YARA-L non-Windows coverage

248 non-Windows YARA-L detection rules across 9 platforms, grouped by MITRE ATT&CK technique within each platform. The Windows coverage matrix lives at /rules/chronicle/; this page reorganizes the same corpus along platform × technique because non-Windows rules have no catalog event IDs to plot.

For coverage organized by each platform's native action vocabulary across all vendors, see the platform matrices: AWS, Azure AD, GCP, M365, Okta. This page is the vendor-organized browse of the same rules.

Platform (all)
Domain (all)

AWS

Resource Development

Compromise Accounts T1586 1 rule
Obtain Capabilities T1588 1 rule

Execution

User Execution T1204 1 rule
User Execution: Malicious File T1204.002 1 rule
Serverless Execution T1648 1 rule

Persistence

Account Manipulation T1098 2 rules
Create Account: Cloud Account T1136.003 2 rules
Boot or Logon Initialization Scripts T1037 1 rule

Stealth

Impair Defenses T1562 7 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 5 rules
Valid Accounts: Cloud Accounts T1078.004 4 rules
Valid Accounts T1078 2 rules
Unused/Unsupported Cloud Regions T1535 1 rule

Defense Impairment

Modify Authentication Process: Multi-Factor Authentication T1556.006 2 rules
Weaken Encryption: Reduce Key Space T1600.001 2 rules

Credential Access

Brute Force: Credential Stuffing T1110.004 2 rules
Credentials from Password Stores T1555 2 rules
Brute Force T1110 1 rule
Unsecured Credentials T1552 1 rule

Discovery

Cloud Infrastructure Discovery T1580 3 rules
Password Policy Discovery T1201 1 rule

Lateral Movement

Use Alternate Authentication Material T1550 1 rule

Command & Control

Application Layer Protocol T1071 2 rules
Proxy: Multi-hop Proxy T1090.003 1 rule
Dynamic Resolution: Domain Generation Algorithms T1568.002 1 rule

Exfiltration

Transfer Data to Cloud Account T1537 2 rules

Impact

Resource Hijacking T1496 2 rules
Data Destruction T1485 1 rule
Inhibit System Recovery T1490 1 rule
Network Denial of Service T1498 1 rule

Azure

Initial Access

Phishing T1566 1 rule

Persistence

Account Manipulation: Additional Cloud Roles T1098.003 3 rules
Account Manipulation: Additional Cloud Credentials T1098.001 1 rule

Stealth

Valid Accounts: Cloud Accounts T1078.004 2 rules

Defense Impairment

Domain or Tenant Policy Modification T1484 1 rule

Lateral Movement

Use Alternate Authentication Material: Application Access Token T1550.001 1 rule

Untagged

GCP

Initial Access

No specific technique 1 rule

Execution

User Execution T1204 1 rule

Persistence

Account Manipulation T1098 1 rule
Account Manipulation: Additional Cloud Credentials T1098.001 1 rule
Account Manipulation: Additional Cloud Roles T1098.003 1 rule
Create Account: Cloud Account T1136.003 1 rule
No specific technique 2 rules

Privilege Escalation

No specific technique 1 rule

Stealth

Impair Defenses T1562 4 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 2 rules
Valid Accounts: Cloud Accounts T1078.004 1 rule
No specific technique 1 rule

Credential Access

Unsecured Credentials: Private Keys T1552.004 1 rule
Credentials from Password Stores T1555 1 rule

Discovery

Cloud Infrastructure Discovery T1580 1 rule

Exfiltration

Transfer Data to Cloud Account T1537 1 rule
Exfiltration Over Web Service T1567 1 rule

Impact

Data Destruction T1485 2 rules
Service Stop T1489 1 rule
Account Access Removal T1531 1 rule

Microsoft 365

Persistence

Account Manipulation: Additional Cloud Credentials T1098.001 2 rules
Account Manipulation: Additional Cloud Roles T1098.003 2 rules

Stealth

Valid Accounts: Cloud Accounts T1078.004 3 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 2 rules

Lateral Movement

Remote Services: Cloud Services T1021.007 1 rule
Exploitation of Remote Services T1210 1 rule

Exfiltration

Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.002 4 rules

Untagged

Google Workspace

Initial Access

Phishing T1566 1 rule
Phishing: Spearphishing Link T1566.002 1 rule

Execution

User Execution: Malicious File T1204.002 1 rule

Persistence

Account Manipulation: Additional Cloud Roles T1098.003 3 rules
Account Manipulation T1098 1 rule
No specific technique 1 rule

Stealth

Valid Accounts: Cloud Accounts T1078.004 2 rules
Valid Accounts T1078 1 rule
Impair Defenses: Disable or Modify Tools T1562.001 1 rule
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 1 rule

Defense Impairment

Modify Authentication Process T1556 1 rule

Credential Access

Unsecured Credentials: Private Keys T1552.004 1 rule

Collection

Data Staged: Remote Data Staging T1074.002 1 rule

Exfiltration

Exfiltration Over Web Service T1567 6 rules

Impact

Data Destruction T1485 1 rule

Untagged

Okta

Initial Access

Phishing T1566 1 rule

Stealth

Valid Accounts T1078 7 rules

Defense Impairment

Modify Authentication Process: Multi-Factor Authentication T1556.006 1 rule

Credential Access

Brute Force T1110 3 rules
Multi-Factor Authentication Request Generation T1621 2 rules
Brute Force: Password Guessing T1110.001 1 rule
Brute Force: Password Spraying T1110.003 1 rule
Brute Force: Credential Stuffing T1110.004 1 rule
Steal Web Session Cookie T1539 1 rule

Lateral Movement

Use Alternate Authentication Material: Web Session Cookie T1550.004 1 rule

GitHub

Persistence

Account Manipulation: Additional Cloud Credentials T1098.001 2 rules

Stealth

Impair Defenses: Disable or Modify Tools T1562.001 6 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 2 rules

Credential Access

Unsecured Credentials T1552 1 rule

Collection

Data from Information Repositories: Code Repositories T1213.003 3 rules

Exfiltration

Transfer Data to Cloud Account T1537 1 rule

Impact

Data Destruction T1485 3 rules

Untagged

Identity

Stealth

Valid Accounts: Cloud Accounts T1078.004 3 rules

Defense Impairment

Modify Authentication Process: Multi-Factor Authentication T1556.006 1 rule

Credential Access

Brute Force T1110 1 rule
Unsecured Credentials T1552 1 rule

Lateral Movement

Use Alternate Authentication Material T1550 1 rule

Application

Initial Access

Exploit Public-Facing Application T1190 1 rule

Execution

Shared Modules T1129 2 rules
Command and Scripting Interpreter T1059 1 rule

Persistence

Account Manipulation T1098 10 rules
Create Account T1136 3 rules

Stealth

Impair Defenses T1562 3 rules
Impair Defenses: Disable or Modify Tools T1562.001 2 rules
Hide Artifacts T1564 1 rule

Credential Access

Brute Force T1110 1 rule

Discovery

System Information Discovery T1082 1 rule

Collection

Data from Local System T1005 2 rules

Exfiltration

Exfiltration Over C2 Channel T1041 1 rule

Untagged