail - Creation of CRUD Lambda policy and then privilege escalation
- AWSCloudTrail - Creation of DataPipeline policy and then privilege escalation
- AWSCloudTrail - Creation of EC2 policy and then privilege escalation
- AWSCloudTrail - Creation of Glue policy and then privilege escalation
starts_with: http 2 rules, 2 vendors
body.previous_threads 2 values
length_compare: 0 23 rules
- Brand impersonation: Internal Revenue Service
- Brand impersonation: Meta and subsidiaries
- Brand Impersonation: PayPal
- Business Email Compromise: Request for mobile number via reply thread hijacking
- Credential phishing: Blue button styled link with file-sharing template artifacts
- Fake Zoom meeting invite with suspicious link
- Fraudulent order confirmation/shipping notification from Chinese sender domain
- Headers: Fake in-reply-to with wildcard sender and missing thread context
length_compare: 1 5 rules
- Attachment: Identity Confirmation With Document Unlock Code
- BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
- Spam: Personalized subject and greetings via Salesforce Marketing Cloud
- VIP impersonation: Fake thread with VIPs missing email metadata
- VIP Impersonation: VIP handoff with fake forwarded invoice thread
jevt.rawtime 2 values
is_not_null: 23 rules
MessageType 2 values
eq: 2 21 rules
dll.code_signature.trusted 2 values
eq: false 21 rules
- DLL Loaded from a Macro Enabled Document
- DLL Side Loading of a file dropped by Microsoft Office
- Evasion via LdrpKernel32 Overwrite
- Execution of a File Downloaded via Windows OpenSSH
- Known Desktop Application DLL Search Order Hijack
- Library Loaded via a CallBack Function
- Library Loaded via Thread Fiber CallBack
- Microsoft Office AddIn Loaded
RecommendedActions 2 values
contains: block 18 rules
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity File Hash Indicators with Block Action Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
contains: monitor 18 rules
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - High severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
priority_s 2 values
eq: P1 16 rules
eq: P2 16 rules
network.http.method 2 values
eq: GET 14 rules
T1048, Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.002- API access to mailboxes for top N messages via the Microsoft Graph
- Entra ID application enumeration observed in the Microsoft Graph API
- Enumeration observed in the Microsoft Graph API using GraphRunner GraphRecon command
- Enumeration of inboxes accessible by a user in the Microsoft Graph API
- Enumeration of updatable groups in the Microsoft Graph API
- Enumeration of users and group membership observed in the Microsoft Graph API
- Hunt for application API calls in the Microsoft Graph
- Hunt for authorization policy API calls in the Microsoft Graph
eq: POST 7 rules
- Enumeration observed in the Microsoft Graph API using GraphRunner GraphRecon command
- Enumeration of updatable groups in the Microsoft Graph API
- Hunt for Bad Request errors against the Groups endpoint in the Microsoft Graph API
- Hunt for search/query endpoint API requests in the Microsoft Graph
- Hunt for successful group creation in the Microsoft Graph API
- Hunt for Undocumented API - Estimate Access called in Microsoft Graph API
- SharePoint CVE-2025-49706 Exploitation
recipients.to[0].email.domain.valid 2 values
eq: true 14 rules
- Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
- Attachment: EML with QR code redirecting to Cloudflare challenges
- Attachment: PDF with credential theft language and invalid reply-to domain
- Attachment: QR code with recipient targeting and special characters
- Attachment: QR code with suspicious URL patterns in EML file
- Link: Commonly Abused Web Service redirecting to ZIP file
- Link: Credential theft with invisible Unicode character in page title from unsolicited sender
- Link: JavaScript obfuscation with Telegram bot integration
eq: false 9 rules
- Attachment: PDF with localhost IP in EXIF title metadata
- Attachment: PDF with self-service platform links with self sender or blank recipients
- Attachment: Self-sender PDF with minimal content and view prompt
- Brand impersonation: Bids & Tenders
- Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
- Link: PDF filename impersonation with credential theft language
- Link: Self-sent message with quarterly document review request
- Link: Single character path with credential theft body and self sender behavior or invalid recipient
process.parent.user.id 2 values
ne: 0 13 rules
- Potential Local Privilege Escalation via Unshare
- Potential Privilege Escalation via a Known SUID/SGID Binary
- Potential Privilege Escalation via a Parent Process Sequence
- Potential Privilege Escalation via a Parent Process Sequence
- Potential Privilege Escalation via a Parent/Child Process Sequence
- Potential Privilege Escalation via a Parent/Child Process Sequence
- Potential Privilege Escalation via a SUID/SGID Binary
- Potential Privilege Escalation via a Suspicious UID Change
ge: 1000 2 rules
network.http.response_code 2 values
eq: 200 12 rules
- API access to mailboxes for top N messages via the Microsoft Graph
- Entra ID application enumeration observed in the Microsoft Graph API
- Enumeration observed in the Microsoft Graph API using GraphRunner GraphRecon command
- Enumeration of updatable groups in the Microsoft Graph API
- Enumeration of users and group membership observed in the Microsoft Graph API
- Hunt for application API calls in the Microsoft Graph
- Hunt for authorization policy API calls in the Microsoft Graph
- Hunt for group members enumeration in the Microsoft Graph API
azure_ad::logged_by_service 2 values
eq: core directory 11 rules, 2 vendors
T1078, Cloud Accounts T1078.004, Account Manipulation T1098, Additional Cloud Roles T1098.003, Use Alternate Authentication Material T1550, Steal Application Access Token T1528- [Entra ID] Application Assigned Administrator Permissions Immediately After Obtaining Role Management Permissions
- [Entra ID] Application Granted Administrative Permission to Assign Microsoft Entra ID Roles
- Admin promotion after Role Management Application Permission Grant
- full_access_as_app Granted To Application
- Microsoft Entra ID Role Management Permission Grant
- NRT Privileged Role Assigned Outside PIM
- Privileged Role Assigned Outside PIM
- Suspicious application consent for offline access
eq: authentication methods 2 rules, 2 vendors
azure_ad::user_type 2 values
eq: member 11 rules
T1078, Cloud Accounts T1078.004, Use Alternate Authentication Material T1550, Application Access Token T1550.001, Steal Application Access Token T1528, Brute Force T1110- Entra ID ADRS Token Request by Microsoft Authentication Broker
- Entra ID Conditional Access MFA Bypass with Unusual User, Client and Source ASN
- Entra ID MFA TOTP Brute Force Attempted
- Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource
- Entra ID OAuth Flow by Microsoft Authentication Broker to Device Registration Service (DRS)
- Entra ID OAuth ROPC Grant Login Detected
- Entra ID OAuth user_impersonation Scope for Unusual User and Client
- Entra ID User Sign-In via Unusual Legacy Authentication Client
kibana.alert.risk_score 2 values
gt: 21 11 rules
- Alerts From Multiple Integrations by Destination Address
- Alerts From Multiple Integrations by Source Address
- Alerts From Multiple Integrations by User Name
- Alerts in Different ATT&CK Tactics by Host
- FortiGate SSL VPN Login Followed by SIEM Alert by User
- LLM-Based Attack Chain Triage by Host
- LLM-Based Compromised User Triage by User
- Multiple Alerts in Same ATT&CK Tactic by Host
ge: 73 2 rules
process.parent.group.id 2 values
ne: 0 11 rules
- Potential Privilege Escalation via a Known SUID/SGID Binary
- Potential Privilege Escalation via a Parent Process Sequence
- Potential Privilege Escalation via a Parent Process Sequence
- Potential Privilege Escalation via a Parent/Child Process Sequence
- Potential Privilege Escalation via a Parent/Child Process Sequence
- Potential Privilege Escalation via a SUID/SGID Binary
- Potential Privilege Escalation via a Suspicious UID Change
- Potential Privilege Escalation via a Suspicious UID Change
ge: 1000 2 rules
action_id_s 2 values
contains: bcm 10 rules
- Affected rows stateful anomaly on database
- Credential errors stateful anomaly on database
- Drop attempts stateful anomaly on database
- Execution attempts stateful anomaly on database
- Firewall errors stateful anomaly on database
- Firewall rule manipulation attempts stateful anomaly on database
- OLE object manipulation attempts stateful anomaly on database
- Outgoing connection attempts stateful anomaly on database
contains: rcm 10 rules
- Affected rows stateful anomaly on database
- Credential errors stateful anomaly on database
- Drop attempts stateful anomaly on database
- Execution attempts stateful anomaly on database
- Firewall errors stateful anomaly on database
- Firewall rule manipulation attempts stateful anomaly on database
- OLE object manipulation attempts stateful anomaly on database
- Outgoing connection attempts stateful anomaly on database
uid 2 values
is_not_null: 10 rules
Signed 2 values
eq: false 9 rules, 2 vendors
T1574, DLL T1574.001, OS Credential Dumping T1003, LSASS Memory T1003.001, Masquerading T1036, Match Legitimate Resource Name or Location T1036.005- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded
- Unsigned .node File Loaded
- Unsigned Image Loaded Into LSASS Process
- Unsigned Module Loaded by ClickOnce Application
- UAC Bypass MMC Load Unsigned Dll
- Windows Hijack Execution Flow Version Dll Side Load
- Windows Unsigned DLL Side-Loading
- Windows Unsigned DLL Side-Loading In Same Process Path
CommonSecurityLog_TimeGenerated 2 values
cross_field_compare: ValidUntil 9 rules
- HoneyLabs TI Map IP Entity to CommonSecurityLog
- HoneyLabs TI Map URL Entity to CommonSecurityLog
- Lumen TI IPAddress in CommonSecurityLog
- TI Map Domain entity to PaloAlto
- TI Map Domain entity to PaloAlto CommonSecurityLog
- TI Map Email entity to PaloAlto CommonSecurityLog
- TI Map File Hash to CommonSecurityLog Event
- TI Map IP Entity to CommonSecurityLog
cross_field_compare: ExpirationDateTime 7 rules
RoleName 2 values
contains: admin 9 rules
T1078, Cloud Accounts T1078.004, Account Manipulation T1098, Additional Cloud Credentials T1098.001- [Entra ID] Mass Privileged Role Change Activity Detected
- [Entra ID] Privileged Role Assigned to a New User
- [Entra ID] Privileged Role Assigned to User
- Bulk Changes to Privileged Account Permissions
- New External User Granted Admin Role
- New User Assigned to Privileged Role
- Threat Essentials - User Assigned Privileged Role
- User Added to Admin Role
eq: global administrator 2 rules
beta.profile.by_reply_to 2 values
func_call: beta.profile.by_reply_to().prevalence == new 8 rules
- HR impersonation via e-sign agreement comment
- Link: Multistage landing - Abused Google Drive
- Link: Secure SharePoint file share from new or unusual sender
- Service abuse: Adobe Sign notification from an unsolicited reply-to address
- Service abuse: DocuSign notification with suspicious sender or document name
- Service abuse: Dropbox share from an unsolicited reply-to address
- Service abuse: Google Drive share from an unsolicited reply-to address
- Service Abuse: Zoom with freemail reply-to and recipient address in greeting
func_call: beta.profile.by_reply_to().any_messages_malicious_or_spam 3 rules
dc_host 2 values
http_method 2 values
eq: post 8 rules
- Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity
- HTTP Rapid POST with Mixed Status Codes
- JetBrains TeamCity Authentication Bypass Suricata CVE-2024-27198
- Multiple Archive Files Http Post Traffic
- Nginx ConnectWise ScreenConnect Authentication Bypass
- Plain HTTP POST Exfiltrated Data
- Suspicious Java Classes
- Web Spring4Shell HTTP Request Class Module
okta::actor.alternateId 2 values
is_not_null: 7 rules, 2 vendors
T1110, Password Guessing T1110.001, Password Spraying T1110.003, Credential Stuffing T1110.004, Valid Accounts T1078, Cloud Accounts T1078.004- Okta Successful Login After Credential Attack
- Potential Okta Brute Force (Device Token Rotation)
- Potential Okta Brute Force (Multi-Source)
- Potential Okta Credential Stuffing (Single Source)
- Potential Okta Password Spray (Multi-Source)
- Potential Okta Password Spray (Single Source)
- Failed Logins from Unknown or Invalid User
DestinationIP 2 values
is_not_null: 7 rules
- Fortinet - Beacon pattern detected
- Threat Essentials - Time series anomaly for data size transferred to public internet
- Time series anomaly detection for total volume of traffic
- Time series anomaly for data size transferred to public internet
- Whisper Security - BGP Route Anomaly with Traffic Spike
- Whisper Security - C2 Communication Detection
- Whisper Security - Tor Exit Node Communication
EventSubType 2 values
ne: AttackAttempt 7 rules
- CyberArkEPM - MSBuild usage as LOLBin
- CyberArkEPM - Possible execution of Powershell Empire
- CyberArkEPM - Process started from different locations
- CyberArkEPM - Renamed Windows binary
- CyberArkEPM - Uncommon Windows process started from System folder
- CyberArkEPM - Unexpected executable extension
- CyberArkEPM - Unexpected executable location
eq: attackattempt 2 rules
SuspiciousLevel 2 values
eq: high suspicious attack 7 rules
- AIShield - Image classification AI Model Evasion high suspicious vulnerability detection
- AIShield - Image classification AI Model extraction high suspicious vulnerability detection
- AIShield - Image Segmentation AI Model extraction high suspicious vulnerability detection
- AIShield - Natural language processing AI model extraction high suspicious vulnerability detection
- AIShield - Tabular classification AI Model Evasion high suspicious vulnerability detection
- AIShield - Tabular classification AI Model extraction high suspicious vulnerability detection
- AIShield - Timeseries Forecasting AI Model extraction high suspicious vulnerability detection
eq: low suspicious attack 2 rules
endgame.metadata.type 2 values
eq: detection 7 rules
- Credential Dumping - Detected - Elastic Endgame
- Credential Manipulation - Detected - Elastic Endgame
- Exploit - Detected - Elastic Endgame
- Malware - Detected - Elastic Endgame
- Permission Theft - Detected - Elastic Endgame
- Process Injection - Detected - Elastic Endgame
- Ransomware - Detected - Elastic Endgame
eq: prevention 7 rules
- Credential Dumping - Prevented - Elastic Endgame
- Credential Manipulation - Prevented - Elastic Endgame
- Exploit - Prevented - Elastic Endgame
- Malware - Prevented - Elastic Endgame
- Permission Theft - Prevented - Elastic Endgame
- Process Injection - Prevented - Elastic Endgame
- Ransomware - Prevented - Elastic Endgame
event_platform 2 values
eq: Win 7 rules
eq: Mac 3 rules
filter(attachments, .file_type == 'pdf') 2 values
length_compare: 1 7 rules
- Attachment: PDF proposal with credential theft indicators
- Attachment: PDF with password in filename matching body text
- Attachment: PDF with personal Microsoft OneNote URL
- Attachment: PDF with recipient email in link
- Attachment: PDF with specific author metadata
- Attachment: PDF with suspicious link and action-oriented language
- Brand Impersonation: ShareFile
message_id 2 values
in: 111008 7 rules
in: 111010 7 rules
objectRef.subresource 2 values
is_null: 7 rules
is_not_null: 2 rules
prefix 2 values
process.parent.interactive 2 values
eq: false 7 rules
- Payload Downloaded via Curl or Wget by Web Server
- Payload Execution by Node.js Web Server
- Payload Execution by Web Server
- Potential Remote Code Execution via Database Server
- Potential Remote Code Execution via Mail Server
- Suspicious Web Server Child Process
- Web Server Exploitation Detected via Defend for Containers
eq: true 2 rules
source.as.organization.name 2 values
is_not_null: 7 rules
T1552, Account Discovery T1087, Cloud Account T1087.004, Serverless Execution T1648, Valid Accounts T1078, Cloud Accounts T1078.004- AWS AssumeRoleWithWebIdentity from Kubernetes SA and External ASN
- AWS Credentials Used from GitHub Actions and Non-CI/CD Infrastructure
- AWS EC2 CreateKeyPair by New Principal from Non-Cloud AS Organization
- AWS EC2 Role GetCallerIdentity from New Source AS Organization
- AWS Lambda Function Invoked from an Unusual Source ASN
- AWS Rare Source AS Organization Activity
- GKE Secrets List from Unusual Source AS Organization
ne: microsoft-corp-msn-as-block 3 rules
AccountType 2 values
eq: User 6 rules
- EatonForeseer - Unauthorized Logins
- New user created and added to the built-in administrators group
- Potentially Relayed NTLM Authentication - Microsoft Sentinel
- PROD (TM011.1) - LAPS - Tier Level Computer Object LAPS Password Expiration Time Set Manually
- User account added to built in domain local or global group
- User account created and deleted within 10 mins
eq: user 5 rules
DstBytes 2 values
ne: 0 6 rules
Esql.recent 2 values
le: 6 6 rules
Esql.script_block_length 2 values
gt: 500 6 rules
T1027, Command Obfuscation T1027.010, Command and Scripting Interpreter T1059, PowerShell T1059.001, Deobfuscate/Decode Files or Information T1140- Dynamic IEX Reconstruction via Method String Access
- Potential Dynamic IEX Reconstruction via Environment Variables
- Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion
- Potential PowerShell Obfuscation via String Concatenation
- Potential PowerShell Obfuscation via String Reordering
- PowerShell Obfuscation via Negative Index String Reversal
Esql.script_block_pattern_count 2 values
ge: 1 6 rules
T1027, Command Obfuscation T1027.010, Command and Scripting Interpreter T1059, PowerShell T1059.001, Deobfuscate/Decode Files or Information T1140- Dynamic IEX Reconstruction via Method String Access
- Potential Dynamic IEX Reconstruction via Environment Variables
- Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion
- Potential PowerShell Obfuscation via Character Array Reconstruction
- Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation
- PowerShell Obfuscation via Negative Index String Reversal
EventResourceId 2 values
eq: traffic 6 rules
Initiator 2 values
ne: MS-PIM 6 rules
T1078, Cloud Accounts T1078.004, Account Access Removal T1531, Account Manipulation T1098, Additional Cloud Credentials T1098.001- [Entra ID] Privileged Role Assigned to a New User
- [Entra ID] Privileged Role Assigned to User
- Multiple admin membership removals from newly created admin.
- New External User Granted Admin Role
- Threat Essentials - Multiple admin membership removals from newly created admin.
- User Assigned New Privileged Role
ne: MS-PIM-Fairfax 4 rules
azure_ad::modified_properties_new 2 values
gt: 0 6 rules
T1098, Steal Application Access Token T1528, Additional Cloud Roles T1098.003, Use Alternate Authentication Material T1550, Valid Accounts T1078, Cloud Accounts T1078.004- [Entra ID] Application Granted Administrative Permission to Assign Microsoft Entra ID Roles
- Mail.Read Permissions Granted to Application
- Microsoft Entra ID Role Management Permission Grant
- Suspicious application consent for offline access
- Suspicious application consent similar to O365 Attack Toolkit
- Suspicious application consent similar to PwnAuth
file.Ext.windows.zone_identifier 2 values
github.programmatic_access_type 2 values
in: fine-grained personal access token 6 rules
- First Occurrence GitHub Event for a Personal Access Token (PAT)
- First Occurrence of IP Address For GitHub Personal Access Token (PAT)
- First Occurrence of Personal Access Token (PAT) Use For a GitHub User
- First Occurrence of Private Repo Event from Specific GitHub Personal Access Token (PAT)
- First Occurrence of User Agent For a GitHub Personal Access Token (PAT)
- High Number of Cloned GitHub Repos From PAT
in: oauth access token 6 rules
- First Occurrence GitHub Event for a Personal Access Token (PAT)
- First Occurrence of IP Address For GitHub Personal Access Token (PAT)
- First Occurrence of Personal Access Token (PAT) Use For a GitHub User
- First Occurrence of Private Repo Event from Specific GitHub Personal Access Token (PAT)
- First Occurrence of User Agent For a GitHub Personal Access Token (PAT)
- High Number of Cloned GitHub Repos From PAT
outcome.result 2 values
eq: SUCCESS 6 rules
eq: failure 2 rules, 2 vendors
ResultStatus 2 values
eq: success 5 rules, 2 vendors
eq: succeeded 2 rules
data.details.response.body.enabled 2 values
eq: false 5 rules, 2 vendors
- Auth0 Attack Protection Monitoring Disabled
- Attack protection features manipulation - some attack protection features have been disabled.
- Breached Password Detection - critical settings manipulated
- Brute Force Protection - critical settings manipulated
- Suspicious IP Throttling - critical settings manipulated
eq: true 2 rules
DNS_TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 5 rules
cross_field_compare: ValidUntil 3 rules
EVENT_TYPE 2 values
eq: LOGIN 5 rules
in: ApiConnectedApp 2 rules
OnboardingStatus 2 values
ne: Onboarded 5 rules
T1021, Remote Desktop Protocol T1021.001, Credentials from Password Stores T1555, Windows Credential Manager T1555.004, Forge Web Credentials T1606, Remote System Discovery T1018- Detect Suspicious ncrypt.dll usage on admin device with RDP connections to non TPM protected device
- Detect Suspicious ncrypt.dll usage with RDP connections to unmanaged or non TPM protected device
- Hunt devices supporting MDE Containment
- Hunt for ADWS requests from unknown devices
- Hunt for RDP sessions to unmanaged and non TPM devices
eq: Onboarded 2 rules
RemoteIPType 2 values
SChannelName 2 values
cross_field_compare: src 5 rules
current 2 values
eq: true 5 rules
ne: false 3 rules
m365::TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 5 rules
cross_field_compare: ValidUntil 3 rules
match 2 values
is_not_null: 5 rules
eq: 0 2 rules
properties.authenticationDetails{}.succeeded 2 values
eq: false 5 rules
properties.status.errorCode 2 values
resource 2 values
in: clusterroles 5 rules
state 2 values
eq: ACTIVE 5 rules
- GCP Security Command Center - Detect DNSSEC disabled for DNS zones
- GCP Security Command Center - Detect Firewall rules allowing unrestricted high-risk ports
- GCP Security Command Center - Detect Open/Unrestricted API Keys
- GCP Security Command Center - Detect projects with API Keys present
- GCP Security Command Center - Detect Resources with Logging Disabled
eq: successful 2 rules
ClientIP 2 values
is_not_null: 4 rules
EntityName 2 values
eq: organization 4 rules
Esql.verdict 2 values
in: suspicious 4 rules
SigninLogs_TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 4 rules
cross_field_compare: ValidUntil 3 rules
Target.process.executable 2 values
is_not_null: 4 rules
ne: process.executable 3 rules
ThreatLevel 2 values
eq: dangerous 4 rules
beta.parse_exif 2 values
func_call: beta.parse_exif(file.message_screenshot()).image_height < 2000 4 rules
func_call: beta.parse_exif(file.message_screenshot()).image_width < 2000 4 rules
dc_process_name 2 values
gt: 2 4 rules
distinct(body.links, .href_url.domain.root_domain) 2 values
length_compare: 10 4 rules
length_compare: 3 2 rules
event0.process.command_line 2 values
contains: file.name 4 rules
file.Ext.entropy 2 values
ge: 6 4 rules
graph.entity.file.prevalence.rolling_max 2 values
gt: 0 4 rules
le: 3 3 rules
headers.message_id 2 values
ends_with: @odspnotify> 4 rules
starts_with: <Share- 3 rules
m365::Folder.Path 2 values
in: \\recoverable items\\deletions 4 rules
in: \\sent items 4 rules
process.thread.Ext.call_stack_final_user_module.protection_provenance_path 2 values
is_not_null: 4 rules
wildcard: c:\windows\microsoft.net\framework*\clr.dll 3 rules
process_guid 2 values
eq: event0.process.entity_id 4 rules
eq: event1.process.entity_id 2 rules
registry.hive 2 values
eq: HKEY_USERS 4 rules
signature 2 values
eq: consolelogin 4 rules
eq: user.session.start 2 rules
target.resource.product_object_id 2 values
eq: %sap_sensitive_roles.role 4 rules
eq: 1b730954-1685-4b74-9bfd-dac224a7b894 3 rules
additionalEventData.MFAUsed 2 values
eq: no 3 rules, 2 vendors
AdditionalFields 2 values
contains: esaurldetails 3 rules
contains: esaampverdict 2 rules
Alert_TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 3 rules
cross_field_compare: ValidUntil 3 rules
All_Traffic.action 2 values
in: allow 3 rules
in: allowed 3 rules
CloudAppEvents_TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 3 rules
cross_field_compare: ValidUntil 3 rules
Esql.rule_severity_values 2 values
eq: 73 3 rules
HitTime 2 values
cross_field_compare: ExpirationDateTime 3 rules
cross_field_compare: TimeGenerated 3 rules
IPAddresses 2 values
is_not_null: 3 rules
IS_SUCCESS 2 values
eq: NO 3 rules
eq: YES 2 rules
Identity 2 values
ne: MS-PIM 3 rules
ne: MS-PIM-Fairfax 3 rules
LogType 2 values
eq: Update 3 rules
in: Update 2 rules
Score 2 values
ge: 50 3 rules
ge: 3 2 rules
SecurityEvent_TimeGenerated 2 values
cross_field_compare: ValidUntil 3 rules
cross_field_compare: ExpirationDateTime 2 rules
State 2 values
eq: open 3 rules
is_null: 3 rules
UserCount 2 values
gt: 0 3 rules
Value 2 values
eq: False 3 rules
is_not_null: 2 rules
auditLevel 2 values
eq: WORKSPACE_LEVEL 3 rules
eq: ACCOUNT_LEVEL 2 rules
azure_ad::authentication_protocol 2 values
error_code 2 values
is_not_null: 3 rules
ne: 394304 2 rules
graph.entity.domain.prevalence.rolling_max 2 values
gt: 0 3 rules
le: 3 2 rules
graph.relations.relationship 2 values
eq: CONTACTS 3 rules
eq: DOWNLOADED_FROM 2 rules
list_ActivityStatusValue 2 values
contains: succeeded 3 rules
contains: success 3 rules
objectCategory 2 values
starts_with: cn=group-policy-container 3 rules
starts_with: cn=group-policy-container,cn=schema,cn=configuration,dc= 2 rules
second 2 values
ge: 1 3 rules
target.resource.attribute.labels.key 2 values
regex_match: NewValue_EntitlementId- 3 rules
regex_match: OldValue_EntitlementId- 3 rules
timestamp.current_seconds() 2 values
time_arithmetic: 2592000 3 rules
time_arithmetic: graph.entity.domain.creation_time.seconds 2 rules
comm 2 values
eq: insmod 2 rules, 2 vendors
eq: split 2 rules, 2 vendors
event_type_id 2 values
eq: 3 2 rules, 2 vendors
eq: 11 2 rules
reason 2 values
eq: bypass_user 2 rules, 2 vendors
eq: risky application detected 2 rules
@Name 2 values
eq: KeyName 2 rules
eq: SubjectUserName 2 rules
ActivityStatusValue 2 values
eq: success 2 rules
starts_with: Accept 2 rules
All_Changes.command 2 values
contains: tftp-server 2 rules
contains: user table modified 2 rules
All_Traffic.app 2 values
eq: smb 2 rules
AppName 2 values
eq: lsass.exe 2 rules
starts_with: ConnectSyncProvisioning_ 2 rules
ApplicationProtocol 2 values
in: pop3 2 rules
in: smtp 2 rules
AzureActivity_TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 2 rules
cross_field_compare: ValidUntil 2 rules
Caller 2 values
is_not_null: 2 rules
regex_match: ^[a-zA-Z0-9_.+-]+@[a-zA-Z0-9-]+\.[a-zA-Z0-9-.]+$ 2 rules
DGADomain 2 values
gt: 8 2 rules
regex_match: ^[A-Za-z]{0,}$ 2 rules
DestinationHost 2 values
contains: domains 2 rules
is_not_null: 2 rules
DestinationHostName 2 values
contains: domains 2 rules
is_not_null: 2 rules
DestinationUserID 2 values
is_not_null: 2 rules
regex_match: ^[a-zA-Z0-9_.+-]+@[a-zA-Z0-9-]+\.[a-zA-Z0-9-.]+$ 2 rules
DeviceNetworkEvents_TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 2 rules
cross_field_compare: ValidUntil 2 rules
Direction 2 values
cross_field_compare: NetworkDirection 2 rules
DnsQueryTypeName 2 values
in: A 2 rules
EmailEvents_TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 2 rules
cross_field_compare: ValidUntil 2 rules
Esql.document_count 2 values
Esql.region_count 2 values
ge: 2 2 rules
Esql.total_attempts 2 values
ge: 10 2 rules
EventSeverity 2 values
eq: High 2 rules
is_not_null: 2 rules
EventVendor 2 values
eq: ODI-X 2 rules
eq: Workday 2 rules
GCPUserIp 2 values
is_not_null: 2 rules
IncomingTokenType 2 values
eq: none 2 rules
LogonId 2 values
eq: 0 2 rules
NewTargetUserName 2 values
ends_with: $ 2 rules
ParentUser 2 values
contains: authori 2 rules
Path 2 values
contains: \desktop\ 2 rules
contains: \downloads\ 2 rules
Process 2 values
contains: powershell.exe 2 rules
eq: sdelete.exe 2 rules
QueryType 2 values
eq: select 2 rules
eq: show 2 rules
RADIUSAuth 2 values
eq: reject 2 rules
is_not_null: 2 rules
RenderedDescription 2 values
contains: downloaded 2 rules
contains: uploaded 2 rules
RescanVerdict 2 values
in: malware 2 rules
SecondAppDisplayName 2 values
in: Microsoft Azure CLI 2 rules
in: Microsoft Azure PowerShell 2 rules
SidHistoryMatch 2 values
cross_field_compare: TargetDomainName 2 rules
cross_field_compare: TargetSidmatch 2 rules
StartTime 2 values
ge: UEBAWindowStart 2 rules
Syslog_TimeGenerated 2 values
cross_field_compare: ExpirationDateTime 2 rules
cross_field_compare: ValidUntil 2 rules
TI_EmailAddress 2 values
eq: RecipientAddresses 2 rules
eq: SenderAddresses 2 rules
TotalEvents 2 values
gt: 30 2 rules
Total_TrackingReference 2 values
ge: 1 2 rules
ge: 3 2 rules
URI 2 values
ends_with: AllUsers 2 rules
ends_with: AuthenticatedUsers 2 rules
UriPath 2 values
contains: /api/login 2 rules
contains: /api/login?user= 2 rules
UserAccountControl 2 values
eq: %%2093 2 rules
UserType 2 values
in: admin 2 rules
in: dcadmin 2 rules
User_Id 2 values
is_not_null: 2 rules
regex_match: ^[a-zA-Z0-9_.+-]+@[a-zA-Z0-9-]+\.[a-zA-Z0-9-.]+$ 2 rules
XCsAppCcl 2 values
eq: low 2 rules
eq: poor 2 rules
a2 2 values
eq: clip 2 rules
eq: clipboard 2 rules
a3 2 values
ends_with: .jpg 2 rules
ends_with: .png 2 rules
aceType 2 values
in: access denied 2 rules
azure.auditlogs.properties.category 2 values
eq: directorymanagement 2 rules
eq: rolemanagement 2 rules
azure.platformlogs.properties.log.objectRef.resource 2 values
eq: nodes 2 rules
azure.platformlogs.properties.log.responseStatus.code 2 values
in: 200 2 rules
azure.signinlogs.properties.incoming_token_type 2 values
eq: primaryRefreshToken 2 rules
azure_ad::target_resources 2 values
contains: offline 2 rules
is_not_null: 2 rules
computer_name 2 values
is_not_null: 2 rules
starts_with: substring(user.name, 0, (-1)) 2 rules
confidence_score 2 values
ge: 60 2 rules
cs-host 2 values
eq: api.telegram.org 2 rules
data.details.request.path 2 values
eq: /api/v2/guardian/policies 2 rules
eq: /api/v2/risk-assessment/config 2 rules
data_action_s 2 values
eq: accept 2 rules
eq: reject 2 rules
destination.address 2 values
wildcard: 127.* 2 rules
wildcard: ::1 2 rules
entity_type 2 values
eq: account 2 rules
eq: host 2 rules
event.OperationName 2 values
in: CreateAllowlistGroup 2 rules
in: UpdateAllowlistGroup 2 rules
failed_attempts 2 values
gt: 10 2 rules
gcp::method_name 2 values
ends_with: instances.insert 2 rules
graph.entity.domain.expiration_time.seconds 2 values
gt: 0 2 rules
macro: access.metadata.event_timestamp.seconds 2 rules
headers.mailer 2 values
eq: microsoft cdo for windows 2000 2 rules
starts_with: Open-Xchange Mailer 2 rules
headers.return_path.domain.root_domain 2 values
eq: salesforce.com 2 rules
ne: bestdeals.today 2 rules
headers.return_path.email 2 values
cross_field_compare: sender.email.email 2 rules
is_not_null: 2 rules
kibana.alert.rule.threat.tactic.name 2 values
eq: lateral movement 2 rules
is_not_null: 2 rules
logger 2 values
in: wt.method.methodcontextmonitor.contexts.servletrequest 2 rules
in: wt.servlet.servletrequestmonitor.request 2 rules
m365::ObjectId 2 values
in: 00000003-0000-0000-c000-000000000000 2 rules
is_not_null: 2 rules
okta::debugContext.debugData.dt_hash 2 values
is_not_null: 2 rules
old_value_set 2 values
eq: [] 2 rules
parent_process_guid 2 values
eq: event0.process.entity_id 2 rules
eq: event1.process.entity_id 2 rules
primaryDisplayName 2 values
contains: admin 2 rules
ne: *admin* 2 rules
process.Ext.api.summary 2 values
contains: amsi.dll 2 rules
contains: ntdll.dll 2 rules
process.Ext.protection 2 values
ne: PsProtectedSignerAntimalware-Light 2 rules
starts_with: PsProtectedSigner 2 rules
proctitle 2 values
in: *service * 2 rules
in: *systemctl * 2 rules
properties.message 2 values
eq: add app role assignment to service principal 2 rules
eq: add delegated permission grant 2 rules
requestParameters.VersioningConfiguration.Status 2 values
in: Disabled 2 rules
in: Suspended 2 rules
resource.type 2 values
eq: http_load_balancer 2 rules
starts_with: bigquery 2 rules
risk_type 2 values
eq: duplicate_password 2 rules
eq: weak_password_policy 2 rules
s_domain 2 values
cross_field_compare: rec_domain 2 rules
eq: corp_domain 2 rules
scStatus 2 values
in: 401 2 rules
in: 403 2 rules
strings.count 2 values
func_call: strings.count(body.current_thread.text, "©") == 1 2 rules
func_call: strings.count(subject.base, " ") > 8 2 rules
target.resource.attribute.labels["visibility"] 2 values
eq: people_with_link 2 rules
eq: public_on_the_web 2 rules
target.resource.name 2 values
eq: IDENTITY 2 rules
eq: PFCG 2 rules
vulnerability_category 2 values
eq: ATTACK_SURFACE_VULNERABILITY 2 rules
ne: ATTACK_SURFACE_VULNERABILITY 2 rules
type.inbound 1 value
eq: true 1158 rules
- Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
- Abuse: Robinhood injected content
- Adobe branded PDF file linking to a password-protected file from untrusted sender
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
- AnonymousFox indicators
- Anthropic Magic String in HTML
- Attachment soliciting user to enable macros
- Attachment with auto-executing macro (unsolicited)
type.outbound 1 value
Active 1 value
eq: true 70 rules
T1071, Phishing T1566, Valid Accounts T0859, Remote Services T0886, Remote Services T1021, Valid Accounts T1078- Dataverse - TI map IP to DataverseActivity
- Dataverse - TI map URL to DataverseActivity
- GreyNoise TI Map IP Entity to CommonSecurityLog
- GreyNoise TI Map IP Entity to DnsEvents
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)
- GreyNoise TI map IP entity to OfficeActivity
- GreyNoise TI Map IP Entity to SigninLogs
- Infoblox - TI - CommonSecurityLog Match Found - MalwareC2
ValidUntil 1 value
is_null: 58 rules
headers.references 1 value
length_compare: 0 46 rules
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
- Attachment with auto-executing macro (unsolicited)
- Attachment: Adobe image lure in body or attachment with suspicious link
- Attachment: Callback phishing solicitation via pdf file
- Attachment: EML file contains HTML attachment with login portal indicators
- Attachment: Legal themed message or PDF with suspicious indicators
- Attachment: Microsoft 365 credential phishing
- BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
isOutlier 1 value
eq: 1 33 rules
T1110, Password Spraying T1110.003, Credential Stuffing T1110.004, Compromise Accounts T1586, Cloud Accounts T1586.003, Account Manipulation T1098- AWS Unusual Number of Failed Authentications From Ip
- Azure AD Unusual Number of Failed Authentications From Ip
- Cloud Security Groups Modifications by User
- Detect Distributed Password Spray Attempts
- Detect New Login Attempts to Routers
- Detect Password Spray Attempts
- Detect Spike in AWS Security Hub Alerts for EC2 Instance
- Detect Spike in AWS Security Hub Alerts for User
headers.auth_summary.spf.pass 1 value
eq: true 32 rules
- Attachment: HTML attachment with login portal indicators
- Brand impersonation: Adobe with suspicious language and link
- Brand impersonation: QuickBooks notification from Intuit themed company name
- Callback phishing via Adobe Sign comment
- Callback phishing via DocuSign comment
- Callback phishing via e-signature service
- Callback phishing via Intuit service abuse
- Callback Phishing via Signable E-Signature Request
headers.reply_to 1 value
length_compare: 0 32 rules
- Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
- Attachment: Office document with VSTO add-in
- BEC with unusual reply-to or return-path mismatch
- BEC/Fraud: Generic scam attempt to undisclosed recipients
- BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
- BEC: Tax document request
- Brand impersonation: LinkedIn
- Brand impersonation: Microsoft fake sign-in alert
Result 1 value
eq: success 31 rules
T1078, Cloud Accounts T1078.004, Account Manipulation T1098, Use Alternate Authentication Material T1550, Application Access Token T1550.001, Create Account T1136- [Entra ID] Privileged Role Assigned to a New User
- Account created or deleted by non-approved user
- Account Elevated to New Role
- Application Redirect URL Update
- Cisco Duo - Authentication device new location
- Cisco Duo - New access device
- Cisco Duo - Unexpected authentication factor
- Conditional Access Policy Modified by New User
NetworkSourceIP 1 value
is_not_null: 27 rules
T1071, Valid Accounts T0859, Remote Services T0886, Remote Services T1021, Valid Accounts T1078, External Remote Services T1133- Dataverse - TI map IP to DataverseActivity
- GitLab - TI - Connection from Malicious IP
- GreyNoise TI Map IP Entity to CommonSecurityLog
- GreyNoise TI Map IP Entity to DnsEvents
- GreyNoise TI map IP entity to OfficeActivity
- GreyNoise TI Map IP Entity to SigninLogs
- Preview - TI map IP entity to Cloud App Events
- ProofpointPOD - Email sender IP in TI list
Effect 1 value
eq: allow 26 rules
T1098, Additional Cloud Roles T1098.003, Domain or Tenant Policy Modification T1484, Transfer Data to Cloud Account T1537, Data Encrypted for Impact T1486- AWSCloudTrail - CloudFormation policy created then used for privilege escalation
- AWSCloudTrail - Created CRUD S3 policy and then privilege escalation
- AWSCloudTrail - Creation of CRUD DynamoDB policy and then privilege escalation
- AWSCloudTrail - Creation of CRUD KMS policy and then privilege escalation
- AWSCloudTrail - Creation of CRUD Lambda policy and then privilege escalation
- AWSCloudTrail - Creation of DataPipeline policy and then privilege escalation
- AWSCloudTrail - Creation of EC2 policy and then privilege escalation
- AWSCloudTrail - Creation of Glue policy and then privilege escalation
EmailSourceIpAddress 1 value
is_not_null: 26 rules
T1071, Valid Accounts T0859, Remote Services T0886, Remote Services T1021, Valid Accounts T1078, External Remote Services T1133- Dataverse - TI map IP to DataverseActivity
- GitLab - TI - Connection from Malicious IP
- GreyNoise TI Map IP Entity to CommonSecurityLog
- GreyNoise TI Map IP Entity to DnsEvents
- GreyNoise TI map IP entity to OfficeActivity
- GreyNoise TI Map IP Entity to SigninLogs
- Preview - TI map IP entity to Cloud App Events
- ProofpointPOD - Email sender IP in TI list
NetworkDestinationIP 1 value
is_not_null: 26 rules
T1071, Valid Accounts T0859, Remote Services T0886, Remote Services T1021, Valid Accounts T1078, External Remote Services T1133- Dataverse - TI map IP to DataverseActivity
- GitLab - TI - Connection from Malicious IP
- GreyNoise TI Map IP Entity to CommonSecurityLog
- GreyNoise TI Map IP Entity to DnsEvents
- GreyNoise TI map IP entity to OfficeActivity
- GreyNoise TI Map IP Entity to SigninLogs
- Preview - TI map IP entity to Cloud App Events
- ProofpointPOD - Email sender IP in TI list
NetworkIP 1 value
is_not_null: 26 rules
T1071, Valid Accounts T0859, Remote Services T0886, Remote Services T1021, Valid Accounts T1078, External Remote Services T1133- Dataverse - TI map IP to DataverseActivity
- GitLab - TI - Connection from Malicious IP
- GreyNoise TI Map IP Entity to CommonSecurityLog
- GreyNoise TI Map IP Entity to DnsEvents
- GreyNoise TI map IP entity to OfficeActivity
- GreyNoise TI Map IP Entity to SigninLogs
- Preview - TI map IP entity to Cloud App Events
- ProofpointPOD - Email sender IP in TI list
process.parent.code_signature.trusted 1 value
eq: false 26 rules
T1059, Unix Shell T1059.004, AppleScript T1059.002, Hijack Execution Flow T1574, Abuse Elevation Control Mechanism T1548, Credentials from Password Stores T1555- Apple Scripting Execution with Administrator Privileges
- Attempt to Install Root Certificate
- Default Application Hijacking
- Enumeration of Users or Groups via Built-in Commands
- ExecuteWithPrivileges Prompt via Unsigned or Untrusted Application
- External IP Address Discovery via Curl
- Finder Sync Plugin Registered and Enabled
- Keychain CommandLine Interaction via Unsigned or Untrusted Process
process.parent.code_signature.exists 1 value
eq: false 25 rules
T1059, AppleScript T1059.002, Unix Shell T1059.004, Hijack Execution Flow T1574, Abuse Elevation Control Mechanism T1548, Credentials from Password Stores T1555- Apple Scripting Execution with Administrator Privileges
- Attempt to Install Root Certificate
- Default Application Hijacking
- Enumeration of Users or Groups via Built-in Commands
- ExecuteWithPrivileges Prompt via Unsigned or Untrusted Application
- External IP Address Discovery via Curl
- Finder Sync Plugin Registered and Enabled
- Keychain CommandLine Interaction via Unsigned or Untrusted Process
recipients.bcc 1 value
length_compare: 0 24 rules
- Attachment: Callback phishing solicitation via image file
- Body: HTML whitespace stuffing with short initial message
- Brand impersonation: Norton
- Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
- Callback phishing: AOL senders with suspicious HTML template or PDF attachment
- Credential Phishing: Suspicious language, link, recipients and other indicators
- Free subdomain link with credential theft indicators
- Headers: Self-sender using Microsoft CompAuth bypass with credential theft content
username 1 value
contains: serviceaccount 24 rules
T1078.004, Escape to Host T1611, Unsecured Credentials T1552, Account Manipulation T1098, Container API T1552.007, Data from Cloud Storage T1530- Kubernetes Admission Controller Webhook Created
- Kubernetes All Secrets Dumped Across Namespaces
- Kubernetes Client Certificate Credential Created
- Kubernetes ClusterRoleBinding to Privileged Role
- Kubernetes CronJob Created or Modified
- Kubernetes DaemonSet Created
- Kubernetes Data Copy via kubectl cp
- Kubernetes Ingress Created Without TLS
dll.code_signature.exists 1 value
eq: false 22 rules
- DLL Loaded from a Macro Enabled Document
- DLL Side Loading of a file dropped by Microsoft Office
- Evasion via LdrpKernel32 Overwrite
- Execution of a File Downloaded via Windows OpenSSH
- Known Desktop Application DLL Search Order Hijack
- Library Loaded via a CallBack Function
- Library Loaded via Thread Fiber CallBack
- Microsoft Office AddIn Loaded
IsActive 1 value
eq: true 21 rules
T1071, Command and Scripting Interpreter T1059, Exploit Public-Facing Application T1190, Phishing T1566, Dynamic Resolution T1568, Brute Force T1110- Google Threat Intelligence - Threat Hunting Domain
- Google Threat Intelligence - Threat Hunting Hash
- Google Threat Intelligence - Threat Hunting IP
- Google Threat Intelligence - Threat Hunting Url
- HoneyLabs TI Map IP Entity to CommonSecurityLog
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- HoneyLabs TI Map IP Entity to SigninLogs
- HoneyLabs TI Map URL Entity to CommonSecurityLog
process.interactive 1 value
eq: true 19 rules
T1059, Unix Shell T1059.004, Permission Groups Discovery T1069, Account Discovery T1087, Container Administration Command T1609, Deploy Container T1610- Container Management Utility Run Inside A Container
- Direct Interactive Kubernetes API Request by Common Utilities
- Direct Interactive Kubernetes API Request by Unusual Utilities
- Execution of Memory File Descriptor via Interactive Session
- Forbidden Direct Interactive Kubernetes API Request
- Interactive Shell Launched via Unusual Parent Process in a Container
- Long Base64 Command Execution via Interactive Shell
- Payload Downloaded and Piped to Interpreter
OperationType 1 value
eq: %%14674 17 rules, 3 vendors
T1098, Domain or Tenant Policy Modification T1484, File and Directory Permissions Modification T1222, Windows Permissions T1222.001, Group Policy Modification T1484.001, Event Triggered Execution T1546- Account Configured with Never-Expiring Password
- AdminSDHolder SDProp Exclusion Added
- Modification of the msPKIAccountCredentials
- User account exposed to Kerberoasting
- AdminSDHolder permissions changed for persistence
- Computer account modifying Active Directory permissions
- Computer account modifying Active Directory permissions (PrivExchange)
- Extended rights backdoor obfuscation (via localizationDisplayId attribute)
data.details.request.channel 1 value
eq: https://manage.auth0.com/ 17 rules
protoPayload.authorizationInfo 1 value
is_not_null: 17 rules
T1548, Exfiltration Over C2 Channel T1041, Escape to Host T1611, Exploit Public-Facing Application T1190- GCP Cloud Run Service Created
- GCP Cloud Run Set IAM Policy
- GCP CloudBuild Potential Privilege Escalation
- GCP cloudfunctions functions create
- GCP cloudfunctions functions update
- GCP GKE Kubernetes Cron Job Created Or Modified
- GCP IAM serviceAccounts getAccessToken Privilege Escalation
- GCP IAM serviceAccounts signBlob
DomainName 1 value
is_not_null: 15 rules
- Infoblox - TI - CommonSecurityLog Match Found - MalwareC2
- Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains
- Infoblox - TI - Syslog Match Found - URL
- Threat Connect TI map Domain entity to DnsEvents
- TI Map Domain Entity to DeviceNetworkEvents
- TI map Domain entity to Dns Events (ASIM DNS Schema)
- TI map Domain entity to DnsEvents
- TI map Domain entity to EmailEvents
isNew 1 value
eq: True 15 rules
- Denial of Service (Microsoft Defender for IoT)
- Excessive Login Attempts (Microsoft Defender for IoT)
- Firmware Updates (Microsoft Defender for IoT)
- High bandwidth in the network (Microsoft Defender for IoT)
- Illegal Function Codes for ICS traffic (Microsoft Defender for IoT)
- Internet Access (Microsoft Defender for IoT)
- Multiple scans in the network (Microsoft Defender for IoT)
- No traffic on Sensor Detected (Microsoft Defender for IoT)
kibana.alert.rule.name 1 value
is_not_null: 13 rules
- Alerts From Multiple Integrations by Destination Address
- Alerts From Multiple Integrations by Source Address
- Alerts From Multiple Integrations by User Name
- Alerts in Different ATT&CK Tactics by Host
- AWS IAM Long-Term Access Key Correlated with Elevated Detection Alerts
- Correlated Alerts on Similar User Identities
- FortiGate SSL VPN Login Followed by SIEM Alert by User
- LLM-Based Attack Chain Triage by Host
process.entry_leader.entry_meta.type 1 value
eq: container 13 rules
- AWS Credentials Searched For Inside A Container
- Chroot Execution in Container Context on Linux
- Container Management Utility Run Inside A Container
- Egress Connection from Entrypoint in Container
- Exec Into Container Detected via Defend for Containers
- File System Debugger Launched Inside a Container
- Interactive Shell Launched via Unusual Parent Process in a Container
- Mount Launched Inside a Container
anomalies 1 value
gt: 0 12 rules
T1078, Cloud Accounts T1078.004, Resource Hijacking T1496, Email Collection T1114, Command and Scripting Interpreter T1059- Azure Key Vault access TimeSeries anomaly
- Detect unauthorized data transfers using timeseries anomaly (ASIM Web Session)
- Exchange workflow MailItemsAccessed operation anomaly
- Mass Cloud resource deletions Time Series Anomaly
- Privileged Accounts - Sign in Failure Spikes
- Process Execution Frequency Anomaly
- Suspicious number of resource creation or deployment activities
- Threat Essentials - Mass Cloud resource deletions Time Series Anomaly
key 1 value
eq: user-agent 12 rules
T1550, Account Manipulation T1098, Application Access Token T1550.001, Credentials from Password Stores T1555, Steal Application Access Token T1528, Exploitation for Privilege Escalation T1068- [Entra ID] Domain Federation Trust Settings Modified
- First access credential added to Application or Service Principal where no credential was present
- full_access_as_app Granted To Application
- Mail.Read Permissions Granted to Application
- Modified domain federation trust settings
- New access credential added to Application or Service Principal
- NRT First access credential added to Application or Service Principal where no credential was present
- NRT Modified domain federation trust settings
log_source 1 value
eq: auditevents 12 rules
T1556, Account Manipulation T1098, Valid Accounts T1078, Disable or Modify Tools T1562, Create Account T1136, Credentials from Password Stores T1555- 1Password - Changes to firewall rules
- 1Password - Changes to SSO configuration
- 1Password - Disable MFA factor or type for all user accounts
- 1Password - New service account integration created
- 1Password - Non-privileged vault user permission change
- 1Password - Potential insider privilege escalation via group
- 1Password - Potential insider privilege escalation via vault
- 1Password - Privileged vault permission change
pattern 1 value
contains: file:hashes 12 rules
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity File Hash Indicators with Block Action Rule
- CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - High severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action Rule
process.parent.Ext.real.pid 1 value
gt: 0 11 rules
- API Call from a Process with a Spoofed Parent
- Parent Process PID Spoofing
- Parent Process PID Spoofing
- Potential Parent Process PID Spoofing via MalSecLogon
- Potential Privilege Escalation via Rogue WinRM
- Potential Privilege Escalation via Token Impersonation
- Privilege Escalation via EXTENDED STARTUPINFO
- Privileges Elevation via Parent Process PID Spoofing
subject.is_reply 1 value
eq: true 11 rules
- BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
- BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
- Credential phishing: Blue button styled link with file-sharing template artifacts
- Fake message thread with a suspicious link and engaging language from an unknown sender
- Fake thread with suspicious indicators
- Link: Non-standard port 8443 in display URL
- Reconnaissance: Large unknown recipient list
- Spam: Website errors solicitation
Activity 1 value
contains: modified 10 rules
T1484, Group Policy Modification T1484.001, Valid Accounts T1078, Domain Accounts T1078.002, File and Directory Permissions Modification T1222, Windows Permissions T1222.001- PROD (TM001.1) - GROUP - Added to Group Outside the Object Tier Level
- PROD (TM005.1) - GPO - Linked, Unlinked, or Enforced at Tier Level OU
- PROD (TM006.1) - ACL - Modified at Tier Level OU
- PROD (TM008.1) - GPO - Linked, Unlinked, or Enforced at Root of Domain
- PROD (TM009.1) - ACL - Modified at Root of the Domain
- PROD (TM012.1) - GPO - Enforced Outside of Tier Model
- PROD (TM013.1) - OU - Block Inheritance was Enabled on an OU
- PROD (TM014.1) - GPO - Linked, Unlinked, or Enforced at the AD Site Level
CsUsername 1 value
is_not_null: 10 rules
- Netskope - Anomalous User Behavior (High Volume from Unmanaged Device)
- Netskope - Data Movement Tracking (Upload/Download Monitoring)
- Netskope - Excessive Downloads Detection (Spike vs Baseline)
- Netskope - Heavy Personal Cloud Storage Usage (Shadow IT)
- Netskope - Impossible Travel Detection (Two Countries in Less Than 1 Hour)
- Netskope - Large Outbound Data Transfer / Sensitive Upload (DLP)
- Netskope - New Risky App Access vs 7-Day Baseline
- Netskope - Repeated or Critical Policy Violations
RiskScore 1 value
data_data_result_s 1 value
data_data_severity_s 1 value
deviceProduct_s 1 value
enough_data 1 value
eq: 1 10 rules
- Cloud API Calls From Previously Unseen User Roles
- Cloud Compute Instance Created By Previously Unseen User
- Cloud Compute Instance Created In Previously Unused Region
- Cloud Compute Instance Created With Previously Unseen Image
- Cloud Compute Instance Created With Previously Unseen Instance Type
- Cloud Instance Modified By Previously Unseen User
- Cloud Provisioning Activity From Previously Unseen City
- Cloud Provisioning Activity From Previously Unseen Country
event.errorcode 1 value
event.result 1 value
eq: SUCCESS 10 rules
process.Ext.api.parameters.app_name 1 value
eq: PowerShell 10 rules
- AMSI Bypass via PowerShell
- Potential Obfuscated PowerShell Script
- Potential Pentesting PowerShell Script
- Potential Reverse Shell via Powershell
- PowerShell Empire Script Execution
- PowerShell Execution from WinGet Configuration Remoting Server
- Powershell Execution via Named Pipe
- PowerShell Script with Passwords Vault Access Capability
process.group.id 1 value
eq: 0 10 rules
- Potential Privilege Escalation via a Known SUID/SGID Binary
- Potential Privilege Escalation via a SUID/SGID Binary
- Potential Privilege Escalation via SUID Binary
- Potential Privilege Escalation via SUID/SGID
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Sudo Token Manipulation via Process Injection
- Privilege Escalation via SUID/SGID
process.user.id 1 value
eq: 0 10 rules
- Potential Privilege Escalation via a Known SUID/SGID Binary
- Potential Privilege Escalation via a SUID/SGID Binary
- Potential Privilege Escalation via SUID Binary
- Potential Privilege Escalation via SUID/SGID
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Sudo Token Manipulation via Process Injection
- Privilege Escalation via SUID/SGID
TicketEncryptionType 1 value
eq: 0x17 9 rules, 4 vendors
T1558, Kerberoasting T1558.003, Golden Ticket T1558.001, Use Alternate Authentication Material T1550- Newly Observed RC4 Kerberos Service Ticket Request
- Potential Kerberoasting
- Kerberoasting Activity - Initial Query
- Potential AS-REP Roasting via Kerberos TGT Requests
- Suspicious Kerberos RC4 Ticket Encryption
- Kerberoasting spn request with RC4 encryption
- Kerberos Service Ticket Request Using RC4 Encryption
- Kerberos TGT Request Using RC4 Encryption
ObservableValue 1 value
is_not_null: 9 rules
T1071, Command and Scripting Interpreter T1059, Phishing T1566, Dynamic Resolution T1568, Drive-by Compromise T1189, Compromise Host Software Binary T1554- Google Threat Intelligence - Threat Hunting Domain
- Google Threat Intelligence - Threat Hunting Hash
- Google Threat Intelligence - Threat Hunting IP
- Google Threat Intelligence - Threat Hunting Url
- RecordedFuture Threat Hunting Domain All Actors
- RecordedFuture Threat Hunting Hash All Actors
- RecordedFuture Threat Hunting IP All Actors
- RecordedFuture Threat Hunting Url All Actors
fdr_event_type 1 value
eq: ProcessRollup2 9 rules
process.real_group.id 1 value
ne: 0 9 rules
- Potential Privilege Escalation via a Known SUID/SGID Binary
- Potential Privilege Escalation via a SUID/SGID Binary
- Potential Privilege Escalation via SUID Binary
- Potential Privilege Escalation via SUID/SGID
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Privilege Escalation via SUID/SGID
- Suspicious SUID Binary Execution
process.real_user.id 1 value
ne: 0 9 rules
- Potential Privilege Escalation via a Known SUID/SGID Binary
- Potential Privilege Escalation via a SUID/SGID Binary
- Potential Privilege Escalation via SUID Binary
- Potential Privilege Escalation via SUID/SGID
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Potential Privilege Escalation via SUID/SGID Proxy Execution
- Privilege Escalation via SUID/SGID
- Suspicious SUID Binary Execution
security_result.about.labels["Sample"] 1 value
ne: true 9 rules
- AWS GuardDuty Black Hole Traffic Detected
- AWS GuardDuty Bruteforce Activity Detected
- AWS GuardDuty Command And Control Activity Detected
- AWS GuardDuty Cryptocurrency Activity Detected
- AWS GuardDuty Denial Of Service Activity Detected
- AWS GuardDuty DGA Domain Activity Detected
- AWS GuardDuty Malicious Or Suspicious File Executed
- AWS GuardDuty Penetration Testing Activity Detected
span 1 value
eq: 10s 9 rules
- Kubernetes Anomalous Inbound Network Activity from Process
- Kubernetes Anomalous Inbound Outbound Network IO
- Kubernetes Anomalous Inbound to Outbound Network IO Ratio
- Kubernetes Anomalous Outbound Network Activity from Process
- Kubernetes Anomalous Traffic on Network Edge
- Kubernetes Process with Anomalous Resource Utilisation
- Kubernetes Process with Resource Ratio Anomalies
- Kubernetes Shell Running on Worker Node
unique_accounts 1 value
gt: 30 9 rules
- AWS Multiple Users Failing To Authenticate From Ip
- Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos
- Windows Multiple Invalid Users Fail To Authenticate Using Kerberos
- Windows Multiple Invalid Users Failed To Authenticate Using NTLM
- Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials
- Windows Multiple Users Failed To Authenticate From Host Using NTLM
- Windows Multiple Users Failed To Authenticate From Process
- Windows Multiple Users Failed To Authenticate Using Kerberos
azure_ad::authentication_requirement 1 value
eq: singlefactorauthentication 8 rules, 2 vendors
T1078, Cloud Accounts T1078.004, Modify Authentication Process T1556, Brute Force T1110, Password Guessing T1110.001, Password Spraying T1110.003- Entra ID Conditional Access MFA Bypass with Unusual User, Client and Source ASN
- Entra ID Excessive Account Lockouts Detected
- Entra ID OAuth ROPC Grant Login Detected
- Entra ID OAuth user_impersonation Scope for Unusual User and Client
- Entra ID User Sign-in Brute Force Attempted
- Azure AD Only Single Factor Authentication Required
- Sign-ins by Unknown Devices
- Suspicious SignIns From A Non Registered Device
ComplianceStatus 1 value
eq: FAILED 8 rules
- AWS Security Hub - Detect CloudTrail trails lacking KMS encryption
- AWS Security Hub - Detect EC2 Security groups allowing unrestricted high-risk ports
- AWS Security Hub - Detect IAM Policies allowing full administrative privileges
- AWS Security Hub - Detect IAM root user Access Key existence
- AWS Security Hub - Detect root user lacking MFA
- AWS Security Hub - Detect SQS Queue lacking encryption at rest
- AWS Security Hub - Detect SQS Queue policy allowing public access
- AWS Security Hub - Detect SSM documents public sharing enabled
Reason 1 value
eq: new_alert 8 rules
- Palo Alto Prisma Cloud - Access keys are not rotated for 90 days
- Palo Alto Prisma Cloud - High risk score alert
- Palo Alto Prisma Cloud - High severity alert opened for several days
- Palo Alto Prisma Cloud - IAM Group with Administrator Access Permissions
- Palo Alto Prisma Cloud - Maximum risk score alert
- Palo Alto Prisma Cloud - Network ACL allow all outbound traffic
- Palo Alto Prisma Cloud - Network ACL allow ingress traffic to server administration ports
- Palo Alto Prisma Cloud - Network ACLs Inbound rule to allow All Traffic
RecordState 1 value
eq: ACTIVE 8 rules
- AWS Security Hub - Detect CloudTrail trails lacking KMS encryption
- AWS Security Hub - Detect EC2 Security groups allowing unrestricted high-risk ports
- AWS Security Hub - Detect IAM Policies allowing full administrative privileges
- AWS Security Hub - Detect IAM root user Access Key existence
- AWS Security Hub - Detect root user lacking MFA
- AWS Security Hub - Detect SQS Queue lacking encryption at rest
- AWS Security Hub - Detect SQS Queue policy allowing public access
- AWS Security Hub - Detect SSM documents public sharing enabled
aws::userIdentity.arn 1 value
is_not_null: 8 rules
T1526, Cloud Infrastructure Discovery T1580, Serverless Execution T1648, Data from Cloud Storage T1530, Cloud Storage Object Discovery T1619, Resource Hijacking T1496- AWS Access Token Used from Multiple Addresses
- AWS Bedrock High-Frequency Single-Model Inference API Probing
- AWS Discovery API Calls from VPN ASN for the First Time by Identity
- AWS IAM User Self-Created Access Key Subsequently Used
- AWS Lambda Function High-Frequency Invocation by a Single Principal
- AWS Lambda Function Invoked by an Unusual Principal
- AWS Lambda Function Invoked Cross-Account
- AWS S3 Rapid Bucket Posture API Calls from a Single Principal
objectRef:resource 1 value
eq: pods 8 rules
- Kubernetes Pod Created in Pre-Configured or Default Name Spaces
- Pod attached to the Node Host Network
- Pod Created or Modified Using the Host IPC Namespace
- Pod Created or Modified Using the Host PID Namespace
- Pod Created with Overly Permissive Linux Capabilities
- Pod creation or modification to a Host Path Volume Mount
- Privileged Pod Created
- Unauthorized Kubernetes Pod Execution
process.Ext.api.parameters.hook_type 1 value
eq: WH_KEYBOARD_LL 8 rules
- Keystroke Capture by Unsigned Process
- Keystroke Messages Hooking via SetWindowsHookEx
- Keystrokes Input Capture from a Managed Application
- Keystrokes Input Capture from a Suspicious Module
- Keystrokes Input Capture from Suspicious CallStack
- Keystrokes Input Capture from Unsigned DLL
- Keystrokes Input Capture via PowerShell
- Keystrokes Input Capture via SetWindowsHookEx
subject.is_forward 1 value
eq: true 8 rules
- BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
- Credential phishing: Blue button styled link with file-sharing template artifacts
- Fake message thread with a suspicious link and engaging language from an unknown sender
- Fake thread with suspicious indicators
- Link: Non-standard port 8443 in display URL
- Spam: Website errors solicitation
- VIP Impersonation via Google Group relay with suspicious indicators
- VIP impersonation with charitable donation fraud
tool 1 value
All_Risk.risk_object_type 1 value
eq: system 7 rules
- Active Directory Lateral Movement Identified
- Active Directory Privilege Escalation Identified
- Linux Persistence and Privilege Escalation Risk Behavior
- Living Off The Land Detection
- Log4Shell CVE-2021-44228 Exploitation
- ProxyShell ProxyNotShell Behavior Detected
- Steal or Forge Authentication Certificates Behavior Identified
DstUserName 1 value
is_not_null: 7 rules
- OracleDBAudit - Multiple tables dropped in short time
- OracleDBAudit - New user account
- OracleDBAudit - Query on Sensitive Table
- OracleDBAudit - SQL injection patterns
- OracleDBAudit - Unusual user activity on multiple tables
- OracleDBAudit - User activity after long inactivity time
- OracleDBAudit - User connected to database from new IP
Esql.agent_id_count_distinct 1 value
eq: 1 7 rules
- File Transfer Utility Launched from Unusual Parent
- High Number of Egress Network Connections from Unusual Executable
- Potential Malware-Driven SSH Brute Force Attempt
- Potential Port Scanning Activity from Compromised Host
- Potential Subnet Scanning Activity from Compromised Host
- Unusual Base64 Encoding/Decoding Activity
- Unusual File Creation by Web Server
Version 1 value
eq: 2 7 rules
T1204, Remote Services T1021, Distributed Component Object Model T1021.003, System Services T1569, Service Execution T1569.002, Windows Management Instrumentation T1047- Certutil payload obfuscation - Tchopper (command)
- Edge abuse for payload download via console
- Impacket DCOMexec process abuse via MMC
- PSexec application execution
- Spool process spawned a CMD shell (PrintNightmare vulnerability - CVE-2021-36958)
- Stickey key called CMD via command execution
- WMI spwaning PowerShell process - WMImplant
_waf_matches_any_group 1 value
func_call: event.get('terminatingRuleId', ''), rule_groups 7 rules
- AWS WAF Managed Admin Protection Passthrough Rule
- AWS WAF Managed Anti-DDoS Passthrough Rule
- AWS WAF Managed Bot Control Passthrough Rule
- AWS WAF Managed Core Rule Set Passthrough Rule
- AWS WAF Managed IP Reputation Passthrough Rule
- AWS WAF Managed Known Bad Inputs Passthrough Rule
- AWS WAF Managed SQL Database Passthrough Rule
azure.platformlogs.properties.log.stage 1 value
eq: responsecomplete 7 rules
T1557, Steal or Forge Authentication Certificates T1649, Steal Application Access Token T1528, Indicator Removal T1070, Permission Groups Discovery T1069, Cloud Groups T1069.003- Azure AKS Certificate Signing Request Created or Approved
- Azure AKS CoreDNS or Kube-DNS Configuration Modified
- Azure AKS Ephemeral Container Added to Pod
- Azure AKS Kubernetes Events Deleted
- Azure AKS Potential API Enumeration by User
- Azure AKS Service Account Token Created via TokenRequest API
- Azure AKS Suspicious Self-Subject Review by Service Account or Node Identity
azure_ad::user_principal_name 1 value
is_not_null: 7 rules
T1078, Cloud Accounts T1078.004, Brute Force T1110, Password Guessing T1110.001, Password Spraying T1110.003, Credential Stuffing T1110.004- Entra ID Conditional Access MFA Bypass with Unusual User, Client and Source ASN
- Entra ID Excessive Account Lockouts Detected
- Entra ID OAuth Flow by Microsoft Authentication Broker to Device Registration Service (DRS)
- Entra ID Sign-in Brute Force Attempted (Microsoft 365)
- Entra ID User Sign-in Brute Force Attempted
- Entra ID User Sign-in with Unusual Non-Managed Device
- Microsoft Entra ID Impossible Travel Sign-in
beta.ocr 1 value
func_call: beta.ocr(file.message_screenshot()).text != 7 rules
beta.scan_qr 1 value
func_call: beta.scan_qr(file.message_screenshot()).found 7 rules
- Brand impersonation: DHL
- Constant Contact link infrastructure abuse
- Impersonation: Legal firm with copyright infringement notice
- QR code to auto-download of a suspicious file type (unsolicited)
- Service abuse: Monday.com infrastructure with phishing intent
- Service abuse: Square marketing with suspicious QR code
- Suspicious message with unscannable Cloudflare link
execution_status 1 value
filter(attachments, .file_type not in $file_types_images) 1 value
length_compare: 0 7 rules
- Attachment: Adobe image lure in body or attachment with suspicious link
- Attachment: Dropbox image lure with no Dropbox domains in links
- Attachment: Microsoft 365 credential phishing
- Brand impersonation: Microsoft quarantine release notification in body
- Brand impersonation: Microsoft quarantine release notification in image attachment
- Display name and subject impersonation using recipient SLD (new sender)
- Display name impersonation using recipient SLD
graph.metadata.threat.threat_feed_name 1 value
eq: Tor Exit Nodes 7 rules
host.id 1 value
is_not_null: 7 rules
- Alerts in Different ATT&CK Tactics by Host
- Entra ID Phishing Kit Default OS Build (Entity Analytics)
- Lateral Movement Alerts from a Newly Observed Source Address
- Lateral Movement Alerts from a Newly Observed User
- LLM-Based Attack Chain Triage by Host
- Multiple Alerts in Same ATT&CK Tactic by Host
- Multiple External EDR Alerts by Host
isutility 1 value
eq: true 7 rules
match_count 1 value
gt: 0 7 rules
T1548, Sudo and Sudo Caching T1548.003, Account Manipulation T1098, SSH Authorized Keys T1098.004, Scheduled Task/Job T1053, Cron T1053.003- Linux Auditd Doas Conf File Creation
- Linux Auditd Possible Access Or Modification Of Sshd Config File
- Linux Auditd Possible Access To Sudoers File
- Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File
- Linux Auditd Preload Hijack Via Preload File
- Linux Auditd Unix Shell Configuration Modification
- Linux Magic SysRq Key Abuse
process.parent.thread.Ext.call_stack_contains_unbacked 1 value
eq: true 7 rules
- Potential Injection via the Console Window Class
- Potential Process Creation via ShellCode
- Process Creation from Unbacked Memory via Unsigned Parent
- Process Creation with Unusual Mitigation
- Process from Archive or Removable Media via Unbacked Code
- Suspicious Suspended Process Creation
- Windows Console Execution from Unbacked Memory
process.thread.Ext.call_stack_final_user_module.code_signature 1 value
is_not_null: 7 rules
- Process Memory Write to a Non Child Process
- Remote Memory Write to Trusted Target Process
- Remote Process Memory Write by Low Reputation Module
- Shellcode API behavior from a signed module
- Shellcode behavior from suspicious RWX provenance
- Shellcode Heap Allocation from Unbacked Memory
- VirtualProtect via Vectored Exception Handling
tld 1 value
CategoryValue 1 value
eq: administrative 6 rules, 2 vendors
T1578, Delete Cloud Instance T1578.003, Steal Application Access Token T1528, Use Alternate Authentication Material T1550- Microsoft Entra ID Hybrid Health AD FS New Server
- Microsoft Entra ID Hybrid Health AD FS Service Delete
- Microsoft Entra ID Hybrid Health AD FS Suspicious Application
- NRT Microsoft Entra ID Hybrid Health AD FS New Server
- Azure Active Directory Hybrid Health AD FS New Server
- Azure Active Directory Hybrid Health AD FS Service Delete
ResourceProviderValue 1 value
eq: microsoft.adhybridhealthservice 6 rules, 2 vendors
T1578, Delete Cloud Instance T1578.003, Steal Application Access Token T1528, Use Alternate Authentication Material T1550- Microsoft Entra ID Hybrid Health AD FS New Server
- Microsoft Entra ID Hybrid Health AD FS Service Delete
- Microsoft Entra ID Hybrid Health AD FS Suspicious Application
- NRT Microsoft Entra ID Hybrid Health AD FS New Server
- Azure Active Directory Hybrid Health AD FS New Server
- Azure Active Directory Hybrid Health AD FS Service Delete
properties.result 1 value
1 1 value
@timestamp 1 value
All_Changes.status 1 value
eq: success 6 rules
- Cloud API Calls From Previously Unseen User Roles
- Cloud Instance Modified By Previously Unseen User
- Cloud Provisioning Activity From Previously Unseen City
- Cloud Provisioning Activity From Previously Unseen Country
- Cloud Provisioning Activity From Previously Unseen IP Address
- Cloud Provisioning Activity From Previously Unseen Region
Anomalies 1 value
gt: 0 6 rules
T1078, Data from Cloud Storage T1530, Native API T0834, Valid Accounts T0859, Execution through API T0871, Steal Application Access Token T1528- Anomalous sign-in location by user account and authenticating application
- Anomaly Sign In Event from an IP
- Brute force attack against an Entra-authenticated Windows device
- Dataverse - Anomalous application user activity
- Suspicious access of BEC related documents
- Suspicious access of BEC related documents in AWS S3 buckets
ClientIp 1 value
is_not_null: 6 rules
T1078, External Remote Services T1133, Exploit Public-Facing Application T1190, Cloud Service Discovery T1526, Cloud Service Dashboard T1538, Exfiltration Over Web Service T1567- Dataverse - Honeypot instance activity
- Dataverse - Login from IP in the block list
- Dataverse - Login from IP not in the allow list
- Dataverse - New sign-in from an unauthorized domain
- Dataverse - TI map IP to DataverseActivity
- Dataverse - Unusual sign-in following disabled IP address-based cookie binding protection
Esql.event_module_distinct_count 1 value
ge: 2 6 rules
SrcBytes 1 value
Total_TransactionId 1 value
category_type 1 value
domain 1 value
is_not_null: 6 rules
event.Success 1 value
recipients.to[0].email.email 1 value
cross_field_compare: sender.email.email 6 rules
- Credential phishing content and link (untrusted sender)
- Link: File sharing impersonation with suspicious language and sending patterns
- Link: Self-sender with IP geolocation check and suspicious link behavior
- Link: Self-sent PDF lure with subject correlation
- Link: SharePoint OneNote or PDF link with self sender behavior
- Self-impersonation: Sender matches recipient with bolded name and suspicious link
score 1 value
ge: 5 6 rules
T1008, Dynamic Resolution T1568, Non-Application Layer Protocol T1095, Encrypted Channel T1573, Gather Victim Network Information T1590, Data Transfer Size Limits T1030- Anomaly found in Network Session Traffic (ASIM Network Session schema)
- Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution)
- Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution)
- Detect port misuse by anomaly based detection (ASIM Network Session schema)
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution)
- Rare client observed with high reverse DNS lookup count - Anomaly based (ASIM DNS Solution)
sha1 1 value
data.details.response.statusCode 1 value
eq: 200 5 rules, 2 vendors
user.username 1 value
EXECUTION_STATUS 1 value
FileHashValue 1 value
IsHotwordAnomalyOnStatement 1 value
eq: true 5 rules
PassedControls 1 value
PassedControlsPercentage 1 value
SrcFileName 1 value
ThreatName 1 value
TotalHits 1 value
admonEventType 1 value
baseline 1 value
gt: 0 5 rules
T1496, Command and Scripting Interpreter T1059, Non-Application Layer Protocol T1095, Exploit Public-Facing Application T1190, Exploitation for Client Execution T1203- Detect port misuse by anomaly based detection (ASIM Network Session schema)
- Detect unauthorized data transfers using timeseries anomaly (ASIM Web Session)
- Mass Cloud resource deletions Time Series Anomaly
- Suspicious number of resource creation or deployment activities
- Threat Essentials - Mass Cloud resource deletions Time Series Anomaly
file.directory 1 value
is_null: 5 rules
T1027, Command Obfuscation T1027.010, Command and Scripting Interpreter T1059, PowerShell T1059.001, Deobfuscate/Decode Files or Information T1140- Dynamic IEX Reconstruction via Method String Access
- Potential PowerShell Obfuscation via High Numeric Character Proportion
- Potential PowerShell Obfuscation via High Special Character Proportion
- Potential PowerShell Obfuscation via Invalid Escape Sequences
- Potential PowerShell Obfuscation via String Reordering
gen_ai.policy.action 1 value
eq: blocked 5 rules
github.hashed_token 1 value
is_not_null: 5 rules
- First Occurrence GitHub Event for a Personal Access Token (PAT)
- First Occurrence of IP Address For GitHub Personal Access Token (PAT)
- First Occurrence of Personal Access Token (PAT) Use For a GitHub User
- First Occurrence of Private Repo Event from Specific GitHub Personal Access Token (PAT)
- First Occurrence of User Agent For a GitHub Personal Access Token (PAT)
github.repository_public 1 value
eq: false 5 rules
T1213, Code Repositories T1213.003, Serverless Execution T1648, Command and Scripting Interpreter T1059, Valid Accounts T1078, Cloud Accounts T1078.004- First Occurrence of GitHub Repo Interaction From a New IP
- First Occurrence of GitHub User Interaction with Private Repo
- First Occurrence of Private Repo Event from Specific GitHub Personal Access Token (PAT)
- Github Activity on a Private Repository from an Unusual IP
- High Number of Cloned GitHub Repos From PAT
inspected_document 1 value
is_not_null: 5 rules
kibana.alert.workflow_status 1 value
kubernetes.audit.objectRef.subresource 1 value
ml.nlu_classifier 1 value
func_call: ml.nlu_classifier(body.current_thread.text).language == english 5 rules
ml.nlu_classifier(body.current_thread.text).intents 1 value
length_compare: 0 5 rules
module_s 1 value
unique_targets 1 value
upwind_is_known_severity 1 value
user.email 1 value
userPrincipalName 1 value
contains: @ 5 rules
T1550, Application Access Token T1550.001, Account Manipulation T1098- First access credential added to Application or Service Principal where no credential was present
- Mail.Read Permissions Granted to Application
- New access credential added to Application or Service Principal
- NRT First access credential added to Application or Service Principal where no credential was present
- NRT New access credential added to Application or Service Principal
OldTargetUserName 1 value
ends_with: $ 4 rules, 3 vendors
All_Traffic.transport 1 value
AmpFileName 1 value
CollectorHostName 1 value
Condition 1 value
is_null: 4 rules
Esql.dest_host 1 value
Esql.destination_host_count 1 value
Esql.event_category_distinct_count 1 value
Esql.executed_command 1 value
Esql.host_key 1 value
EventTime_t 1 value
cross_field_compare: min_t 4 rules
T1008, Dynamic Resolution T1568, Encrypted Channel T1573, Data Transfer Size Limits T1030, Network Service Discovery T1046, Application Layer Protocol T1071- Anomaly found in Network Session Traffic (ASIM Network Session schema)
- Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution)
- Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution)
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution)
FileDirection 1 value
Fqdn 1 value
is_not_null: 4 rules
MSTI 1 value
MultipleClientErrors 1 value
MultipleServerErrors 1 value
OriginalRequestId 1 value
PermissionGrant 1 value
contains: rolemanagement.readwrite.directory 4 rules
T1098, Additional Cloud Roles T1098.003, Valid Accounts T1078, Cloud Accounts T1078.004- [Entra ID] Application Assigned Administrator Permissions Immediately After Obtaining Role Management Permissions
- [Entra ID] Application Granted Administrative Permission to Assign Microsoft Entra ID Roles
- Admin promotion after Role Management Application Permission Grant
- Microsoft Entra ID Role Management Permission Grant
QueryExecutionStatus 1 value
RecipientEmailAddress 1 value
SenderFromAddress 1 value
ServiceSid 1 value
ends_with: -502 4 rules
Target.process.name 1 value
TpmActivated 1 value
ne: true 4 rules
T1021, Remote Desktop Protocol T1021.001, Credentials from Password Stores T1555, Windows Credential Manager T1555.004, Forge Web Credentials T1606- Detect Suspicious ncrypt.dll usage on admin device with RDP connections to non TPM protected device
- Detect Suspicious ncrypt.dll usage with RDP connections to unmanaged or non TPM protected device
- Hunt for critical credentials on non-TPM enabled devices
- Hunt for RDP sessions to unmanaged and non TPM devices
TpmEnabled 1 value
ne: true 4 rules
T1021, Remote Desktop Protocol T1021.001, Credentials from Password Stores T1555, Windows Credential Manager T1555.004, Forge Web Credentials T1606- Detect Suspicious ncrypt.dll usage on admin device with RDP connections to non TPM protected device
- Detect Suspicious ncrypt.dll usage with RDP connections to unmanaged or non TPM protected device
- Hunt for critical credentials on non-TPM enabled devices
- Hunt for RDP sessions to unmanaged and non TPM devices
TpmSupported 1 value
ne: true 4 rules
T1021, Remote Desktop Protocol T1021.001, Credentials from Password Stores T1555, Windows Credential Manager T1555.004, Forge Web Credentials T1606- Detect Suspicious ncrypt.dll usage on admin device with RDP connections to non TPM protected device
- Detect Suspicious ncrypt.dll usage with RDP connections to unmanaged or non TPM protected device
- Hunt for critical credentials on non-TPM enabled devices
- Hunt for RDP sessions to unmanaged and non TPM devices