YARA-L non-Windows coverage
248 non-Windows YARA-L detection rules across 9 platforms, grouped by MITRE ATT&CK technique within each platform. The Windows coverage matrix lives at /rules/chronicle/; this page reorganizes the same corpus along platform × technique because non-Windows rules have no catalog event IDs to plot.
For coverage organized by each platform's native action vocabulary across all vendors, see the platform matrices: AWS, Azure AD, GCP, M365, Okta. This page is the vendor-organized browse of the same rules.
AWS
Resource Development
Execution
Persistence
Account Manipulation T1098 2 rules
Stealth
Impair Defenses T1562 7 rules
Valid Accounts T1078 2 rules
Defense Impairment
Credential Access
Discovery
Lateral Movement
Command & Control
Application Layer Protocol T1071 2 rules
Exfiltration
Impact
Resource Hijacking T1496 2 rules
Azure
Initial Access
Persistence
Stealth
Defense Impairment
Lateral Movement
Untagged
- API access to mailboxes for top N messages via the Microsoft Graph
- Entra ID Application Creation
- Entra ID Application Deletion
- Entra ID application enumeration observed in the Microsoft Graph API
- Entra ID Application Hard Deletion
- Entra ID Application Restore
- Entra ID Excessive Permission Changes to Application
- Entra ID Login Activity to Azure AD PowerShell Application
- Entra ID Successful Group Deletion
- Enumeration observed in the Microsoft Graph API using GraphRunner GraphRecon command
- Enumeration of inboxes accessible by a user in the Microsoft Graph API
- Enumeration of updatable groups in the Microsoft Graph API
- Enumeration of users and group membership observed in the Microsoft Graph API
- Hunt for application API calls in the Microsoft Graph
- Hunt for authorization policy API calls in the Microsoft Graph
- Hunt for Bad Request errors against the Groups endpoint in the Microsoft Graph API
- Hunt for group members enumeration in the Microsoft Graph API
- Hunt for Groups endpoint requests in the Microsoft Graph API
- Hunt for search/query endpoint API requests in the Microsoft Graph
- Hunt for successful group creation in the Microsoft Graph API
- Hunt for the delete method in Microsoft Graph API calls
- Hunt for Undocumented API - Estimate Access called in Microsoft Graph API
- Hunt for user API endpoint requests in the Microsoft Graph
- Multiple failed file downloads from OneDrive observed in the Microsoft Graph API
- Multiple failed unique file downloads from OneDrive observed in the Microsoft Graph API
- Suspicious User Agent Strings associated withGraphRunner
GCP
Initial Access
No specific technique 1 rule
Execution
Persistence
No specific technique 2 rules
Privilege Escalation
No specific technique 1 rule
Stealth
Impair Defenses T1562 4 rules
No specific technique 1 rule
Credential Access
Discovery
Exfiltration
Impact
Data Destruction T1485 2 rules
Microsoft 365
Persistence
Stealth
Lateral Movement
Exfiltration
Untagged
- Hunt for Office 365 group creation failures
- Hunt for Office 365 group creation success
- Hunt for Office 365 group modification add member success
- Hunt for Office 365 group modification remove member success
- Hunt for suspicious sign-in to Entra ID Using Extrnal Call Method
- O365 Entra ID App Modify Permission Change On Watchlist
- O365 Entra ID App Permissions Percent Threshold Exceeded
- O365 Entra ID App Permissions Threshold Exceeded
- O365 Entra ID Application Creation
- O365 OneDrive Anonymous Link Created or Updated
- Office 365 group deletion success
- Office 365 group modification add member success has exceeded a defined threshold
- Office 365 mail accessed via unexpected application
- Office 365 Teams member removed
Google Workspace
Initial Access
Execution
Persistence
No specific technique 1 rule
Stealth
Defense Impairment
Credential Access
Collection
Exfiltration
Exfiltration Over Web Service T1567 6 rules
- Google Workspace File Shared From Google Drive To Free Email Domain
- Google Workspace Multiple Files Copied From Google Drive
- Google Workspace Multiple Files Downloaded From Google Drive
- Google Workspace Multiple Files Sent As Email Attachments From Google Drive
- Google Workspace Suspicious Login and Google Drive File Download
- Google Workspace Suspicious Login and Google Drive File Share
Impact
Untagged
Okta
Initial Access
Stealth
Defense Impairment
Credential Access
Brute Force T1110 3 rules
Lateral Movement
GitHub
Persistence
Stealth
Credential Access
Collection
Exfiltration
Impact
Untagged
- GitHub Application Installed
- GitHub Enterprise Or Organization Recovery Codes Activity
- GitHub Invitation Sent To Non Company Email Domain
- GitHub OAuth Application Access Restrictions Disabled
- GitHub Outgoing Repository Transfer Initiated
- GitHub Repository Visibility Changed To Public
- GitHub User Blocked From Accessing Organization Repositories
- GitHub User Unblocked From Accessing Organization Repositories
Identity
Stealth
Defense Impairment
Credential Access
Lateral Movement
Application
Initial Access
Execution
Shared Modules T1129 2 rules
Persistence
Account Manipulation T1098 10 rules
- sap change documents sensitive profile assignment
- sap change documents sensitive profile assignment data table
- sap change documents sensitive role assignment
- sap critial role assigned to new user
- sap critical authorization value changed
- sap critical role assigned to new user
- sap hanadb assign admin authorizations
- sap multiple password changes
- sap sensitive role assignment correlation
- sap sensitive role authorization modification