Kusto non-Windows coverage
1,924 non-Windows Kusto detection rules across 13 platforms, grouped by MITRE ATT&CK technique within each platform. The Windows coverage matrix lives at /rules/kusto/; this page reorganizes the same corpus along platform × technique because non-Windows rules have no catalog event IDs to plot.
For coverage organized by each platform's native action vocabulary across all vendors, see the platform matrices: AWS, Azure AD, GCP, M365, Okta. This page is the vendor-organized browse of the same rules.
Linux
Reconnaissance
Active Scanning T1595 1 rule
- Dataverse - Suspicious use of Web API available
Initial Access
Exploit Public-Facing Application T1190 18 rules
- AV detections related to SpringShell Vulnerability available
- Cisco SE - Malware outbreak available
- Cisco SE - Multiple malware on host available
- Cisco SE - Unexpected binary file available
- Cisco SE High Events Last Hour available
- Dataverse - Login by a sensitive privileged user available
- Dataverse - Login from IP in the block list available
- Dataverse - Login from IP not in the allow list available
- Dataverse - New sign-in from an unauthorized domain available
- Dataverse - New user agent type that was not used with Office 365 available
- Dataverse - Suspicious use of TDS endpoint available
- Microsoft Defender for Endpoint (MDE) signatures for Azure Synapse pipelines and Azure Data Factory
- OracleDBAudit - Connection to database from external IP available
- OracleDBAudit - SQL injection patterns available
- Sentinel One - Alert from custom rule available
- Sentinel One - Multiple alerts on host available
- Sentinel One - Same custom rule triggered on different hosts available
- VMware ESXi - Dormant VM started
Phishing T1566 15 rules
- Cisco WSA - Access to unwanted site available
- Dataverse - TI map URL to DataverseActivity available
- McAfee ePO - Spam Email detected available
- Possible Phishing with CSL and Network Sessions available
- Power Apps - Multiple users access a malicious link after launching new app available
- Preview - TI map Email entity to Cloud App Events
- TI map Email entity to Cloud App Events
- Trend Micro CAS - Infected user available
- Trend Micro CAS - Multiple infected users available
- Trend Micro CAS - Possible phishing mail available
- Trend Micro CAS - Suspicious filename available
- Trend Micro CAS - Unexpected file on file share available
- Trend Micro CAS - Unexpected file via mail available
- User Accessed Suspicious URL Categories available
- Website blocked by ESET
Drive-by Compromise T1189 10 rules
- Cisco WSA - Internet access from public IP available
- Cisco WSA - Multiple attempts to download unwanted file available
- Cisco WSA - Multiple errors to resource from risky category available
- Cisco WSA - Multiple infected files available
- Cisco WSA - Unexpected file type available
- Cisco WSA - Unscannable file or scan error available
- McAfee ePO - Multiple threats on same host available
- McAfee ePO - Threat was not blocked available
- Power Apps - Multiple users access a malicious link after launching new app available
- Website blocked by ESET
Supply Chain Compromise T1195 2 rules
- McAfee ePO - Multiple threats on same host available
- McAfee ePO - Threat was not blocked available
Trusted Relationship T1199 1 rule
Hardware Additions T1200 1 rule
- Potential DHCP Starvation Attack available
Execution
User Execution: Malicious File T1204.002 5 rules
- Cisco SE - Dropper activity on host available
- Cisco SE - Generic IOC available
- Cisco SE - Malware execusion on host available
- Cisco SE High Events Last Hour available
- Malware Detected available
User Execution T1204 4 rules
Scheduled Task/Job T1053 1 rule
- AV detections related to Tarrask malware available
Native API T1106 1 rule
- Dataverse - Suspicious use of Web API available
System Services T1569 1 rule
Persistence
External Remote Services T1133 12 rules
- Cisco SE - Malware outbreak available
- Cisco SE - Multiple malware on host available
- Cisco SE - Unexpected binary file available
- CiscoISE - Command executed with the highest privileges from new IP available
- CiscoISE - Command executed with the highest privileges by new user available
- Dataverse - Login by a sensitive privileged user available
- Dataverse - Login from IP in the block list available
- Dataverse - Login from IP not in the allow list available
- Dataverse - New sign-in from an unauthorized domain available
- Dataverse - New user agent type that was not used with Office 365 available
- Dataverse - TI map IP to DataverseActivity available
- OracleDBAudit - Connection to database from external IP available
Account Manipulation T1098 4 rules
Create Account T1136 1 rule
- GitLab - External User Added to GitLab available
Privilege Escalation
Abuse Elevation Control Mechanism T1548 5 rules
- CiscoISE - Command executed with the highest privileges from new IP available
- CiscoISE - Command executed with the highest privileges by new user available
- Dataverse - Bulk record ownership re-assignment or sharing available
- Dataverse - Hierarchy security manipulation available
- Dataverse - Suspicious security role modifications available
Exploitation for Privilege Escalation T1068 2 rules
- CTERA Mass Permissions Changes Detection Analytic available
- McAfee ePO - Threat was not blocked available
Event Triggered Execution T1546 1 rule
- Defender Alert Evidence available
Stealth
Valid Accounts T1078 26 rules
- Dataverse - Hierarchy security manipulation available
- Dataverse - Login by a sensitive privileged user available
- Dataverse - Login from IP in the block list available
- Dataverse - Login from IP not in the allow list available
- Dataverse - New Dataverse application user activity type available
- Dataverse - New non-interactive identity granted access available
- Dataverse - New sign-in from an unauthorized domain available
- Dataverse - New user agent type that was not used before available
- Dataverse - Organization settings modified available
- Dataverse - TI map IP to DataverseActivity available
- GitLab - TI - Connection from Malicious IP available
- GitLab - User Impersonation available
- OracleDBAudit - Connection to database from external IP available
- OracleDBAudit - Connection to database from unknown IP available
- OracleDBAudit - New user account available
- OracleDBAudit - User activity after long inactivity time available
- OracleDBAudit - User connected to database from new IP available
- Potential Ransomware activity related to Cobalt Strike available
- Sentinel One - Admin login from new location available
- Sentinel One - New admin created available
- VMware ESXi - Multiple new VMs started available
- VMware ESXi - New VM started available
- VMware ESXi - Root impersonation available
- VMware ESXi - Root login available
- VMware ESXi - Root password changed available
- VMware ESXi - Shared or stolen root account available
Impair Defenses T1562 24 rules
- Cisco SE - Policy update failure available
- CTERA Mass Access Denied Detection Analytic available
- Dataverse - Audit logging disabled available
- Excessive Denied Proxy Traffic available
- Illumio Enforcement Change Analytic Rule available
- Illumio Firewall Tampering Analytic Rule available
- Illumio VEN Clone Detection Rule available
- Illumio VEN Deactivated Detection Rule available
- Illumio VEN Offline Detection Rule available
- Illumio VEN Suspend Detection Rule available
- McAfee ePO - Agent Handler down available
- McAfee ePO - Attempt uninstall McAfee agent available
- McAfee ePO - Deployment failed available
- McAfee ePO - Error sending alert available
- McAfee ePO - File added to exceptions available
- McAfee ePO - Firewall disabled available
- McAfee ePO - Logging error occurred available
- McAfee ePO - Multiple threats on same host available
- McAfee ePO - Scanning engine disabled available
- McAfee ePO - Task error available
- McAfee ePO - Threat was not blocked available
- McAfee ePO - Unable to clean or delete infected file available
- McAfee ePO - Update failed available
- Trend Micro CAS - Threat detected and not blocked available
Indicator Removal T1070 18 rules
- CiscoISE - Attempt to delete local store logs available
- Dataverse - Audit log data deletion available
- McAfee ePO - Attempt uninstall McAfee agent available
- McAfee ePO - Error sending alert available
- McAfee ePO - File added to exceptions available
- McAfee ePO - Logging error occurred available
- McAfee ePO - Multiple threats on same host available
- McAfee ePO - Scanning engine disabled available
- McAfee ePO - Task error available
- McAfee ePO - Threat was not blocked available
- McAfee ePO - Unable to clean or delete infected file available
- McAfee ePO - Update failed available
- Potential Ransomware activity related to Cobalt Strike available
- Sentinel One - Agent uninstalled from multiple hosts available
- Sentinel One - Blacklist hash deleted available
- Sentinel One - Exclusion added available
- Sentinel One - Rule deleted available
- Sentinel One - Rule disabled available
Process Injection T1055 1 rule
Indicator Removal: File Deletion T1070.004 1 rule
- CiscoISE - Log files deleted available
Impair Defenses: Disable Windows Event Logging T1562.002 1 rule
- CiscoISE - Log collector was suspended available
Hijack Execution Flow T1574 1 rule
Defense Impairment
Modify Authentication Process T1556 2 rules
- GitLab - Repository visibility to Public available
- VMware ESXi - Root password changed available
Credential Access
Brute Force T1110 9 rules
- ClientDeniedAccess available
- Excessive Failed Authentication from Invalid Inputs available
- Failed logon attempts in authpriv
- GitLab - Brute-force Attempts available
- GitLab - Local Auth - No MFA available
- PulseConnectSecure - Large Number of Distinct Failed User Logins available
- PulseConnectSecure - Potential Brute Force Attempts available
- SSH - Potential Brute Force
- VMware ESXi - Multiple Failed Shell Login via SSH available
Unsecured Credentials T1552 1 rule
- CiscoISE - Certificate has expired available
Steal or Forge Kerberos Tickets: Kerberoasting T1558.003 1 rule
- Detect Potential Kerberoast Activities available
No specific technique 1 rule
Discovery
Cloud Service Discovery T1526 3 rules
- Dataverse - Honeypot instance activity available
- Dataverse - Suspicious use of Web API available
- Dataverse - TI map IP to DataverseActivity available
Cloud Infrastructure Discovery T1580 2 rules
- Dataverse - Suspicious use of Web API available
- Dataverse - TI map IP to DataverseActivity available
Network Service Discovery T1046 1 rule
- Port Scan Detected available
System Information Discovery T1082 1 rule
- Pathlock TDnR - SAP System Log Events available
Cloud Service Dashboard T1538 1 rule
- Dataverse - Honeypot instance activity available
No specific technique 1 rule
Lateral Movement
Remote Services T1021 3 rules
Exploitation of Remote Services T1210 3 rules
- Critical Threat Detected available
- Dataverse - TI map IP to DataverseActivity available
- Sentinel One - Same custom rule triggered on different hosts available
Collection
Automated Collection T1119 2 rules
Data from Local System T1005 1 rule
- OracleDBAudit - Query on Sensitive Table available
Command & Control
Application Layer Protocol T1071 25 rules
- Cisco SE - Connection to known C2 server available
- Lumen TI IPAddress in DeviceEvents
- McAfee ePO - Firewall disabled available
- Preview - TI map Domain entity to Cloud App Events
- Preview - TI map IP entity to Cloud App Events
- Preview - TI map URL entity to Cloud App Events
- TI map Domain entity to Cloud App Events
- TI Map Domain Entity to DeviceNetworkEvents
- TI Map Domain Entity to DeviceNetworkEvents
- TI map Domain entity to Syslog
- TI map Domain entity to Syslog
- TI map File Hash to DeviceFileEvents Event
- TI map File Hash to DeviceFileEvents Event
- TI map IP entity to Cloud App Events
- TI Map IP Entity to DeviceNetworkEvents
- TI Map IP Entity to DeviceNetworkEvents
- TI map URL entity to Cloud App Events
- TI Map URL Entity to DeviceNetworkEvents
- TI Map URL Entity to DeviceNetworkEvents
- TI Map URL Entity to Syslog Data
- TI Map URL Entity to Syslog Data
- TI Map URL Entity to UrlClickEvents
- TI Map URL Entity to UrlClickEvents
- User Accessed Suspicious URL Categories available
- Website blocked by ESET
Web Service T1102 7 rules
- Cisco SE - Possible webshell available
- Cisco WSA - Multiple errors to resource from risky category available
- Cisco WSA - Multiple errors to URL available
- Cisco WSA - Unexpected URL available
- NRT Squid proxy events related to mining pools
- Possible Phishing with CSL and Network Sessions available
- Squid proxy events related to mining pools
Fallback Channels T1008 2 rules
Proxy T1090 2 rules
Dynamic Resolution T1568 2 rules
- CiscoISE - Device changed IP in last 24 hours available
- Excessive NXDOMAIN DNS Queries available
Data Obfuscation T1001 1 rule
Data Encoding T1132 1 rule
Exfiltration
Exfiltration Over Alternative Protocol T1048 15 rules
- Cisco WSA - Suspected protocol abuse available
- Dataverse - Export activity from terminated or notified employee available
- Dataverse - Suspicious use of TDS endpoint available
- Dataverse - User bulk retrieval outside normal activity available
- Digital Guardian - Bulk exfiltration to external domain available
- Digital Guardian - Exfiltration to external domain available
- Digital Guardian - Exfiltration to online fileshare available
- Digital Guardian - Exfiltration to private email available
- Digital Guardian - Exfiltration using DNS protocol available
- Digital Guardian - Incident with not blocked action available
- Digital Guardian - Multiple incidents from user available
- Digital Guardian - Possible SMTP protocol abuse available
- Digital Guardian - Sensitive data transfer over insecure channel available
- Digital Guardian - Unexpected protocol available
- Trend Micro CAS - DLP violation available
Exfiltration Over Web Service T1567 7 rules
- Cisco WSA - Unexpected uploads available
- Dataverse - Export activity from terminated or notified employee available
- Dataverse - Honeypot instance activity available
- Dataverse - Mass export of records to Excel available
- Dataverse - SharePoint document management site added or updated available
- Dataverse - Suspicious use of Web API available
- Dataverse - Terminated employee exfiltration over email available
Automated Exfiltration T1020 2 rules
Impact
Data Encrypted for Impact T1486 11 rules
- AV detections related to Dev-0530 actors
- AV detections related to Europium actors
- AV detections related to Hive Ransomware
- AV detections related to Zinc actors available
- Cisco SE - Ransomware Activity available
- Ransom Protect Detected a Ransomware Attack available
- Ransom Protect User Blocked available
- Ransomware Attack Detected available
- Ransomware Client Blocked available
- Trend Micro CAS - Ransomware infection available
- Trend Micro CAS - Ransomware outbreak available
Data Destruction T1485 7 rules
- AV detections related to Ukraine threats available
- CTERA Mass Deletions Detection Analytic available
- Dataverse - Mass deletion of records available
- Dataverse - Mass record updates available
- GitLab - Abnormal number of repositories deleted available
- OracleDBAudit - Multiple tables dropped in short time available
- Unusual Volume of file deletion by users available
System Shutdown/Reboot T1529 5 rules
- OracleDBAudit - Shutdown Server available
- VMware ESXi - Low patch disk space available
- VMware ESXi - Low temp directory space available
- VMware ESXi - Multiple VMs stopped available
- VMware ESXi - VM stopped available
Inhibit System Recovery T1490 2 rules
- CiscoISE - Backup failed available
- Potential Ransomware activity related to Cobalt Strike available
Data Manipulation T1565 2 rules
- Dataverse - Mass record updates available
- Infoblox - TI - Syslog Match Found - URL available
Resource Hijacking T1496 1 rule
- VMware ESXi - Unexpected disk image available
Network Denial of Service T1498 1 rule
- Infoblox - TI - Syslog Match Found - URL available
Untagged
- Adding User or Group Failed available
- Application Group Deleted available
- Application Group Settings Updated available
- Archive Repository Deleted available
- Archive Repository Settings Updated available
- Attempt to Delete Backup Failed available
- Attempt to Update Security Object Failed available
- Backup Proxy Deleted available
- Backup Repository Deleted available
- Backup Repository Settings Updated available
- Cloud Gateway Deleted available
- Cloud Gateway Pool Deleted available
- Cloud Gateway Pool Settings Updated available
- Cloud Gateway Settings Updated available
- Cloud Replica Permanent Failover Performed by Tenant available
- Configuration Backup Job Failed available
- Configuration Backup Job Settings Updated available
- Connection to Backup Repository Lost available
- Create Incident for XDR Alerts available
- Credential Record Deleted available
- Credential Record Updated available
- Detaching Backups Started available
- Encryption Password Added available
- Encryption Password Changed available
- Encryption Password Deleted available
- External Repository Deleted available
- External Repository Settings Updated available
- Failover Plan Deleted available
- Failover Plan Failed available
- Failover Plan Settings Updated available
- Failover Plan Started available
- Failover Plan Stopped available
- File Server Deleted available
- File Server Settings Updated available
- File Share Deleted available
- Four-Eyes Authorization Disabled available
- Four-Eyes Authorization Request Created available
- Four-Eyes Authorization Request Expired available
- Four-Eyes Authorization Request Rejected available
- General Settings Updated available
- Global Network Traffic Rules Deleted available
- Global VM Exclusions Added available
- Global VM Exclusions Changed available
- Global VM Exclusions Deleted available
- Host Deleted available
- Host Settings Updated available
- Hypervisor Host Deleted available
- Hypervisor Host Settings Updated available
- Invalid Code for Multi-Factor Authentication Entered available
- Job Deleted available
- Job No Longer Used as Second Destination available
- KMS Key Rotation Job Finished available
- KMS Server Deleted available
- KMS Server Settings Updated available
- License Expired available
- License Expiring available
- License Grace Period Started available
- License Limit Exceeded available
- License Removed available
- License Support Expired available
- License Support Expiring available
- Malware Activity Detected available
- Malware Detection Exclusions List Updated available
- Malware Detection Session Finished available
- Malware Detection Settings Updated available
- Multi-Factor Authentication Disabled available
- Multi-Factor Authentication for User Disabled available
- Multi-Factor Authentication Token Revoked available
- Multi-Factor Authentication User Locked available
- NDMP Server Deleted available
- Object Marked as Clean available
- Object Storage Deleted available
- Object Storage Settings Updated available
- Objects Added to Malware Detection Exclusions available
- Objects Deleted from Malware Detection Exclusions available
- Objects for Job Deleted available
- Objects for Protection Group Changed available
- Objects for Protection Group Deleted available
- Preferred Networks Deleted available
- Protection Group Deleted available
- Protection Group Settings Updated available
- Recovery Token Deleted available
- Restore Point Marked as Clean available
- Restore Point Marked as Infected available
- Scale-Out Backup Repository Deleted available
- Scale-Out Backup Repository Settings Updated available
- Service Provider Deleted available
- Service Provider Updated available
- SSH Credentials Changed available
- Storage Deleted available
- Storage Settings Updated available
- Subtenant Deleted available
- Subtenant Updated available
- SureBackup Job Failed available
- Tape Erase Job Started available
- Tape Library Deleted available
- Tape Media Pool Deleted available
- Tape Media Vault Deleted available
- Tape Medium Deleted available
- Tape Server Deleted available
- Tenant Password Changed available
- Tenant Quota Changed available
- Tenant Quota Deleted available
- Tenant Replica Started available
- Tenant Replica Stopped available
- Tenant State Changed available
- Unusual Anomaly
- User or Group Added available
- User or Group Deleted available
- Virtual Lab Deleted available
- Virtual Lab Settings Updated available
- WAN Accelerator Deleted available
- WAN Accelerator Settings Updated available
macOS
Reconnaissance
Active Scanning T1595 1 rule
- Dataverse - Suspicious use of Web API available
Initial Access
Exploit Public-Facing Application T1190 15 rules
- AV detections related to SpringShell Vulnerability available
- Cisco SE - Malware outbreak available
- Cisco SE - Multiple malware on host available
- Cisco SE - Unexpected binary file available
- Cisco SE High Events Last Hour available
- Dataverse - Login by a sensitive privileged user available
- Dataverse - Login from IP in the block list available
- Dataverse - Login from IP not in the allow list available
- Dataverse - New sign-in from an unauthorized domain available
- Dataverse - New user agent type that was not used with Office 365 available
- Dataverse - Suspicious use of TDS endpoint available
- Microsoft Defender for Endpoint (MDE) signatures for Azure Synapse pipelines and Azure Data Factory
- Sentinel One - Alert from custom rule available
- Sentinel One - Multiple alerts on host available
- Sentinel One - Same custom rule triggered on different hosts available
Phishing T1566 11 rules
- Dataverse - TI map URL to DataverseActivity available
- Possible Phishing with CSL and Network Sessions available
- Power Apps - Multiple users access a malicious link after launching new app available
- Preview - TI map Email entity to Cloud App Events
- TI map Email entity to Cloud App Events
- Trend Micro CAS - Infected user available
- Trend Micro CAS - Multiple infected users available
- Trend Micro CAS - Possible phishing mail available
- Trend Micro CAS - Suspicious filename available
- Trend Micro CAS - Unexpected file on file share available
- Trend Micro CAS - Unexpected file via mail available
Drive-by Compromise T1189 1 rule
Trusted Relationship T1199 1 rule
Execution
User Execution: Malicious File T1204.002 4 rules
- Cisco SE - Dropper activity on host available
- Cisco SE - Generic IOC available
- Cisco SE - Malware execusion on host available
- Cisco SE High Events Last Hour available
User Execution T1204 3 rules
Scheduled Task/Job T1053 1 rule
- AV detections related to Tarrask malware available
Native API T1106 1 rule
- Dataverse - Suspicious use of Web API available
System Services T1569 1 rule
Persistence
External Remote Services T1133 9 rules
- Cisco SE - Malware outbreak available
- Cisco SE - Multiple malware on host available
- Cisco SE - Unexpected binary file available
- Dataverse - Login by a sensitive privileged user available
- Dataverse - Login from IP in the block list available
- Dataverse - Login from IP not in the allow list available
- Dataverse - New sign-in from an unauthorized domain available
- Dataverse - New user agent type that was not used with Office 365 available
- Dataverse - TI map IP to DataverseActivity available
Privilege Escalation
Event Triggered Execution T1546 1 rule
- Defender Alert Evidence available
Stealth
Valid Accounts T1078 13 rules
- Dataverse - Hierarchy security manipulation available
- Dataverse - Login by a sensitive privileged user available
- Dataverse - Login from IP in the block list available
- Dataverse - Login from IP not in the allow list available
- Dataverse - New Dataverse application user activity type available
- Dataverse - New non-interactive identity granted access available
- Dataverse - New sign-in from an unauthorized domain available
- Dataverse - New user agent type that was not used before available
- Dataverse - Organization settings modified available
- Dataverse - TI map IP to DataverseActivity available
- Potential Ransomware activity related to Cobalt Strike available
- Sentinel One - Admin login from new location available
- Sentinel One - New admin created available
Indicator Removal T1070 7 rules
- Dataverse - Audit log data deletion available
- Potential Ransomware activity related to Cobalt Strike available
- Sentinel One - Agent uninstalled from multiple hosts available
- Sentinel One - Blacklist hash deleted available
- Sentinel One - Exclusion added available
- Sentinel One - Rule deleted available
- Sentinel One - Rule disabled available
Impair Defenses T1562 3 rules
- Cisco SE - Policy update failure available
- Dataverse - Audit logging disabled available
- Trend Micro CAS - Threat detected and not blocked available
Hijack Execution Flow T1574 1 rule
Credential Access
Steal or Forge Kerberos Tickets: Kerberoasting T1558.003 1 rule
- Detect Potential Kerberoast Activities available
No specific technique 1 rule
Discovery
Cloud Service Discovery T1526 3 rules
- Dataverse - Honeypot instance activity available
- Dataverse - Suspicious use of Web API available
- Dataverse - TI map IP to DataverseActivity available
Cloud Infrastructure Discovery T1580 2 rules
- Dataverse - Suspicious use of Web API available
- Dataverse - TI map IP to DataverseActivity available
Cloud Service Dashboard T1538 1 rule
- Dataverse - Honeypot instance activity available
No specific technique 1 rule
Lateral Movement
Exploitation of Remote Services T1210 3 rules
- Critical Threat Detected available
- Dataverse - TI map IP to DataverseActivity available
- Sentinel One - Same custom rule triggered on different hosts available
Remote Services T1021 1 rule
Command & Control
Application Layer Protocol T1071 18 rules
- Cisco SE - Connection to known C2 server available
- Lumen TI IPAddress in DeviceEvents
- Preview - TI map Domain entity to Cloud App Events
- Preview - TI map IP entity to Cloud App Events
- Preview - TI map URL entity to Cloud App Events
- TI map Domain entity to Cloud App Events
- TI Map Domain Entity to DeviceNetworkEvents
- TI Map Domain Entity to DeviceNetworkEvents
- TI map File Hash to DeviceFileEvents Event
- TI map File Hash to DeviceFileEvents Event
- TI map IP entity to Cloud App Events
- TI Map IP Entity to DeviceNetworkEvents
- TI Map IP Entity to DeviceNetworkEvents
- TI map URL entity to Cloud App Events
- TI Map URL Entity to DeviceNetworkEvents
- TI Map URL Entity to DeviceNetworkEvents
- TI Map URL Entity to UrlClickEvents
- TI Map URL Entity to UrlClickEvents
Web Service T1102 2 rules
- Cisco SE - Possible webshell available
- Possible Phishing with CSL and Network Sessions available
Exfiltration
Exfiltration Over Web Service T1567 6 rules
- Dataverse - Export activity from terminated or notified employee available
- Dataverse - Honeypot instance activity available
- Dataverse - Mass export of records to Excel available
- Dataverse - SharePoint document management site added or updated available
- Dataverse - Suspicious use of Web API available
- Dataverse - Terminated employee exfiltration over email available
Impact
Data Encrypted for Impact T1486 7 rules
- AV detections related to Dev-0530 actors
- AV detections related to Europium actors
- AV detections related to Hive Ransomware
- AV detections related to Zinc actors available
- Cisco SE - Ransomware Activity available
- Trend Micro CAS - Ransomware infection available
- Trend Micro CAS - Ransomware outbreak available
Data Destruction T1485 4 rules
- AV detections related to Ukraine threats available
- Dataverse - Mass deletion of records available
- Dataverse - Mass record updates available
- Unusual Volume of file deletion by users available
Data Manipulation T1565 1 rule
- Dataverse - Mass record updates available
Untagged
AWS
Reconnaissance
Resource Development
Initial Access
Drive-by Compromise T1189 1 rule
- New UserAgent observed in last 24 hours available
Execution
Persistence
Account Manipulation: Additional Cloud Roles T1098.003 27 rules
- AWS Security Hub - Detect IAM Policies allowing full administrative privileges available
- AWSCloudTrail - CloudFormation policy created then used for privilege escalation available
- AWSCloudTrail - Created CRUD S3 policy and then privilege escalation available
- AWSCloudTrail - Creation of CRUD DynamoDB policy and then privilege escalation available
- AWSCloudTrail - Creation of CRUD KMS policy and then privilege escalation available
- AWSCloudTrail - Creation of CRUD Lambda policy and then privilege escalation available
- AWSCloudTrail - Creation of DataPipeline policy and then privilege escalation available
- AWSCloudTrail - Creation of EC2 policy and then privilege escalation available
- AWSCloudTrail - Creation of Glue policy and then privilege escalation available
- AWSCloudTrail - Creation of Lambda policy and then privilege escalation available
- AWSCloudTrail - Creation of new CRUD IAM policy and then privilege escalation available
- AWSCloudTrail - Creation of SSM policy and then privilege escalation available
- AWSCloudTrail - Policy version set to default available
- AWSCloudTrail - Privilege escalation via CloudFormation policy available
- AWSCloudTrail - Privilege escalation via CRUD DynamoDB policy available
- AWSCloudTrail - Privilege escalation via CRUD IAM policy available
- AWSCloudTrail - Privilege escalation via CRUD KMS policy available
- AWSCloudTrail - Privilege escalation via CRUD Lambda policy available
- AWSCloudTrail - Privilege escalation via CRUD S3 policy available
- AWSCloudTrail - Privilege escalation via DataPipeline policy available
- AWSCloudTrail - Privilege escalation via EC2 policy available
- AWSCloudTrail - Privilege escalation via Glue policy available
- AWSCloudTrail - Privilege escalation via Lambda policy available
- AWSCloudTrail - Privilege escalation via SSM policy available
- AWSCloudTrail - Privilege escalation with admin managed policy available
- AWSCloudTrail - Privilege escalation with AdministratorAccess managed policy available
- AWSCloudTrail - Privilege escalation with FullAccess managed policy available
Stealth
Valid Accounts T1078 5 rules
- AWSCloudTrail - Changes to Amazon VPC settings available
- AWSCloudTrail - Login to AWS Management Console without MFA available
- AWSCloudTrail - NRT Login to AWS Management Console without MFA available
- AWSCloudTrail - SAML update identity provider available
- Successful AWS Console Login from IP Address Observed Conducting Password Spray
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 5 rules
- AWSCloudTrail - Changes to Amazon VPC settings available
- AWSCloudTrail - Changes to AWS Elastic Load Balancer security groups available
- AWSCloudTrail - Changes to AWS Security Group ingress and egress settings available
- AWSCloudTrail - Changes to internet facing AWS RDS Database instances available
- AWSCloudTrail - Network ACL with all the open ports to a specified CIDR available
Access Token Manipulation T1134 2 rules
Defense Impairment
Domain or Tenant Policy Modification T1484 12 rules
- AWSCloudTrail - CloudFormation policy created then used for privilege escalation available
- AWSCloudTrail - Created CRUD S3 policy and then privilege escalation available
- AWSCloudTrail - Creation of CRUD DynamoDB policy and then privilege escalation available
- AWSCloudTrail - Creation of CRUD KMS policy and then privilege escalation available
- AWSCloudTrail - Creation of CRUD Lambda policy and then privilege escalation available
- AWSCloudTrail - Creation of DataPipeline policy and then privilege escalation available
- AWSCloudTrail - Creation of EC2 policy and then privilege escalation available
- AWSCloudTrail - Creation of Glue policy and then privilege escalation available
- AWSCloudTrail - Creation of Lambda policy and then privilege escalation available
- AWSCloudTrail - Creation of new CRUD IAM policy and then privilege escalation available
- AWSCloudTrail - Creation of SSM policy and then privilege escalation available
- AWSCloudTrail - Full Admin policy created and then attached to Roles, Users or Groups available
Credential Access
Discovery
Network Service Discovery T1046 2 rules
Lateral Movement
Remote Services T1021 1 rule
Collection
Command & Control
Application Layer Protocol T1071 7 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- New UserAgent observed in last 24 hours available
- TI map IP entity to AWSCloudTrail
- TI map IP entity to AWSCloudTrail
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
Exfiltration
Impact
Data Encrypted for Impact T1486 2 rules
Data Destruction T1485 1 rule
Untagged
- AWSGuardDuty - GuardDuty Alert available
Azure
Reconnaissance
Active Scanning: Scanning IP Blocks T1595.001 2 rules
- Port Scan available
- Port Sweep available
Resource Development
Initial Access
Exploit Public-Facing Application T1190 12 rules
- Abnormal Deny Rate for Source IP available
- Anomalous User Agent connection attempt
- Credential errors stateful anomaly on database available
- Exchange SSRF Autodiscover ProxyShell - Detection
- Failed sign-ins into LastPass due to MFA available
- Firewall errors stateful anomaly on database available
- High count of connections by client IP on many ports
- High severity malicious activity detected available
- OLE object manipulation attempts stateful anomaly on database available
- Silk Typhoon Suspicious Exchange Request
- Syntax errors stateful anomaly on database available
- Web Application attack detected available
Phishing T1566 8 rules
- Power Apps - Bulk sharing of Power Apps to newly created guest users available
- Star Blizzard C2 Domains August 2022
- TI map Email entity to AzureActivity
- TI map Email entity to AzureActivity
- TI map Email entity to SecurityAlert
- TI map Email entity to SecurityAlert
- TI map Email entity to SigninLogs
- TI map Email entity to SigninLogs
Trusted Relationship T1199 2 rules
No specific technique 1 rule
- Vaikora - High severity security alerts available
Execution
Cloud Administration Command T1651 6 rules
- Detect Custom Script or Run Command deployment by risky user
- Detect entra token request via specific BOF (IOC based)
- Detect first time Azure Custom Script or Run Command deployment
- Detect non-admin requesting token for admin applications
- Detect suspicious foci token logins
- Detect suspicious foci token logins V2
User Execution T1204 3 rules
Command and Scripting Interpreter T1059 2 rules
- Azure Machine Learning Write Operations available
- New CloudShell User available
Scheduled Task/Job T1053 1 rule
System Services T1569 1 rule
No specific technique 1 rule
- Vaikora - High severity security alerts available
Persistence
Account Manipulation T1098 26 rules
- Attempt to bypass conditional access rule in Microsoft Entra ID available
- Authentication Method Changed for Privileged Account
- Authentication Methods Changed for Privileged Account available
- Azure DevOps Administrator Group Monitoring available
- Azure DevOps Pull Request Policy Bypassing - Historic allow list available
- Azure DevOps Service Connection Abuse available
- Azure DevOps Service Connection Addition/Abuse - Historic allow list available
- Conditional Access - A Conditional Access user/group/role exclusion has changed
- Credential added after admin consented to Application available
- Detect changes to Connect Sync Application
- Detect PIM Alert Disabling activity
- Firewall rule manipulation attempts stateful anomaly on database available
- High risk Office operation conducted by IP Address that recently attempted to log into a disabled account
- Mail.Read Permissions Granted to Application available
- Modified domain federation trust settings available
- Multi-Factor Authentication Disabled for a User available
- NRT Authentication Methods Changed for VIP Users
- NRT Modified domain federation trust settings available
- NRT User added to Microsoft Entra ID Privileged Groups available
- Possible SignIn from Azure Backdoor
- Rare subscription-level operations in Azure available
- Sign-ins from IPs that attempt sign-ins to disabled accounts available
- Suspicious granting of permissions to an account available
- Threat Essentials - NRT User added to Microsoft Entra ID Privileged Groups available
- User added to Microsoft Entra ID Privileged Groups available
- User State changed from Guest to Member
Create Account: Cloud Account T1136.003 11 rules
- Account created from non-approved sources
- Cross-tenant Access Settings Organization Added available
- Cross-tenant Access Settings Organization Deleted available
- Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed available
- Cross-tenant Access Settings Organization Inbound Direct Settings Changed available
- Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed available
- Cross-tenant Access Settings Organization Outbound Direct Settings Changed available
- External guest invitation followed by Microsoft Entra ID PowerShell signin available
- Guest accounts added in Entra ID Groups other than the ones specified available
- User Account Created Using Incorrect Naming Format
- User account created without expected attributes defined
External Remote Services T1133 2 rules
Server Software Component T1505 2 rules
Create Account T1136 1 rule
- Rare application consent available
No specific technique 1 rule
- Vaikora - High severity security alerts available
Privilege Escalation
Stealth
Valid Accounts: Cloud Accounts T1078.004 52 rules
- Account Created and Deleted in Short Timeframe available
- Account created or deleted by non-approved user available
- Account Elevated to New Role
- Addition of a Temporary Access Pass to a Privileged Account
- Admin promotion after Role Management Application Permission Grant available
- Anomalous Single Factor Signin
- Application ID URI Changed
- Application Redirect URL Update
- Authentication Attempt from New Country
- Authentications of Privileged Accounts Outside of Expected Controls
- Bulk Changes to Privileged Account Permissions available
- Changes to Application Logout URL
- Changes to Application Ownership
- Changes to PIM Settings
- Conditional Access Policy Modified by New User
- Cross-tenant Access Settings Organization Added available
- Cross-tenant Access Settings Organization Deleted available
- Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed available
- Cross-tenant Access Settings Organization Inbound Direct Settings Changed available
- Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed available
- Cross-tenant Access Settings Organization Outbound Direct Settings Changed available
- Detect changes to Connect Sync Application
- Detect credential add to Connect Sync Application
- Detect device code login with user risk
- End-user consent stopped due to risk-based consent
- External guest invitation followed by Microsoft Entra ID PowerShell signin available
- Guest accounts added in Entra ID Groups other than the ones specified available
- Guest Users Invited to Tenant by New Inviters
- MFA Rejected by User available
- Microsoft Entra ID Role Management Permission Grant available
- New PA, PCA, or PCAS added to Azure DevOps available
- New User Assigned to Privileged Role available
- NRT PIM Elevation Request Rejected available
- NRT Privileged Role Assigned Outside PIM available
- PIM Elevation Request Rejected available
- Possible AiTM Phishing Attempt Against Microsoft Entra ID available
- Privileged Account Permissions Changed
- Privileged Accounts - Sign in Failure Spikes available
- Privileged Role Assigned Outside PIM available
- Privileged User Logon from new ASN
- Service Principal Assigned App Role With Sensitive Access
- Service Principal Assigned Privileged Role
- Service Principal Authentication Attempt from New Country
- Suspicious linking of existing user to external User
- Suspicious Login from deleted guest account
- Suspicious modification of Global Administrator user properties
- Suspicious Sign In Followed by MFA Modification available
- Threat Essentials - User Assigned Privileged Role available
- URL Added to Application from Unknown Domain
- User Accounts - Sign in Failure due to CA Spikes available
- User Added to Admin Role
- User Assigned New Privileged Role available
Valid Accounts T1078 32 rules
- Anomalous sign-in location by user account and authenticating application available
- Anomaly Sign In Event from an IP
- Attempt to bypass conditional access rule in Microsoft Entra ID available
- Attempts to sign in to disabled accounts available
- Azure Machine Learning Write Operations available
- Azure RBAC (Elevate Access)
- Conditional Access - A Conditional Access user/group/role exclusion has changed
- Correlate Unfamiliar sign-in properties & atypical travel alerts available
- Detect PIM Alert Disabling activity
- Detecting Impossible travel with mailbox permission tampering & Privilege Escalation attempt
- Elevation of Privilege attempt detected available
- F&O - Unusual sign-in activity using single factor authentication available
- Failed AWS Console logons but success logon to AzureAD
- Failed AzureAD logons but success logon to AWS Console
- Failed sign-ins into LastPass due to MFA available
- GSA - Detect Connections Outside Operational Hours available
- High risk Office operation conducted by IP Address that recently attempted to log into a disabled account
- Hunt for critical credentials on devices with non-critical accounts
- Hunt for privilege escalation paths with high ACLs
- IP with multiple failed Microsoft Entra ID logins successfully logs in to Palo Alto VPN
- Microsoft Entra ID PowerShell accessing non-Entra ID resources available
- New country signIn with correct password
- NRT User added to Microsoft Entra ID Privileged Groups available
- Power Apps - App activity from unauthorized geo available
- Power Platform - Account added to privileged Microsoft Entra roles available
- Power Platform - Possibly compromised user accesses Power Platform services available
- Sign-ins from IPs that attempt sign-ins to disabled accounts available
- Successful logon from IP and failure from a different IP available
- Suspicious Service Principal creation activity available
- Threat Essentials - NRT User added to Microsoft Entra ID Privileged Groups available
- User added to Microsoft Entra ID Privileged Groups available
- Workspace deletion activity from an infected device
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 5 rules
- Conditional Access - A Conditional Access Device platforms condition has changed (the Device platforms condition can be spoofed)
- Conditional Access - A Conditional Access policy was deleted
- Conditional Access - A Conditional Access policy was disabled
- Conditional Access - A Conditional Access policy was put into report-only mode
- Conditional Access - A new Conditional Access policy was created
Masquerading T1036 3 rules
Impair Defenses T1562 2 rules
Hide Artifacts T1564 1 rule
- Azure DevOps Retention Reduced available
No specific technique 1 rule
- Vaikora - High severity security alerts available
Defense Impairment
Modify Cloud Compute Infrastructure T1578 6 rules
- Azure DevOps Build Variable Modified by New User available
- Azure DevOps Pipeline modified by a new user available
- Creation of expensive computes in Azure available
- Microsoft Entra ID Hybrid Health AD FS New Server available
- NRT Creation of expensive computes in Azure available
- NRT Microsoft Entra ID Hybrid Health AD FS New Server available
Credential Access
Brute Force T1110 20 rules
- [Deprecated] Explicit MFA Deny available
- Brute force attack against an Entra-authenticated Windows device available
- Brute force attack against Azure Portal available
- Brute Force Attack against GitHub Account available
- Distributed Password cracking attempts in Microsoft Entra ID available
- Elevation of Privilege attempt detected available
- Failed AWS Console logons but success logon to AzureAD
- Failed AzureAD logons but success logon to AWS Console
- Failed login attempts to Azure Portal available
- GitHub Signin Burst from Multiple Locations available
- GitLab - SSO - Sign-Ins Burst available
- High count of failed attempts from same client IP
- High count of failed logons by a user
- IP with multiple failed Microsoft Entra ID logins successfully logs in to Palo Alto VPN
- MFA Spamming followed by Successful login available
- New country signIn with correct password
- Password spray attack against ADFSSignInLogs available
- Password spray attack against Microsoft Entra ID application available
- Password spray attack against Microsoft Entra ID Seamless SSO available
- Successful logon from IP and failure from a different IP available
Steal Application Access Token T1528 8 rules
- Azure DevOps PAT used with Browser available
- Expired access credentials being used in Azure available
- Microsoft Entra ID Hybrid Health AD FS Suspicious Application available
- Suspicious application consent for offline access available
- Suspicious application consent similar to O365 Attack Toolkit available
- Suspicious application consent similar to PwnAuth available
- Suspicious Entra ID Joined Device Update available
- Suspicious Service Principal creation activity available
Forge Web Credentials T1606 5 rules
OS Credential Dumping T1003 4 rules
- Azure Key Vault access TimeSeries anomaly available
- High severity malicious activity detected available
- Mass secret retrieval from Azure Key Vault available
- Rare subscription-level operations in Azure available
Adversary-in-the-Middle T1557 3 rules
Unsecured Credentials T1552 2 rules
No specific technique 1 rule
- Vaikora - High severity security alerts available
Discovery
Account Discovery: Cloud Account T1087.004 8 rules
- Cross-tenant Access Settings Organization Added available
- Cross-tenant Access Settings Organization Deleted available
- Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed available
- Cross-tenant Access Settings Organization Inbound Direct Settings Changed available
- Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed available
- Cross-tenant Access Settings Organization Outbound Direct Settings Changed available
- External guest invitation followed by Microsoft Entra ID PowerShell signin available
- Guest accounts added in Entra ID Groups other than the ones specified available
Network Service Discovery T1046 7 rules
- Abnormal Deny Rate for Source IP available
- CloudNGFW By Palo Alto Networks - possible internal to external port scanning available
- CloudNGFW By Palo Alto Networks - Threat signatures from Unusual IP addresses available
- GSA - Detect Source IP Scanning Multiple Open Ports available
- Port Scan available
- Port Sweep available
- Several deny actions registered available
No specific technique 2 rules
- Vaikora - Anomaly detection available
- Vaikora - High severity security alerts available
Lateral Movement
Use Alternate Authentication Material: Application Access Token T1550.001 4 rules
- First access credential added to Application or Service Principal where no credential was present available
- full_access_as_app Granted To Application available
- New access credential added to Application or Service Principal available
- NRT First access credential added to Application or Service Principal where no credential was present
Lateral Tool Transfer T1570 2 rules
Remote Services T1021 1 rule
Internal Spearphishing T1534 1 rule
No specific technique 2 rules
- Vaikora - Anomaly detection available
- Vaikora - High severity security alerts available
Collection
Email Collection T1114 1 rule
Automated Collection T1119 1 rule
No specific technique 2 rules
- Vaikora - Anomaly detection available
- Vaikora - High severity security alerts available
Command & Control
Application Layer Protocol T1071 35 rules
- Conditional Access - A Conditional Access app exclusion has changed
- GreyNoise TI Map IP Entity to SigninLogs
- GSA - TI Domain Entity available
- GSA - TI IP Entity available
- GSA - TI URL Entity available
- Linked Malicious Storage Artifacts available
- Lumen TI IPAddress in IdentityLogonEvents
- Lumen TI IPAddress in SigninLogs
- Multiple Sources Affected by the Same TI Destination available
- Outgoing connection attempts stateful anomaly on database available
- Palo Alto - potential beaconing detected available
- Risky user signin observed in non-Microsoft network device
- Several deny actions registered available
- SUPERNOVA webshell
- ThreatConnect TI map Email entity to SigninLogs
- TI map Domain entity to SecurityAlert
- TI map Domain entity to SecurityAlert
- TI Map IP Entity to Azure SQL Security Audit Events
- TI Map IP Entity to Azure SQL Security Audit Events
- TI Map IP Entity to AzureActivity
- TI Map IP Entity to AzureActivity
- TI map IP entity to AzureFirewall
- TI map IP entity to AzureFirewall
- TI Map IP Entity to SigninLogs
- TI Map IP Entity to SigninLogs
- TI Map IP Entity to VMConnection
- TI Map IP Entity to VMConnection
- TI Map IP Entity to W3CIISLog
- TI Map IP Entity to W3CIISLog
- TI Map URL Entity to AuditLogs
- TI Map URL Entity to AuditLogs
- TI Map URL Entity to EmailUrlInfo
- TI Map URL Entity to EmailUrlInfo
- TI Map URL Entity to SecurityAlert Data
- TI Map URL Entity to SecurityAlert Data
Non-Standard Port T1571 4 rules
Ingress Tool Transfer T1105 1 rule
Dynamic Resolution: Domain Generation Algorithms T1568.002 1 rule
- Abnormal Deny Rate for Source IP available
Protocol Tunneling T1572 1 rule
- Abnormal Port to Protocol available
No specific technique 1 rule
- Vaikora - High severity security alerts available
Exfiltration
Exfiltration Over C2 Channel T1041 4 rules
- Abnormal Deny Rate for Source IP available
- Abnormal Port to Protocol available
- High severity malicious activity detected available
- Multiple Sources Affected by the Same TI Destination available
No specific technique 2 rules
- Vaikora - Anomaly detection available
- Vaikora - High severity security alerts available
Impact
Resource Hijacking T1496 9 rules
- Azure DevOps Personal Access Token (PAT) misuse available
- Azure DevOps Service Connection Abuse available
- Azure DevOps Service Connection Addition/Abuse - Historic allow list available
- Azure Machine Learning Write Operations available
- Detect CoreBackUp Deletion Activity from related Security Alerts available
- Medium severity malicious activity detected available
- Subscription moved to another tenant
- Suspicious number of resource creation or deployment activities available
- Suspicious Resource deployment available
Data Destruction T1485 6 rules
- Affected rows stateful anomaly on database available
- Drop attempts stateful anomaly on database available
- Mass Cloud resource deletions Time Series Anomaly available
- NRT Sensitive Azure Key Vault operations available
- Sensitive Azure Key Vault operations available
- Threat Essentials - Mass Cloud resource deletions Time Series Anomaly available
Network Denial of Service T1498 3 rules
- DDoS attack detected available
- DDoS Attack IP Addresses - Percent Threshold available
- DDoS Attack IP Addresses - PPS Threshold available
Account Access Removal T1531 2 rules
Defacement T1491 1 rule
Data Manipulation T1565 1 rule
No specific technique 1 rule
- Vaikora - High severity security alerts available
Untagged
GCP
Resource Development
Initial Access
Phishing T1566 3 rules
Execution
Persistence
External Remote Services T1133 2 rules
Create Account T1136 1 rule
- GCP IAM - New Service Account available
Privilege Escalation
Stealth
Impair Defenses: Disable or Modify Tools T1562.001 6 rules
- GCP Audit Logs - Detect Bulk VM Snapshot Deletion available
- GCP Audit Logs - Detect Organization Policy Deletion or Updation available
- GCP Audit Logs - DNSSEC Disabled on Managed DNS Zone available
- GCP Audit Logs - Open Firewall Rule Created or Modified available
- GCP Audit Logs - VPC Flow Logs Disabled available
- GCP Security Command Center - Detect DNSSEC disabled for DNS zones available
Valid Accounts T1078 4 rules
Impair Defenses T1562 2 rules
Credential Access
Unsecured Credentials T1552 4 rules
Discovery
Network Service Discovery T1046 2 rules
Account Discovery T1087 1 rule
- GCP IAM - Service Account Enumeration available
Lateral Movement
Use Alternate Authentication Material T1550 3 rules
- GCP IAM - Empty user agent available
- GCP IAM - New Authentication Token for Service Account available
- GCP IAM - New Service Account Key available
Collection
Command & Control
Exfiltration
Impact
Data Destruction T1485 1 rule
Microsoft 365
Initial Access
Phishing T1566 13 rules
- Accessed files shared by temporary external user available
- Detect Direct Send phishing emails
- Detect Possible Teams BEC Attack by High Teams Recipients
- Phishing link click observed in Network Traffic
- TI map Domain entity to EmailEvents
- TI map Domain entity to EmailEvents
- TI map Domain entity to EmailUrlInfo
- TI map Domain entity to EmailUrlInfo
- TI map Email entity to EmailEvents
- TI map Email entity to EmailEvents
- TI map Email entity to OfficeActivity
- TI map Email entity to OfficeActivity
- VTI - High Severity Domain Collision Detection
Execution
Persistence
Account Manipulation T1098 6 rules
Privilege Escalation
Stealth
Valid Accounts T1078 6 rules
Impair Defenses T1562 2 rules
- Exchange AuditLog Disabled available
- Office Policy Tampering available
Credential Access
Lateral Movement
Collection
Email Collection T1114 6 rules
- Exchange workflow MailItemsAccessed operation anomaly available
- Mail redirect via ExO transport rule available
- Multiple users email forwarded to same destination available
- NRT Multiple users email forwarded to same destination
- Rare and potentially high-risk Office operations available
- Threat Essentials - Mail redirect via ExO transport rule available
Command & Control
Application Layer Protocol T1071 7 rules
- GreyNoise TI map IP entity to OfficeActivity
- Lumen TI IPAddress in OfficeActivity
- ThreatConnect TI map Email entity to OfficeActivity
- ThreatConnect TI Map URL Entity to OfficeActivity Data
- TI map IP entity to OfficeActivity
- TI map IP entity to OfficeActivity
- TI Map URL Entity to OfficeActivity Data [Deprecated]
Exfiltration
Automated Exfiltration T1020 6 rules
- Mail redirect via ExO transport rule available
- Multiple users email forwarded to same destination available
- NRT Multiple users email forwarded to same destination
- Office365 Sharepoint File transfer above threshold
- Office365 Sharepoint File transfer Folders above threshold
- Threat Essentials - Mail redirect via ExO transport rule available
Data Transfer Size Limits T1030 2 rules
Exfiltration Over Alternative Protocol T1048 2 rules
- Filewall - Blocked emails available
- Filewall - Blocked files available
Impact
Data Destruction T1485 1 rule
- Multiple Teams deleted by a single user available
Service Stop T1489 1 rule
- Multiple Teams deleted by a single user available
Untagged
Google Workspace
Initial Access
Exploit Public-Facing Application T1190 1 rule
- GWorkspace - Alert events available
Phishing T1566 1 rule
Persistence
Account Manipulation T1098 2 rules
- GWorkspace - Admin permissions granted available
- GWorkspace - User access has been changed available
External Remote Services T1133 1 rule
- GWorkspace - Alert events available
Compromise Host Software Binary T1554 1 rule
- GWorkspace - Unexpected OS update available
Stealth
Masquerading T1036 1 rule
- GWorkspace - Unexpected OS update available
Credential Access
Brute Force T1110 1 rule
- GWorkspace - Possible brute force attack available
Lateral Movement
Collection
Email Collection T1114 1 rule
Okta
Initial Access
Phishing T1566 1 rule
- Okta Fast Pass phishing Detection available
Persistence
Account Manipulation T1098 2 rules
- Device Registration from Malicious IP available
- High-Risk Admin Activity available
Stealth
Defense Impairment
Credential Access
Brute Force T1110 1 rule
Brute Force: Password Spraying T1110.003 1 rule
- Potential Password Spray Attack available
Multi-Factor Authentication Request Generation T1621 1 rule
- MFA Fatigue (OKTA) available
GitHub
Initial Access
Execution
Privilege Escalation
Stealth
Valid Accounts T1078 11 rules
- GitHub - A payment method was removed available
- GitHub - Oauth application - a client secret was removed available
- GitHub - pull request was created available
- GitHub - pull request was merged available
- GitHub - Repository was created available
- GitHub - Repository was destroyed available
- GitHub - User visibility Was changed available
- GitHub - User was added to the organization available
- GitHub - User was blocked available
- GitHub - User was invited to the repository available
- GitHub Activites from a New Country available
Impair Defenses T1562 2 rules
Credential Access
Unsecured Credentials T1552 1 rule
- Cyble Vision Alerts Github available
Lateral Movement
Collection
Data from Information Repositories T1213 1 rule
- Cyble Vision Alerts Github available
Data from Cloud Storage T1530 1 rule
- Cyble Vision Alerts Github available
Network
Reconnaissance
Active Scanning T1595 4 rules
- App Gateway WAF - Scanner Detection available
- Claroty - Threat detected available
- Palo Alto - possible nmap scan on with top 100 option available
- PaloAlto - Possible port scan available
Resource Development
Develop Capabilities: Malware T1587.001 1 rule
- Cisco SDWAN - Maleware Events available
Initial Access
Exploit Public-Facing Application T1190 92 rules
- A potentially malicious web request was executed against a web server available
- AFD WAF - Code Injection available
- AFD WAF - Path Traversal Attack available
- Apache - Apache 2.4.49 flaw CVE-2021-41773 available
- Apache - Command in URI available
- Apache - Known malicious user agent available
- Apache - Multiple client errors from single IP available
- Apache - Multiple server errors from single IP available
- Apache - Private IP in URL available
- Apache - Put suspicious file available
- Apache - Request from private IP available
- Apache - Requests to rare files available
- ApexOne - Attack Discovery Detection available
- ApexOne - Commands in Url available
- ApexOne - Multiple deny or terminate actions on single IP available
- ApexOne - Spyware with failed response available
- App Gateway WAF - Scanner Detection available
- App Gateway WAF - SQLi Detection available
- App GW WAF - Code Injection available
- App GW WAF - Path Traversal Attack available
- Application Gateway WAF - SQLi Detection
- Azure WAF matching for Log4j vuln(CVE-2021-44228) available
- Cisco SDWAN - Intrusion Events available
- Cisco SDWAN - IPS Event Threshold available
- Claroty - Login to uncommon location available
- Claroty - Multiple failed logins by user available
- Claroty - Multiple failed logins to same destinations available
- Claroty - New Asset available
- Cloudflare - Bad client IP available
- Cloudflare - Bad client IP available
- Cloudflare - Client request from country in blocklist available
- Cloudflare - Client request from country in blocklist available
- Cloudflare - Empty user agent available
- Cloudflare - Empty user agent available
- Cloudflare - Multiple error requests from single source available
- Cloudflare - Multiple error requests from single source available
- Cloudflare - Multiple user agents for single source available
- Cloudflare - Multiple user agents for single source available
- Cloudflare - Unexpected client request available
- Cloudflare - Unexpected client request available
- Cloudflare - Unexpected URI available
- Cloudflare - Unexpected URI available
- Cloudflare - WAF Allowed threat available
- Cloudflare - WAF Allowed threat available
- Cloudflare - XSS probing pattern in request available
- Cloudflare - XSS probing pattern in request available
- Fortiweb - WAF Allowed threat available
- Front Door Premium WAF - SQLi Detection available
- NGINX - Command in URI available
- NGINX - Known malicious user agent available
- NGINX - Multiple client errors from single IP address available
- NGINX - Multiple server errors from single IP address available
- NGINX - Multiple user agents for single source available
- NGINX - Private IP address in URL available
- NGINX - Put file and get file from same IP address available
- NGINX - Sql injection patterns available
- Oracle - Command in URI available
- Oracle - Malicious user agent available
- Oracle - Multiple client errors from single IP available
- Oracle - Multiple server errors from single IP available
- Oracle - Multiple user agents for single source available
- Oracle - Oracle WebLogic Exploit CVE-2021-2109 available
- Oracle - Private IP in URL available
- Oracle - Put file and get file from same IP address available
- Oracle - Put suspicious file available
- PaloAlto - Dropping or denying session with traffic available
- PaloAlto - File type changed available
- PaloAlto - Forbidden countries available
- PaloAlto - Inbound connection to high risk ports available
- PaloAlto - MAC address conflict available
- PaloAlto - Possible attack without response available
- PaloAlto - Possible flooding available
- PaloAlto - Put and post method request in high risk file type available
- PaloAlto - User privileges was changed available
- Ping Federate - OAuth old version available
- Ping Federate - SAML old version available
- Silverfort - Log4Shell Incident
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Tomcat - Commands in URI available
- Tomcat - Known malicious user agent available
- Tomcat - Multiple client errors from single IP address available
- Tomcat - Multiple empty requests from same IP available
- Tomcat - Multiple server errors from single IP address available
- Tomcat - Put file and get file from same IP address available
- Tomcat - Request from localhost IP address available
- Tomcat - Server errors after multiple requests from same IP available
- Tomcat - Sql injection patterns available
- User agent search for log4j exploitation attempt available
- Zscaler - Forbidden countries available
- Zscaler - Unexpected update operation available
- Zscaler - ZPA connections from new country available
- Zscaler - ZPA connections outside operational hours available
Phishing T1566 19 rules
- Cisco SEG - Malicious attachment not blocked available
- Cisco SEG - Multiple suspiciuos attachments received available
- Cisco SEG - Possible outbreak available
- Cisco SEG - Potential phishing link available
- Cisco SEG - Suspicious link available
- Cisco SEG - Suspicious sender domain available
- Cisco SEG - Unexpected attachment available
- Cisco SEG - Unexpected link available
- Cisco SEG - Unscannable attacment available
- Contrast Blocks available
- Contrast Exploits available
- Contrast Probes available
- Contrast Suspicious available
- Corelight - Network Service Scanning Multiple IP Addresses available
- Corelight - Possible Typo Squatting or Punycode Phishing HTTP Request available
- Corelight - SMTP Email containing NON Ascii Characters within the Subject available
- TI map Email entity to PaloAlto CommonSecurityLog
- TI map Email entity to PaloAlto CommonSecurityLog
- Votiro - File Blocked in Email
Drive-by Compromise T1189 14 rules
- A client made a web request to a potentially harmful file (ASIM Web Session schema)
- Apache - Request to sensitive files available
- App Gateway WAF - XSS Detection available
- Application Gateway WAF - XSS Detection
- Cisco Cloud Security - Request to blocklisted file type available
- Cisco SDWAN - Intrusion Events available
- Cisco SDWAN - IPS Event Threshold available
- Critical Risks available
- Front Door Premium WAF - XSS Detection available
- Malformed user agent
- NGINX - Request to sensitive files available
- Oracle - Request to sensitive files available
- Tomcat - Request to sensitive files available
- Vulerabilities available
No specific technique 2 rules
Execution
Command and Scripting Interpreter T1059 9 rules
- A host is potentially running a hacking tool (ASIM Web Session schema)
- ApexOne - Suspicious commandline arguments available
- App Gateway WAF - SQLi Detection available
- Application Gateway WAF - SQLi Detection
- Cisco Cloud Security - Hack Tool User-Agent Detected available
- Critical Risks available
- Front Door Premium WAF - SQLi Detection available
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Vulerabilities available
Exploitation for Client Execution T1203 9 rules
- AFD WAF - Code Injection available
- AFD WAF - Path Traversal Attack available
- App Gateway WAF - Scanner Detection available
- App Gateway WAF - XSS Detection available
- App GW WAF - Code Injection available
- App GW WAF - Path Traversal Attack available
- Application Gateway WAF - XSS Detection
- Front Door Premium WAF - XSS Detection available
- Malformed user agent
Scheduled Task/Job T1053 2 rules
- Critical Risks available
- Vulerabilities available
User Execution: Malicious File T1204.002 2 rules
- Critical Severity Detection available
- Microsoft COVID-19 file hash indicator matches available
User Execution T1204 1 rule
- SonicWall - Capture ATP Malicious File Detection experimental
Persistence
External Remote Services T1133 77 rules
- Apache - Apache 2.4.49 flaw CVE-2021-41773 available
- Apache - Command in URI available
- Apache - Known malicious user agent available
- Apache - Multiple client errors from single IP available
- Apache - Multiple server errors from single IP available
- Apache - Private IP in URL available
- Apache - Put suspicious file available
- Apache - Request from private IP available
- Apache - Requests to rare files available
- ApexOne - Commands in Url available
- Claroty - Login to uncommon location available
- Claroty - Multiple failed logins by user available
- Claroty - Multiple failed logins to same destinations available
- Claroty - New Asset available
- Cloudflare - Bad client IP available
- Cloudflare - Bad client IP available
- Cloudflare - Client request from country in blocklist available
- Cloudflare - Client request from country in blocklist available
- Cloudflare - Empty user agent available
- Cloudflare - Empty user agent available
- Cloudflare - Multiple error requests from single source available
- Cloudflare - Multiple error requests from single source available
- Cloudflare - Multiple user agents for single source available
- Cloudflare - Multiple user agents for single source available
- Cloudflare - Unexpected client request available
- Cloudflare - Unexpected client request available
- Cloudflare - Unexpected URI available
- Cloudflare - Unexpected URI available
- Cloudflare - WAF Allowed threat available
- Cloudflare - WAF Allowed threat available
- Cloudflare - XSS probing pattern in request available
- Cloudflare - XSS probing pattern in request available
- Fortiweb - WAF Allowed threat available
- NGINX - Command in URI available
- NGINX - Known malicious user agent available
- NGINX - Multiple client errors from single IP address available
- NGINX - Multiple server errors from single IP address available
- NGINX - Multiple user agents for single source available
- NGINX - Private IP address in URL available
- NGINX - Put file and get file from same IP address available
- Oracle - Command in URI available
- Oracle - Malicious user agent available
- Oracle - Multiple client errors from single IP available
- Oracle - Multiple server errors from single IP available
- Oracle - Multiple user agents for single source available
- Oracle - Private IP in URL available
- Oracle - Put file and get file from same IP address available
- Oracle - Put suspicious file available
- PaloAlto - Dropping or denying session with traffic available
- PaloAlto - File type changed available
- PaloAlto - Forbidden countries available
- PaloAlto - Inbound connection to high risk ports available
- PaloAlto - MAC address conflict available
- PaloAlto - Possible attack without response available
- PaloAlto - Possible flooding available
- PaloAlto - Put and post method request in high risk file type available
- PaloAlto - User privileges was changed available
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Tomcat - Commands in URI available
- Tomcat - Known malicious user agent available
- Tomcat - Multiple client errors from single IP address available
- Tomcat - Multiple empty requests from same IP available
- Tomcat - Multiple server errors from single IP address available
- Tomcat - Put file and get file from same IP address available
- Tomcat - Request from localhost IP address available
- Tomcat - Server errors after multiple requests from same IP available
- Ubiquiti - RDP from external source available
- Ubiquiti - SSH from external source available
- Ubiquiti - Unknown MAC Joined AP available
- Zscaler - Forbidden countries available
- Zscaler - Shared ZPA session available
- Zscaler - Unexpected event count of rejects by policy available
- Zscaler - Unexpected update operation available
- Zscaler - Unexpected ZPA session duration available
- Zscaler - ZPA connections from new country available
- Zscaler - ZPA connections from new IP available
- Zscaler - ZPA connections outside operational hours available
Server Software Component T1505 4 rules
- Cloudflare - Unexpected POST requests available
- Cloudflare - Unexpected POST requests available
- Corelight - Possible Webshell available
- Corelight - Possible Webshell (Rare PUT or POST) available
Account Manipulation T1098 2 rules
- Illusive Incidents Analytic Rule available
- Ping Federate - Abnormal password resets for user available
Create Account T1136 1 rule
Privilege Escalation
Abuse Elevation Control Mechanism T1548 9 rules
- AFD WAF - Code Injection available
- AFD WAF - Path Traversal Attack available
- App Gateway WAF - Scanner Detection available
- App GW WAF - Code Injection available
- App GW WAF - Path Traversal Attack available
- Critical Risks available
- Illusive Incidents Analytic Rule available
- Silverfort - NoPacBreach Incident
- Vulerabilities available
Stealth
Valid Accounts T1078 20 rules
- Acronis - Login from Abnormal IP - Low Occurrence
- ApexOne - Device access permissions was changed available
- Cisco - firewall block but success logon to Microsoft Entra ID
- Illusive Incidents Analytic Rule available
- Ping Federate - Abnormal password resets for user available
- Ping Federate - Authentication from new IP. available
- Ping Federate - Forbidden country available
- Ping Federate - New user SSO success login available
- Ping Federate - Password reset request from unexpected source IP address.. available
- Ping Federate - Unexpected authentication URL. available
- Ping Federate - Unexpected country for user available
- Ping Federate - Unusual mail domain. available
- vCenter - Root impersonation available
- VMware vCenter - Root login available
- Zscaler - Connections by dormant user available
- Zscaler - Shared ZPA session available
- Zscaler - Unexpected event count of rejects by policy available
- Zscaler - Unexpected ZPA session duration available
- Zscaler - ZPA connections by new user available
- Zscaler - ZPA connections from new IP available
Exploitation for Stealth T1211 3 rules
Impair Defenses T1562 1 rule
No specific technique 1 rule
Defense Impairment
Credential Access
OS Credential Dumping T1003 8 rules
- Europium - Hash and IP IOCs - September 2022
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Vectra Account's Behaviors available
- Vectra AI Detect - Detections with High Severity available
- Vectra AI Detect - Suspected Compromised Account available
- Vectra AI Detect - Suspected Compromised Host available
- Vectra AI Detect - Suspicious Behaviors by Category available
- Vectra Host's Behaviors available
Brute Force T1110 6 rules
- Claroty - Multiple failed logins by user available
- Excessive number of HTTP authentication failures from a source (ASIM Web Session schema)
- Ping Federate - Abnormal password reset attempts available
- Silverfort - UserBruteForce Incident
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Wazuh - Large Number of Web errors from an IP
Adversary-in-the-Middle T1557 2 rules
Forced Authentication T1187 1 rule
- Corelight - Forced External Outbound SMB available
Discovery
Account Discovery T1087 9 rules
- AFD WAF - Path Traversal Attack available
- App GW WAF - Path Traversal Attack available
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Vectra Account's Behaviors available
- Vectra AI Detect - Detections with High Severity available
- Vectra AI Detect - Suspected Compromised Account available
- Vectra AI Detect - Suspected Compromised Host available
- Vectra AI Detect - Suspicious Behaviors by Category available
- Vectra Host's Behaviors available
Network Service Discovery T1046 8 rules
- A host is potentially running a hacking tool (ASIM Web Session schema)
- App Gateway WAF - Scanner Detection available
- Cisco ASA - average attack detection rate increase available
- Cisco ASA - threat detection message fired available
- Cisco Cloud Security - Hack Tool User-Agent Detected available
- Palo Alto - possible internal to external port scanning available
- Palo Alto Threat signatures from Unusual IP addresses available
- Rare client observed with high reverse DNS lookup count available
Remote System Discovery T1018 5 rules
- Claroty - Policy violation available
- Claroty - Suspicious activity available
- Claroty - Suspicious file transfer available
- Claroty - Threat detected available
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
Network Share Discovery T1135 2 rules
- Claroty - Policy violation available
- vArmour AppController - SMB Realm Traversal available
Lateral Movement
Remote Services T1021 12 rules
- A host is potentially running a hacking tool (ASIM Web Session schema)
- ApexOne - Inbound remote access connection available
- Cisco Cloud Security - Hack Tool User-Agent Detected available
- Illusive Incidents Analytic Rule available
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Vectra Account's Behaviors available
- Vectra AI Detect - Detections with High Severity available
- Vectra AI Detect - New Campaign Detected available
- Vectra AI Detect - Suspected Compromised Account available
- Vectra AI Detect - Suspected Compromised Host available
- Vectra AI Detect - Suspicious Behaviors by Category available
- Vectra Host's Behaviors available
Lateral Tool Transfer T1570 1 rule
Collection
Automated Collection T1119 6 rules
- Vectra Account's Behaviors available
- Vectra AI Detect - Detections with High Severity available
- Vectra AI Detect - Suspected Compromised Account available
- Vectra AI Detect - Suspected Compromised Host available
- Vectra AI Detect - Suspicious Behaviors by Category available
- Vectra Host's Behaviors available
Data from Local System T1005 1 rule
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
Command & Control
Application Layer Protocol T1071 47 rules
- ApexOne - C&C callback events available
- Cisco Cloud Security - URI contains IP address available
- Cisco SDWAN - Monitor Critical IPs available
- Cloudflare - Unexpected POST requests available
- Cloudflare - Unexpected POST requests available
- Europium - Hash and IP IOCs - September 2022
- Fortinet - Beacon pattern detected
- GreyNoise TI Map IP Entity to CommonSecurityLog
- GreyNoise TI Map IP Entity to DnsEvents
- Known Forest Blizzard group domains - July 2019
- Lumen TI domain in DnsEvents
- Lumen TI IPAddress in CommonSecurityLog
- Malformed user agent
- Mercury - Domain, Hash and IP IOCs - August 2022
- Palo Alto - potential beaconing detected available
- Request for single resource on domain available
- Threat Connect TI map Domain entity to DnsEvents
- TI map Domain entity to Dns Events (ASIM DNS Schema)
- TI map Domain entity to Dns Events (ASIM DNS Schema)
- TI map Domain entity to DnsEvents
- TI map Domain entity to DnsEvents
- TI map Domain entity to PaloAlto
- TI map Domain entity to PaloAlto
- TI map Domain entity to Web Session Events (ASIM Web Session schema)
- TI map Domain entity to Web Session Events (ASIM Web Session schema)
- TI map File Hash to CommonSecurityLog Event
- TI map File Hash to CommonSecurityLog Event
- TI Map IP Entity to CommonSecurityLog
- TI Map IP Entity to CommonSecurityLog
- TI map IP entity to DNS Events (ASIM DNS schema)
- TI map IP entity to DNS Events (ASIM DNS schema)
- TI Map IP Entity to DnsEvents
- TI Map IP Entity to DnsEvents
- TI map IP entity to Web Session Events (ASIM Web Session schema)
- TI map IP entity to Web Session Events (ASIM Web Session schema)
- TI Map URL Entity to PaloAlto Data
- TI Map URL Entity to PaloAlto Data
- TI map URL entity to Web Session Events (ASIM Web Session schema)
- Ubiquiti - Connection to known malicious IP or C2 available
- Ubiquiti - Possible connection to cryptominning pool available
- Vectra Account's Behaviors available
- Vectra AI Detect - Detections with High Severity available
- Vectra AI Detect - New Campaign Detected available
- Vectra AI Detect - Suspected Compromised Account available
- Vectra AI Detect - Suspected Compromised Host available
- Vectra AI Detect - Suspicious Behaviors by Category available
- Vectra Host's Behaviors available
Application Layer Protocol: Web Protocols T1071.001 10 rules
- Beacon Traffic Based on Common User Agents Visiting Limited Number of Domains available
- Cisco Cloud Security - Connection to Unpopular Website Detected available
- Cisco Cloud Security - Crypto Miner User-Agent Detected available
- Cisco Cloud Security - Rare User Agent Detected available
- Cisco Cloud Security - Request Allowed to harmful/malicious URI category available
- Discord CDN Risky File Download available
- Discord CDN Risky File Download (ASIM Web Session Schema)
- IP address of Windows host encoded in web request
- Palo Alto Threat signatures from Unusual IP addresses available
- RunningRAT request parameters
Dynamic Resolution T1568 5 rules
Web Service T1102 4 rules
Non-Standard Port T1571 4 rules
Protocol Tunneling T1572 4 rules
- Ubiquiti - Connection to known malicious IP or C2 available
- Ubiquiti - connection to non-corporate DNS server available
- Ubiquiti - Large ICMP to external server available
- Ubiquiti - Unusual DNS connection available
Fallback Channels T1008 2 rules
Proxy T1090 2 rules
- Corelight - External Proxy Detected available
- Ubiquiti - Unusual DNS connection available
Data Encoding T1132 2 rules
Encrypted Channel T1573 2 rules
Ingress Tool Transfer T1105 1 rule
No specific technique 9 rules
- Cisco Umbrella - Connection to non-corporate private network
- Cisco Umbrella - Connection to Unpopular Website Detected
- Cisco Umbrella - Crypto Miner User-Agent Detected
- Cisco Umbrella - Empty User Agent Detected
- Cisco Umbrella - Hack Tool User-Agent Detected
- Cisco Umbrella - Rare User Agent Detected
- Cisco Umbrella - Request Allowed to harmful/malicious URI category
- Cisco Umbrella - URI contains IP address
- Cisco Umbrella - Windows PowerShell User-Agent Detected
Exfiltration
Exfiltration Over C2 Channel T1041 16 rules
- Cisco Cloud Security - Connection to non-corporate private network available
- Cisco Cloud Security - Connection to Unpopular Website Detected available
- Cisco Cloud Security - Crypto Miner User-Agent Detected available
- Cisco Cloud Security - Rare User Agent Detected available
- Cisco Cloud Security - Request Allowed to harmful/malicious URI category available
- IP address of Windows host encoded in web request
- RunningRAT request parameters
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Ubiquiti - connection to non-corporate DNS server available
- Ubiquiti - Large ICMP to external server available
- Vectra Account's Behaviors available
- Vectra AI Detect - Detections with High Severity available
- Vectra AI Detect - Suspected Compromised Account available
- Vectra AI Detect - Suspected Compromised Host available
- Vectra AI Detect - Suspicious Behaviors by Category available
- Vectra Host's Behaviors available
Data Transfer Size Limits T1030 7 rules
- Cisco SEG - DLP policy violation available
- Cisco SEG - Multiple large emails sent to external recipient available
- Corelight - Multiple files sent over HTTP with abnormal requests available
- Palo Alto Threat signatures from Unusual IP addresses available
- Threat Essentials - Time series anomaly for data size transferred to public internet available
- Time series anomaly detection for total volume of traffic
- Time series anomaly for data size transferred to public internet
Exfiltration Over Alternative Protocol T1048 5 rules
- Apache - Put suspicious file available
- DNS events related to ToR proxies available
- Oracle - Put suspicious file available
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
- Ubiquiti - Unusual FTP connection to external server available
Automated Exfiltration T1020 3 rules
Exfiltration Over Other Network Medium T1011 1 rule
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
No specific technique 1 rule
Impact
Network Denial of Service T1498 20 rules
- Apache - Multiple server errors from single IP available
- Apache - Request from private IP available
- Cisco ASA - average attack detection rate increase available
- Cisco ASA - threat detection message fired available
- Infoblox - Data Exfiltration Attack available
- Infoblox - High Threat Level Query Not Blocked Detected available
- Infoblox - Many High Threat Level Queries From Single Host Detected available
- Infoblox - Many High Threat Level Single Query Detected available
- Infoblox - Many NXDOMAIN DNS Responses Detected available
- Infoblox - SOC Insight Detected - CDC Source available
- Infoblox - TI - CommonSecurityLog Match Found - MalwareC2 available
- Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains available
- NGINX - Multiple server errors from single IP address available
- Oracle - Multiple server errors from single IP available
- Tomcat - Multiple server errors from single IP address available
- Tomcat - Server errors after multiple requests from same IP available
- VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
- VMware SD-WAN Edge - Network Anomaly Detection - Potential Fragmentation Attack
- VMware SD-WAN Edge - Network Anomaly Detection - RPF Check Failure
- Votiro - File Blocked from Connector
Endpoint Denial of Service T1499 9 rules
- Critical Severity Detection available
- NGINX - Core Dump available
- Tomcat - Multiple empty requests from same IP available
- Vectra Account's Behaviors available
- Vectra AI Detect - Detections with High Severity available
- Vectra AI Detect - Suspected Compromised Account available
- Vectra AI Detect - Suspected Compromised Host available
- Vectra AI Detect - Suspicious Behaviors by Category available
- Vectra Host's Behaviors available
Data Manipulation T1565 9 rules
- Infoblox - Data Exfiltration Attack available
- Infoblox - High Threat Level Query Not Blocked Detected available
- Infoblox - Many High Threat Level Queries From Single Host Detected available
- Infoblox - Many High Threat Level Single Query Detected available
- Infoblox - Many NXDOMAIN DNS Responses Detected available
- Infoblox - SOC Insight Detected - CDC Source available
- Infoblox - TI - CommonSecurityLog Match Found - MalwareC2 available
- Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains available
- Votiro - File Blocked from Connector
Resource Hijacking T1496 4 rules
Data Encrypted for Impact T1486 2 rules
System Shutdown/Reboot T1529 2 rules
- Claroty - Asset Down available
- Claroty - Critical baseline deviation available
Service Stop T1489 1 rule
Inhibit System Recovery T1490 1 rule
- SonicWall - Allowed SSH, Telnet, and RDP Connections experimental
Untagged
- Awake Security - High Match Counts By Device available
- Awake Security - High Severity Matches By Device available
- Awake Security - Model With Multiple Destinations available
- Create Incidents from IronDefense available
- Dragos Notifications available
- VMware Cloud Web Security - Data Loss Prevention Violation
- VMware Cloud Web Security - Policy Change Detected
- VMware Cloud Web Security - Policy Publish Event
- VMware Cloud Web Security - Web Access Policy Violation
- VMware Edge Cloud Orchestrator - New LAN-Side Client Device Detected
- VMware SD-WAN - Orchestrator Audit Event
- VMware SD-WAN Edge - All Cloud Security Service Tunnels DOWN
- VMware SD-WAN Edge - IDS/IPS Signature Update Failed
- VMware SD-WAN Edge - IDS/IPS Signature Update Succeeded
SaaS
Initial Access
Drive-by Compromise T1189 3 rules
- Box - Executable file in folder available
- Box - Forbidden file type downloaded available
- SlackAudit - Suspicious file downloaded. available
Persistence
External Remote Services T1133 1 rule
- SlackAudit - Empty User Agent available
Stealth
Valid Accounts T1078 20 rules
- Bitglass - Impossible travel distance available
- Bitglass - Login from new device available
- Bitglass - New admin user available
- Bitglass - New risky user available
- Bitglass - User Agent string has changed for user available
- Bitglass - User login from new geo location available
- Box - Inactive user login available
- Box - New external user available
- Box - User logged in as admin available
- Box - User role changed to owner available
- Jira - Global permission added available
- Jira - New site admin user available
- Jira - New site admin user available
- Jira - New user created available
- Jira - User's password changed multiple times available
- SlackAudit - User email linked to account changed. available
- SlackAudit - User role changed to admin or owner available
- Snowflake - Multiple login failures by user available
- Snowflake - Multiple login failures from single IP available
- Snowflake - User granted admin privileges available
Credential Access
Brute Force T1110 2 rules
- Bitglass - Multiple failed logins available
- SlackAudit - Multiple failed logins for user available
Discovery
System Information Discovery T1082 1 rule
- Snowflake - Multiple failed queries available
Software Discovery T1518 1 rule
- Snowflake - Multiple failed queries available
Cloud Service Discovery T1526 1 rule
- Snowflake - Possible discovery activity available
Collection
Automated Collection T1119 2 rules
- Snowflake - Query on sensitive or restricted table available
- Snowflake - Unusual query available
Data from Information Repositories T1213 1 rule
- Jira - Workflow scheme copied available
Data from Cloud Storage T1530 1 rule
- Box - Abmormal user activity available
Command & Control
Exfiltration
Transfer Data to Cloud Account T1537 1 rule
- Box - Item shared to external entity available
Impact
Account Access Removal T1531 4 rules
- Jira - Permission scheme updated available
- Jira - Project roles changed available
- Jira - User removed from group available
- Jira - User removed from project available
Data Destruction T1485 2 rules
- Box - Many items deleted by user available
- Snowflake - Possible data destraction available
Endpoint Denial of Service T1499 1 rule
- Snowflake - Abnormal query process time available
Identity
Persistence
Account Manipulation T1098 4 rules
- Empty group with entitlements available
- IaaS policy not attached to any identity available
- Lateral Movement Risk - Role Chain Length available
- Stale IAAS policy attachment to role available
Privilege Escalation
Exploitation for Privilege Escalation T1068 1 rule
- Unused IaaS Policy available
Stealth
Valid Accounts T1078 22 rules
- Access to AWS without MFA available
- Admin password not updated in 30 days available
- Admin SaaS account detected available
- AWS role with admin privileges available
- AWS role with shadow admin privileges available
- Cisco Duo - Admin password reset available
- Cisco Duo - Admin user created available
- Cisco Duo - Authentication device new location available
- Cisco Duo - Multiple admin 2FA failures available
- Cisco Duo - Multiple user login failures available
- Cisco Duo - New access device available
- Cisco Duo - Unexpected authentication factor available
- Detect AWS IAM Users available
- IaaS admin detected available
- IaaS shadow admin detected available
- New direct access policy was granted against organizational policy available
- New service account gained access to IaaS resource available
- Refactor AWS policy based on activities in the last 60 days available
- Stale AWS policy attachment to identity available
- Unused IaaS Policy available
- User assigned to a default admin role available
- User without MFA available
Credential Access
Network Sniffing T1040 1 rule
Unsecured Credentials T1552 1 rule
Discovery
Command & Control
Impact
Account Access Removal T1531 2 rules
- Cisco Duo - Admin user deleted available
- Cisco Duo - Multiple users deleted available
Service Stop T1489 1 rule
- Cisco Duo - AD sync failed available
Application
Reconnaissance
Active Scanning T1595 34 rules
- API - Kiterunner detection available
- blacklens Insights available
- BTP - Failed access attempts across multiple BAS subaccounts available
- Cyble Advisory Alerts Advisory available
- Cyble Vision Alerts Cyble Web Applications available
- Cyble Vision Alerts Discovered Subdomain available
- Cyble Vision Alerts Hacktivism available
- Cyble Vision Alerts IOC'S available
- Cyble Vision Alerts IP Risk Score available
- Cyble Vision Alerts Postman API Exposure Detection available
- Cyble Vision Alerts Social Media Monitoring available
- Cyble Vision Alerts Suspicious Domain available
- Cyble Vision Alerts TOR Links available
- Cyble Vision Alerts Vulnerability available
- CybleVision Alerts Mobile Apps available
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation Medium Rule available
- CYFIRMA - Attack Surface - Weak Certificate Exposure - High Rule available
- CYFIRMA - Attack Surface - Weak Certificate Exposure - Medium Rule available
- Disks Alerts From Prancer available
- Flow Logs Alerts for Prancer available
- NetworkSecurityGroups Alert From Prancer available
- OCI - Multiple rejects on rare ports available
- OCI - SSH scanner available
- PAC high severity available
- Registries Alerts for Prancer available
- Sites Alerts for Prancer available
- Storage Accounts Alerts From Prancer available
- Subnets Alerts for Prancer available
- Vaults Alerts for Prancer available
- Virtual Machines Alerts for Prancer available
- VirtualNetworkPeerings Alerts From Prancer available
- XbowNewAssetDiscovered available
Gather Victim Identity Information T1589 15 rules
- API - Anomaly Detection available
- Cyble Vision Alerts Darkweb Data Breaches available
- Cyble Vision Alerts Flash Report available
- Cyble Vision Alerts OSINT Mention Detected available
- Cyble Vision Alerts Social Media Monitoring available
- CybleVision Alerts Cyber Crime Forum Alerts available
- CybleVision Alerts Darkweb Marketplace Alerts available
- CybleVision Alerts Stealer Logs available
- SOCRadar High or Critical Severity Alarm available
- TacitRed - High Confidence Compromise
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Search Open Websites/Domains T1593 13 rules
- API - Anomaly Detection available
- API - API Scraping available
- CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule available
- CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule available
- CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule available
- CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule available
- Flare chat results available
- Flare cloud bucket results available
- Flare google dork results available
- Flare lookalike domain results available
- Flare marketplace results available
- Flare paste results available
- Flare source code results available
Gather Victim Host Information T1592 11 rules
- API - Invalid host access available
- CyberBlindSpot - Any Issue Detected available
- Cyble Vision Alerts Assets available
- Cyble Vision Alerts Cyble Web Applications available
- Cyble Vision Alerts OSINT Mention Detected available
- HackerView - Any Issue Detected available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Active Scanning: Vulnerability Scanning T1595.002 10 rules
- BitSight - diligence risk category detected available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation High Rule available
- CYFIRMA - High severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - High severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Monitor Recommended Rule
Phishing for Information T1598 9 rules
- CyberBlindSpot - Any Issue Detected available
- Cyble Vision Alerts Discord Keyword available
- Cyble Vision Alerts Flash Report available
- Cyble Vision Alerts News Feed Alert available
- Cyble Vision Alerts Website Defacement Keyword available
- CybleVision Alerts Cyber Crime Forum Alerts available
- CybleVision Alerts Telegram Mentions available
- HackerView - Any Issue Detected available
- Suspicious link sharing pattern
Gather Victim Identity Information: Employee Names T1589.003 4 rules
- CYFIRMA - Brand Intelligence - Executive/People Impersonation High Rule available
- CYFIRMA - Brand Intelligence - Executive/People Impersonation Medium Rule available
- CYFIRMA - Brand Intelligence - Social Media Handle Impersonation Detected High Rule available
- CYFIRMA - Brand Intelligence - Social Media Handle Impersonation Detected Medium Rule available
Gather Victim Org Information T1591 3 rules
- BitSight - drop in company ratings available
- BitSight - drop in the headline rating available
- Cyble Vision Alerts Pastebin available
Gather Victim Network Information T1590 2 rules
- Contrast ADR - DLP SQL Injection Correlation available
- Cyble Vision Alerts TOR Links available
Search Open Technical Databases T1596 2 rules
- Cyble Advisory Alerts Advisory available
- Flare host results available
No specific technique 1 rule
- XbowMediumFindings available
Resource Development
Acquire Infrastructure T1583 6 rules
- blacklens Insights available
- Cyble Vision Alerts TOR Links available
- ZeroFox Alerts - High Severity Alerts available
- ZeroFox Alerts - Informational Severity Alerts available
- ZeroFox Alerts - Low Severity Alerts available
- ZeroFox Alerts - Medium Severity Alerts available
Acquire Infrastructure: Domains T1583.001 6 rules
- CYFIRMA - Brand Intelligence - Domain Impersonation High Rule available
- CYFIRMA - Brand Intelligence - Domain Impersonation Medium Rule available
- CYFIRMA - Brand Intelligence - Malicious Mobile App High Rule available
- CYFIRMA - Brand Intelligence - Malicious Mobile App Medium Rule available
- CYFIRMA - Brand Intelligence - Product/Solution High Rule available
- CYFIRMA - Brand Intelligence - Product/Solution Medium Rule available
Establish Accounts: Social Media Accounts T1585.001 6 rules
- CYFIRMA - Brand Intelligence - Executive/People Impersonation High Rule available
- CYFIRMA - Brand Intelligence - Executive/People Impersonation Medium Rule available
- CYFIRMA - Brand Intelligence - Social Media Handle Impersonation Detected High Rule available
- CYFIRMA - Brand Intelligence - Social Media Handle Impersonation Detected Medium Rule available
- CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule available
- CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule available
Establish Accounts T1585 5 rules
- Cyble Vision Alerts Hacktivism available
- Cyble Vision Alerts I2P Monitoring available
- Cyble Vision Alerts Social Media Monitoring available
- CybleVision Alerts Cyber Crime Forum Alerts available
- CybleVision Alerts Telegram Mentions available
Compromise Accounts T1586 4 rules
- ZeroFox Alerts - High Severity Alerts available
- ZeroFox Alerts - Informational Severity Alerts available
- ZeroFox Alerts - Low Severity Alerts available
- ZeroFox Alerts - Medium Severity Alerts available
Obtain Capabilities T1588 3 rules
Compromise Infrastructure T1584 2 rules
- BTP - Malware detected in BAS dev space available
- Cyble Vision Alerts Domain Watchlist available
Develop Capabilities T1587 1 rule
- Cyble Advisory Alerts Advisory available
Stage Capabilities T1608 1 rule
- CybleVision Alerts Mobile Apps available
Initial Access
Exploit Public-Facing Application T1190 62 rules
- API - JWT validation available
- API - Rate limiting available
- API - Suspicious Login available
- ARGOS Cloud Security - Exploitable Cloud Resources available
- BitSight - new alert found available
- BitSight - new breach found available
- blacklens Insights available
- Contrast ADR - DLP SQL Injection Correlation available
- Contrast ADR - EDR Alert Correlation available
- Contrast ADR - Exploited Attack Event available
- Contrast ADR - Exploited Attack in Production available
- Contrast ADR - Security Incident Alert available
- Contrast ADR - WAF Alert Correlation available
- Cyble Vision Alerts New Vulnerability Detected available
- Cyble Vision Alerts Product Vulnerability Detected available
- Cyble Vision Alerts SSL Certificate Expiry available
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- CYFIRMA - Attack Surface - Weak Certificate Exposure - High Rule available
- CYFIRMA - Attack Surface - Weak Certificate Exposure - Medium Rule available
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- Detect instances of multiple client errors occurring within a brief period of time (ASIM Web Session) available
- Detect instances of multiple server errors occurring within a brief period of time (ASIM Web Session) available
- Detect known risky user agents (ASIM Web Session) available
- Detect Local File Inclusion(LFI) in web requests (ASIM Web Session) available
- Detect presence of uncommon user agents in web requests (ASIM Web Session) available
- Detect threat information in web requests (ASIM Web Session) available
- Detect URLs containing known malicious keywords or commands (ASIM Web Session) available
- Dynatrace Application Security - Attack detection available
- Exchange Server Suspicious File Downloads.
- High Number of Urgent Vulnerabilities Detected available
- High Urgency IONIX Action Items available
- Hunt for public facing devices and exposed ports over time
- Hunt for public facing devices via public tag
- Hunt for public remotly exploitable devices (with high EPSS)
- Identify instances where a single source is observed using multiple user agents (ASIM Web Session) available
- Imperva - Abnormal protocol usage available
- Imperva - Critical severity event not blocked available
- Imperva - Forbidden HTTP request method in request available
- Imperva - Malicious Client available
- Imperva - Malicious user agent available
- Imperva - Multiple user agents from same source available
- Imperva - Possible command injection available
- Imperva - Request from unexpected countries available
- Imperva - Request from unexpected IP address to admin panel available
- Imperva - Request to unexpected destination port available
- New High Severity Vulnerability Detected Across Multiple Hosts available
- OCI - Inbound SSH connection available
- OCI - Unexpected user agent available
- OMI Vulnerability Exploitation
- Pathlock TDnR - J2EE Security Events available
- Pathlock TDnR - SAP HTTP Webserver Events available
- Pathlock TDnR - SAP Web Dispatcher HTTP Events available
- PulseConnectSecure - CVE-2021-22893 Possible Pulse Connect Secure RCE Vulnerability Attack
- Silk Typhoon Suspicious File Downloads.
- Silk Typhoon Suspicious UM Service Error
- Vulnerable Machines related to log4j CVE-2021-44228 available
- Vulnerable Machines related to OMIGOD CVE-2021-38647
- XbowCriticalHighFindings available
Phishing T1566 42 rules
- CyberBlindSpot - Any Issue Detected available
- Cyble Vision Alerts Malicious Ads Detected available
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation Medium Rule available
- CYFIRMA - Attack Surface - Open Ports High Rule available
- CYFIRMA - Attack Surface - Open Ports Medium Rule available
- CYFIRMA - Brand Intelligence - Product/Solution High Rule available
- CYFIRMA - Brand Intelligence - Product/Solution Medium Rule available
- CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule available
- CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule available
- Cyren High-Risk URL Indicators available
- Detect web requests to potentially harmful files (ASIM Web Session) available
- Egress Defend - Dangerous Attachment Detected available
- Google Threat Intelligence - Threat Hunting Url
- KnowBe4 Defend - Dangerous Attachment Detected available
- Mimecast Secure Email Gateway - Attachment Protect available
- Mimecast Secure Email Gateway - Attachment Protect
- Mimecast Secure Email Gateway - URL Protect available
- Mimecast Secure Email Gateway - URL Protect
- New Sonrai Ticket available
- ProofpointPOD - High risk message not discarded available
- ProofpointPOD - Suspicious attachment available
- Red Canary Threat Detection
- Red Sift - Email with URL to previously unseen domain available
- Red Sift - New email with URL from previously unseen sender available
- Red Sift - New email with URL from previously unseen source available
- Samsung Knox - Suspicious URL Accessed Events available
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
- Stale last password change available
- Valimail Enforce - DMARC Policy Weakened to None available
- ZeroFox Alerts - High Severity Alerts available
- ZeroFox Alerts - Informational Severity Alerts available
- ZeroFox Alerts - Low Severity Alerts available
- ZeroFox Alerts - Medium Severity Alerts available
Phishing: Spearphishing Link T1566.002 28 rules
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation High Rule available
- CYFIRMA - Brand Intelligence - Domain Impersonation High Rule available
- CYFIRMA - Brand Intelligence - Domain Impersonation Medium Rule available
- CYFIRMA - Brand Intelligence - Executive/People Impersonation High Rule available
- CYFIRMA - Brand Intelligence - Executive/People Impersonation Medium Rule available
- CYFIRMA - Brand Intelligence - Social Media Handle Impersonation Detected High Rule available
- CYFIRMA - Brand Intelligence - Social Media Handle Impersonation Detected Medium Rule available
- CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule available
- CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule available
- CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule available
- CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule available
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - High severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- Malware Link Clicked available
Phishing: Spearphishing Attachment T1566.001 23 rules
- CYFIRMA - Brand Intelligence - Domain Impersonation High Rule available
- CYFIRMA - Brand Intelligence - Domain Impersonation Medium Rule available
- CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule available
- CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule available
- CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule available
- CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule available
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity File Hash Indicators with Block Action Rule
- CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - High severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Monitor Action Rule
- Malware attachment delivered available
Drive-by Compromise T1189 22 rules
- Cyble Vision Alerts Malicious Ads Detected available
- CybleVision Alerts Stealer Logs available
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - High severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Monitor Recommended Rule
- CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule available
- CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule available
- Cyren High-Risk URL Indicators available
- Web sites blocked by Eset available
Phishing: Spearphishing via Service T1566.003 4 rules
- CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule available
- CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule available
- CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule available
- CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule available
Content Injection T1659 4 rules
- Dynatrace - Problem detection available
- Dynatrace Application Security - Code-Level runtime vulnerability detection available
- Dynatrace Application Security - Non-critical runtime vulnerability detection available
- Dynatrace Application Security - Third-Party runtime vulnerability detection available
Supply Chain Compromise T1195 3 rules
- BTP - Cloud Integration package import or transport available
- CybleVision Alerts Mobile Apps available
- High Urgency IONIX Action Items available
Trusted Relationship T1199 2 rules
No specific technique 1 rule
- Radiflow - Platform Alert available
Execution
Command and Scripting Interpreter T1059 41 rules
- BTP - Cloud Integration artifact deployment available
- Contrast ADR - EDR Alert Correlation available
- Contrast ADR - Exploited Attack Event available
- Contrast ADR - Exploited Attack in Production available
- Critical Severity Incident available
- Cyble Vision Alerts Malicious Ads Detected available
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- Detect Local File Inclusion(LFI) in web requests (ASIM Web Session) available
- Device Alert Surge available
- Dynatrace - Problem detection available
- Dynatrace Application Security - Attack detection available
- Dynatrace Application Security - Code-Level runtime vulnerability detection available
- Dynatrace Application Security - Non-critical runtime vulnerability detection available
- Dynatrace Application Security - Third-Party runtime vulnerability detection available
- Field Effect MDR Alert: ARO Alert available
- New Sonrai Ticket available
- Pathlock TDnR - Function Module Tested in Production available
- Pathlock TDnR - Logical OS Command Changes available
- Pathlock TDnR - SAP Batch Job Events available
- Pathlock TDnR - TMS Transport and Import Events available
- Process-Level Anomaly available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
- Vaikora - Behavioral anomaly detected available
- Vaikora - High severity AI agent action detected available
User Execution T1204 30 rules
- Critical Severity Incident available
- CyberArkEPM - Attack attempt not blocked
- CyberArkEPM - Multiple attack types
- CyberArkEPM - Possible execution of Powershell Empire
- CyberArkEPM - Process started from different locations
- CyberArkEPM - Renamed Windows binary
- CyberArkEPM - Uncommon process Internet access
- CyberArkEPM - Uncommon Windows process started from System folder
- CyberArkEPM - Unexpected executable extension
- CyberArkEPM - Unexpected executable location
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity File Hash Indicators with Block Action Rule
- CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - High severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Monitor Action Rule
- Device Alert Surge available
- Egress Defend - Dangerous Attachment Detected available
- Egress Defend - Dangerous Link Click available
- KnowBe4 Defend - Dangerous Attachment Detected available
- KnowBe4 Defend - Dangerous Link Click available
- Netskope - WebTransaction Error Detection available
- Process-Level Anomaly available
- Threats detected by Eset available
User Execution: Malicious Link T1204.001 16 rules
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - High severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Monitor Recommended Rule
Exploitation for Client Execution T1203 12 rules
- BitSight - compromised systems detected available
- BitSight - diligence risk category detected available
- Cyble Vision Alerts Vulnerability available
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- Detect web requests to potentially harmful files (ASIM Web Session) available
- Vulnerable Machines related to log4j CVE-2021-44228 available
- Vulnerable Machines related to OMIGOD CVE-2021-38647
Scheduled Task/Job T1053 6 rules
Scheduled Task/Job: Scheduled Task T1053.005 6 rules
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Monitor Recommended Rule
Software Deployment Tools T1072 1 rule
- BTP - Malware detected in BAS dev space available
Deploy Container T1610 1 rule
- Cyble Vision Alerts Docker available
No specific technique 1 rule
- Radiflow - Platform Alert available
Persistence
External Remote Services T1133 38 rules
- Cyble Vision Alerts IOC'S available
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- Detect instances of multiple client errors occurring within a brief period of time (ASIM Web Session) available
- Detect instances of multiple server errors occurring within a brief period of time (ASIM Web Session) available
- Detect known risky user agents (ASIM Web Session) available
- Detect Local File Inclusion(LFI) in web requests (ASIM Web Session) available
- Detect presence of uncommon user agents in web requests (ASIM Web Session) available
- Detect threat information in web requests (ASIM Web Session) available
- Detect URLs containing known malicious keywords or commands (ASIM Web Session) available
- Detect web requests to potentially harmful files (ASIM Web Session) available
- Identify instances where a single source is observed using multiple user agents (ASIM Web Session) available
- Imperva - Abnormal protocol usage available
- Imperva - Critical severity event not blocked available
- Imperva - Forbidden HTTP request method in request available
- Imperva - Malicious Client available
- Imperva - Malicious user agent available
- Imperva - Multiple user agents from same source available
- Imperva - Possible command injection available
- Imperva - Request from unexpected countries available
- Imperva - Request from unexpected IP address to admin panel available
- Imperva - Request to unexpected destination port available
- Jamf Protect - Network Threats available
- Palo Alto Prisma Cloud - High risk score alert available
- Palo Alto Prisma Cloud - High severity alert opened for several days available
- Palo Alto Prisma Cloud - Maximum risk score alert available
- Palo Alto Prisma Cloud - Network ACL allow all outbound traffic available
- Palo Alto Prisma Cloud - Network ACL allow ingress traffic to server administration ports available
- Palo Alto Prisma Cloud - Network ACLs Inbound rule to allow All Traffic available
- Radiflow - New Activity Detected available
- SailPointIdentityNowAlertForTriggers available
- SailPointIdentityNowEventType available
- SailPointIdentityNowEventTypeTechnicalName available
- SailPointIdentityNowFailedEvents available
- SailPointIdentityNowFailedEventsBasedOnTime available
- SailPointIdentityNowUserWithFailedEvent available
Account Manipulation T1098 23 rules
- Copilot - Plugin Created by Non-Admin User available
- CYFIRMA - Compromised Employees Detection Rule available
- External User Access Enabled
- F&O - Non-interactive account mapped to self or sensitive privileged user available
- Pathlock TDnR - Authorization Profile Changes available
- Pathlock TDnR - Authorization Role Changes available
- Pathlock TDnR - CUA Settings Changes available
- Pathlock TDnR - Global System Change Setting Events available
- Pathlock TDnR - Kerberos Keytab Changes available
- Pathlock TDnR - RFC Connection Changes available
- Pathlock TDnR - SAP Authorization Changes available
- Pathlock TDnR - SAP Client Configuration Changes available
- Pathlock TDnR - SAP Instance Profile Changes available
- Pathlock TDnR - System Security Policy Changes available
- Pathlock TDnR - User Access Management Password Resets available
- Pathlock TDnR - User Master Data Changes available
- Pathlock TDnR - User-Profile Assignment Changes available
- Pathlock TDnR - User-Role Assignment Changes available
- RecordedFuture Threat Hunting Url All Actors
- Semperis DSP Recent sIDHistory changes on AD objects available
- Server Oriented Cmdlet And User Oriented Cmdlet used available
- StealthTalk - Multi new devices registration available
- VIP Mailbox manipulation available
Boot or Logon Autostart Execution T1547 10 rules
- New Sonrai Ticket available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
Server Software Component T1505 9 rules
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- CYFIRMA - Attack Surface - Domain/IP Vulnerability Exposure High Rule available
- CYFIRMA - Attack Surface - Domain/IP Vulnerability Exposure Medium Rule available
- CYFIRMA - Attack Surface - Open Ports High Rule available
- CYFIRMA - Attack Surface - Open Ports Medium Rule available
- Detect potential presence of a malicious file with a double extension (ASIM Web Session) available
- Pathlock TDnR - ABAP Source Code Changes available
- Pathlock TDnR - ICF Web Service Changes available
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1547.001 6 rules
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Monitor Action Rule
Create Account T1136 4 rules
Server Software Component: Web Shell T1505.003 4 rules
- CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Monitor Recommended Rule
Compromise Host Software Binary T1554 4 rules
- Dynatrace - Problem detection available
- Dynatrace Application Security - Code-Level runtime vulnerability detection available
- Dynatrace Application Security - Non-critical runtime vulnerability detection available
- Dynatrace Application Security - Third-Party runtime vulnerability detection available
No specific technique 2 rules
Privilege Escalation
Abuse Elevation Control Mechanism T1548 34 rules
- BTP - Cloud Integration access policy tampering available
- Dynatrace - Problem detection available
- Dynatrace Application Security - Code-Level runtime vulnerability detection available
- Dynatrace Application Security - Non-critical runtime vulnerability detection available
- Dynatrace Application Security - Third-Party runtime vulnerability detection available
- New Sonrai Ticket available
- Pathlock TDnR - Authorization Check Value Changes (SU24) available
- Pathlock TDnR - Authorization Profile Changes available
- Pathlock TDnR - Authorization Role Changes available
- Pathlock TDnR - Database Cockpit Audit Events available
- Pathlock TDnR - Dynamic Access Control Events available
- Pathlock TDnR - Emergency User (AdminTrack) Activity available
- Pathlock TDnR - GRC Access Control Change Documents available
- Pathlock TDnR - SAP Authorization Changes available
- Pathlock TDnR - SU24 Table USOBT_C Changes available
- Pathlock TDnR - SU24 Table USOBX_C Changes available
- Pathlock TDnR - Switchable Authorization Design Changes available
- Pathlock TDnR - Switchable Authorization Runtime Changes available
- Pathlock TDnR - User Authorization Buffer Manipulation available
- Pathlock TDnR - User Master Data Changes available
- Pathlock TDnR - User-Profile Assignment Changes available
- Pathlock TDnR - User-Role Assignment Changes available
- Red Canary Threat Detection
- Samsung Knox - Application Privilege Escalation or Change Events available
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
- Threats detected by Eset available
- Vaikora - High severity AI agent action detected available
Event Triggered Execution T1546 17 rules
- BTP - Cloud Integration artifact deployment available
- BTP - Cloud Integration package import or transport available
- Copilot - Plugin Created by Non-Admin User available
- Dataminr - urgent alerts detected available
- Egress Defend - Dangerous Attachment Detected available
- Generate alerts based on ExtraHop detections recommended for triage available
- KnowBe4 Defend - Dangerous Attachment Detected available
- Mimecast Secure Email Gateway - Internal Email Protect available
- Mimecast Secure Email Gateway - Internal Email Protect
- Rubrik Critical Anomaly available
- Rubrik Threat Monitoring available
- Vectra Create Detection Alert for Accounts available
- Vectra Create Detection Alert for Hosts available
- Vectra Create Incident Based on Priority for Accounts available
- Vectra Create Incident Based on Priority for Hosts available
- Vectra Create Incident Based on Tag for Accounts available
- Vectra Create Incident Based on Tag for Hosts available
Exploitation for Privilege Escalation T1068 8 rules
- CYFIRMA - Attack Surface - Domain/IP Vulnerability Exposure High Rule available
- CYFIRMA - Attack Surface - Domain/IP Vulnerability Exposure Medium Rule available
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- Dynatrace Application Security - Attack detection available
- Semperis DSP Zerologon vulnerability available
No specific technique 3 rules
- Radiflow - Platform Alert available
- SAP LogServ - HANA DB - Assign Admin Authorizations available
- SAP LogServ - HANA DB - User Admin actions available
Stealth
Valid Accounts T1078 46 rules
- BTP - Build Work Zone unauthorized access and role tampering available
- BTP - User added to Cloud Identity Service privileged Administrators list available
- BTP - User added to sensitive privileged role collection available
- Copilot - Jailbreak Attempt Detected available
- Cyble Vision Alerts Darkweb Data Breaches available
- CYFIRMA - Compromised Employees Detection Rule available
- CYFIRMA - Customer Accounts Leaks Detection Rule available
- CYFIRMA - Public Accounts Leaks Detection Rule available
- CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule available
- CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule available
- F&O - Bank account change following network alias reassignment available
- F&O - Non-interactive account mapped to self or sensitive privileged user available
- Netskope - Impossible Travel Detection (Two Countries in Less Than 1 Hour) available
- Non-admin guest available
- Palo Alto Prisma Cloud - Access keys are not rotated for 90 days available
- Palo Alto Prisma Cloud - Anomalous access key usage available
- Palo Alto Prisma Cloud - IAM Group with Administrator Access Permissions available
- Palo Alto Prisma Cloud - Inactive user available
- Pathlock TDnR - Emergency User (AdminTrack) Activity available
- Pathlock TDnR - Multiple Login Sessions Detected available
- Pathlock TDnR - SAP Cloud Account Administration Events available
- Pathlock TDnR - SAP HANA Database Audit Trail available
- Pathlock TDnR - User Access Management Password Resets available
- ProofpointPOD - Binary file in attachment available
- ProofpointPOD - Email sender in TI list
- ProofpointPOD - Email sender IP in TI list
- ProofpointPOD - Possible data exfiltration to private email available
- RecordedFuture Threat Hunting Url All Actors
- Red Sift - Login from previously unseen IP address available
- Service principal not using client credentials available
- SOCRadar High or Critical Severity Alarm available
- StealthTalk - After hours work available
- StealthTalk - Login outside work zone available
- StealthTalk - Multi new devices registration available
- Successful logins to SOC Prime platform from bad IP addresses available
- TacitRed - High Confidence Compromise
- TacitRed - Repeat Compromise Detection
- Theom - Overprovisioned Roles Shadow DB available
- Theom - Shadow DB with atypical accesses available
- User joining Zoom meeting from suspicious timezone
- User Sign in from different countries available
- UserAccountDisabled available
- Vaikora - Agent policy violation available
- Vaikora - High severity AI agent action detected available
- Valimail Enforce - High-Value User Management Event available
- Valimail Enforce - Unusual Rate of Configuration Changes or User Additions available
Impair Defenses T1562 42 rules
- blacklens Insights available
- Check Point Exposure Management - Alert Ingestion Anomaly available
- Copilot - Plugin Tampering (Enable and Disable Within 5 Minutes) available
- Cyren Feed Outage Detection available
- Field Effect MDR Alert: ARO Alert available
- Netskope - Repeated or Critical Policy Violations available
- New Sonrai Ticket available
- Pathlock TDnR - ABAP Source Code Changes available
- Pathlock TDnR - Authorization Check Value Changes (SU24) available
- Pathlock TDnR - Critical File Integrity Changes available
- Pathlock TDnR - DDIC Table Utility Changes (SE14) available
- Pathlock TDnR - Generic SAP Change Documents available
- Pathlock TDnR - Generic Table Content Changes available
- Pathlock TDnR - Global System Change Setting Events available
- Pathlock TDnR - ICM Security Events available
- Pathlock TDnR - SAP Client Configuration Changes available
- Pathlock TDnR - SAP HANA Parameter Changes available
- Pathlock TDnR - SAP Instance Profile Changes available
- Pathlock TDnR - SAP Security Audit Log Events available
- Pathlock TDnR - SE16N Direct Table Change Documents available
- Pathlock TDnR - SU24 Table USOBT_C Changes available
- Pathlock TDnR - SU24 Table USOBX_C Changes available
- Pathlock TDnR - Switchable Authorization Design Changes available
- Pathlock TDnR - Switchable Authorization Runtime Changes available
- Pathlock TDnR - System Security Policy Changes available
- Pathlock TDnR - Table Parameter Setting Changes available
- Pathlock TDnR - User Authorization Buffer Manipulation available
- Power Automate - Unusual bulk deletion of flow resources available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
- Vaikora - Agent policy violation available
- Valimail Enforce - DMARC Policy Weakened to None available
- Valimail Enforce - Email Authentication Key Deleted available
- Valimail Enforce - Unusual Rate of Configuration Changes or User Additions available
- Zero Networks Segement - Machine Removed from protection available
Obfuscated Files or Information T1027 15 rules
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity File Hash Indicators with Block Action Rule
- CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - High severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Monitor Action Rule
- Vaikora - Behavioral anomaly detected available
Masquerading T1036 11 rules
- CyberArkEPM - Process started from different locations
- CyberArkEPM - Renamed Windows binary
- CyberArkEPM - Uncommon process Internet access
- CyberArkEPM - Uncommon Windows process started from System folder
- CyberArkEPM - Unexpected executable extension
- CyberArkEPM - Unexpected executable location
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation Medium Rule available
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- Detect potential presence of a malicious file with a double extension (ASIM Web Session) available
- Pathlock TDnR - Critical File Integrity Changes available
Indicator Removal T1070 10 rules
- BTP - Build Work Zone unauthorized access and role tampering available
- BTP - Cloud Integration tampering with security material available
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- OCI - Event rule deleted available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Process Injection T1055 6 rules
- Contrast ADR - EDR Alert Correlation available
- Contrast ADR - Exploited Attack Event available
- Contrast ADR - Exploited Attack in Production available
- Contrast ADR - Security Incident Alert available
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
Access Token Manipulation T1134 4 rules
Deobfuscate/Decode Files or Information T1140 4 rules
- Dynatrace - Problem detection available
- Dynatrace Application Security - Code-Level runtime vulnerability detection available
- Dynatrace Application Security - Non-critical runtime vulnerability detection available
- Dynatrace Application Security - Third-Party runtime vulnerability detection available
Impair Defenses: Indicator Blocking T1562.006 2 rules
- SAP ETD - No new data received available
- SAP ETD - SAP system stopped reporting data available
Exploitation for Stealth T1211 1 rule
- Contrast ADR - WAF Alert Correlation available
Execution Guardrails T1480 1 rule
Impair Defenses: Disable or Modify Cloud Logs T1562.008 1 rule
- BTP - Audit log service unavailable available
No specific technique 2 rules
Defense Impairment
Modify Authentication Process T1556 9 rules
- Azure secure score block legacy authentication available
- BTP - Cloud Identity Service application configuration monitor available
- BTP - Trust and authorization Identity Provider monitor available
- External User Access Enabled
- F&O - Bank account change following network alias reassignment available
- F&O - Non-interactive account mapped to self or sensitive privileged user available
- Keeper Security - Password Changed available
- Keeper Security - User MFA Changed available
- Red Sift - MFA disabled on account available
Subvert Trust Controls T1553 7 rules
- CYFIRMA - Attack Surface - Weak Certificate Exposure - High Rule available
- CYFIRMA - Attack Surface - Weak Certificate Exposure - Medium Rule available
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- Pathlock TDnR - STRUST PSE Certificate Changes available
Modify Authentication Process: Password Filter DLL T1556.002 4 rules
- CYFIRMA - High severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Monitor Recommended Rule
Rogue Domain Controller T1207 1 rule
- Semperis DSP Mimikatz's DCShadow Alert available
Modify Cloud Compute Infrastructure T1578 1 rule
- Commvault Cloud Alert available
Credential Access
Unsecured Credentials T1552 22 rules
- BTP - Cloud Integration JDBC data source changes available
- BTP - Cloud Integration tampering with security material available
- Contrast ADR - DLP SQL Injection Correlation available
- Cyble Vision Alerts Bitbucket available
- Cyble Vision Alerts Compromised Files available
- Cyble Vision Alerts Leaked Credentials available
- Cyble Vision Alerts Postman API Exposure Detection available
- CYFIRMA - Attack Surface - Weak Certificate Exposure - High Rule available
- CYFIRMA - Attack Surface - Weak Certificate Exposure - Medium Rule available
- CYFIRMA - Compromised Employees Detection Rule available
- CYFIRMA - Customer Accounts Leaks Detection Rule available
- CYFIRMA - Public Accounts Leaks Detection Rule available
- Cynerio - IoT - Default password
- Cynerio - IoT - Weak password
- Pathlock TDnR - LDAP Synchronization Application Log Events available
- Pathlock TDnR - STRUST PSE Certificate Changes available
- Theom - Dev secrets unencrypted available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
OS Credential Dumping T1003 21 rules
- CYFIRMA - Compromised Employees Detection Rule available
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Monitor Action Rule
- CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule available
- CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule available
- New Sonrai Ticket available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
Brute Force T1110 17 rules
- API - Account Takeover available
- API - Password Cracking available
- API - Suspicious Login available
- blacklens Insights available
- Brute force attack against user credentials available
- Copilot - Jailbreak Attempt Detected available
- Detect potential file enumeration activity (ASIM Web Session) available
- Flare leaked credentials results available
- Mimecast Audit - Logon Authentication Failed
- Mimecast Audit - Logon Authentication Failed
- Multiple failed attempts of NetBackup login available
- Palo Alto Prisma Cloud - Multiple failed logins for user available
- Pathlock TDnR - Multiple Login Sessions Detected available
- Potential Password Spray Attack available
- Samsung Knox - Password Lockout Events available
- StealthTalk - Password brute force available
- Versasec CMS - Multiple Failed Login Attempts available
Credentials from Password Stores T1555 11 rules
- API - Password Cracking available
- Azure secure score PW age policy new available
- CybleVision Alerts Darkweb Marketplace Alerts available
- CybleVision Alerts Stealer Logs available
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- Flare infected device results available
- Highly Sensitive Password Accessed available
- SpyCloud Enterprise Breach Detection available
- SpyCloud Enterprise Malware Detection available
- Trust Monitor Event
Credentials from Password Stores: Credentials from Web Browsers T1555.003 8 rules
- CYFIRMA - Data Breach and Web Monitoring - Dark Web High Rule available
- CYFIRMA - Data Breach and Web Monitoring - Dark Web Medium Rule available
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Monitor Recommended Rule
Brute Force: Password Spraying T1110.003 4 rules
- CYFIRMA - High severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Monitor Recommended Rule
Forge Web Credentials T1606 3 rules
Network Sniffing T1040 2 rules
Forced Authentication T1187 1 rule
- API - Password Cracking available
No specific technique 3 rules
- Recorded Future Identity - Credential Exposure Detected available
- RSA ID Plus - Locked Administrator Account Detected available
- XbowMediumFindings available
Discovery
System Information Discovery T1082 30 rules
- CDM_ContinuousDiagnostics&Mitigation_PostureChanged available
- CMMC 2.0 Level 1 (Foundational) Readiness Posture available
- CMMC 2.0 Level 2 (Advanced) Readiness Posture available
- Cyble Vision Alerts Leaked Credentials available
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Social and Public Exposure - Source Code Exposure on Public Repositories Rule available
- CYFIRMA - Social and Public Exposure - Source Code Exposure on Public Repositories Rule available
- Datawiza - massive errors detected
- M2131_AssetStoppedLogging available
- M2131_EventLogManagementPostureChanged_EL0 available
- M2131_EventLogManagementPostureChanged_EL1 available
- M2131_EventLogManagementPostureChanged_EL2 available
- M2131_EventLogManagementPostureChanged_EL3 available
- M2131_LogRetentionLessThan1Year available
- M2131_RecommendedDatatableUnhealthy available
- NIST SP 800-53 Posture Changed available
- Pathlock TDnR - ABAP Runtime Dumps available
- Pathlock TDnR - Database Cockpit Audit Events available
- Pathlock TDnR - J2EE Security Audit Events available
- Pathlock TDnR - J2EE Security Events available
- Pathlock TDnR - Missing SAP Security Notes available
- Pathlock TDnR - Pathlock Security Radar Internal Events available
- Pathlock TDnR - RiskTrack Audit Results available
- Pathlock TDnR - SAP BTP Cloud Foundry Events available
- Pathlock TDnR - SAP HANA Database Audit Trail available
- Pathlock TDnR - SAP Public Cloud Security Audit Events available
- Pathlock TDnR - SAP Security Audit Log Events available
- Pathlock TDnR - Transaction and Report Statistics available
- ZeroTrust(TIC3.0) Control Assessment Posture Change available
Account Discovery T1087 19 rules
- API - Account Takeover available
- API - Rate limiting available
- Copilot - Plugin Tampering (Enable and Disable Within 5 Minutes) available
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- CYFIRMA - Public Accounts Leaks Detection Rule available
- Highly Sensitive Password Accessed available
- New Sonrai Ticket available
- Red Canary Threat Detection
- Sensitive Data Discovered in the Last 24 Hours
- Sensitive Data Discovered in the Last 24 Hours - Customized
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
Network Service Discovery T1046 8 rules
- Contrast ADR - DLP SQL Injection Correlation available
- Cyble Vision Alerts IOC'S available
- Cyble Vision Alerts Vulnerability available
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- CYFIRMA - Attack Surface - Domain/IP Vulnerability Exposure High Rule available
- CYFIRMA - Attack Surface - Domain/IP Vulnerability Exposure Medium Rule available
- Netskope - Suspicious Network Context (Unusual IPs/Geo/Ports) available
File and Directory Discovery T1083 8 rules
- API - Kiterunner detection available
- Cyble Vision Alerts Bitbucket available
- Cyble Vision Alerts Cloud Storage available
- Cyble Vision Alerts Docker available
- Detect potential file enumeration activity (ASIM Web Session) available
- Mimecast Secure Email Gateway - Spam Event Thread available
- Mimecast Secure Email Gateway - Spam Event Thread
- NetClean ProActive Incidents available
Cloud Storage Object Discovery T1619 5 rules
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Process Discovery T1057 3 rules
Cloud Service Discovery T1526 3 rules
Permission Groups Discovery T1069 2 rules
- OCI - Insecure metadata endpoint available
- OCI - Instance metadata access available
Cloud Infrastructure Discovery T1580 2 rules
- API - Kiterunner detection available
- OCI - Discovery activity available
Remote System Discovery T1018 1 rule
- Contrast ADR - Security Incident Alert available
No specific technique 4 rules
- SAP ETD - Execution of Sensitive Function Module available
- SAP ETD - Login from unexpected network available
- XbowLowFindings available
- XbowMediumFindings available
Lateral Movement
Remote Services T1021 17 rules
- BTP - Cloud Integration JDBC data source changes available
- Contrast ADR - DLP SQL Injection Correlation available
- New Sonrai Ticket available
- Pathlock TDnR - HANA Standalone DB Connection Events available
- Pathlock TDnR - RFC Connection Changes available
- Pathlock TDnR - SAP Cloud Connector Events available
- Pathlock TDnR - SAP RFC Gateway Events available
- Pathlock TDnR - SAP Router Log Events available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
Exploitation of Remote Services T1210 11 rules
- Contrast ADR - Exploited Attack Event available
- Contrast ADR - Exploited Attack in Production available
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- Dynatrace - Problem detection available
- Dynatrace Application Security - Code-Level runtime vulnerability detection available
- Dynatrace Application Security - Non-critical runtime vulnerability detection available
- Dynatrace Application Security - Third-Party runtime vulnerability detection available
- NRT GravityZone Incident Alerts available
Remote Services: SMB/Windows Admin Shares T1021.002 6 rules
- CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
- CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
Internal Spearphishing T1534 2 rules
No specific technique 3 rules
- Radiflow - Platform Alert available
- SAP LogServ - HANA DB - Audit Trail Policy Changes available
- SAP LogServ - HANA DB - Deactivation of Audit Trail available
Collection
Data from Cloud Storage T1530 38 rules
- Cognni Incidents for Highly Sensitive Business Information available
- Cognni Incidents for Highly Sensitive Financial Information available
- Cognni Incidents for Highly Sensitive Governance Information available
- Cognni Incidents for Highly Sensitive HR Information available
- Cognni Incidents for Highly Sensitive Legal Information available
- Cognni Incidents for Low Sensitivity Business Information available
- Cognni Incidents for Low Sensitivity Financial Information available
- Cognni Incidents for Low Sensitivity Governance Information available
- Cognni Incidents for Low Sensitivity HR Information available
- Cognni Incidents for Low Sensitivity Legal Information available
- Cognni Incidents for Medium Sensitivity Business Information available
- Cognni Incidents for Medium Sensitivity Financial Information available
- Cognni Incidents for Medium Sensitivity Governance Information available
- Cognni Incidents for Medium Sensitivity HR Information available
- Cognni Incidents for Medium Sensitivity Legal Information available
- Cyble Vision Alerts Darkweb Data Breaches available
- Netskope - Excessive Downloads Detection (Spike vs Baseline) available
- Netskope - Heavy Personal Cloud Storage Usage (Shadow IT) available
- Pathlock TDnR - Credit Card Data Changes available
- Theom - Dark Data with large fin value available
- Theom - Dev secrets exposed available
- Theom - Financial data exposed available
- Theom - Financial data unencrypted available
- Theom - Healthcare data exposed available
- Theom - Healthcare data unencrypted available
- Theom - Least priv large value shadow DB available
- Theom - National IDs exposed available
- Theom - National IDs unencrypted available
- Theom - Overprovisioned Roles Shadow DB available
- Theom - Shadow DB large datastore value available
- Theom - Shadow DB with atypical accesses available
- Theom - Unencrypted public data stores available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
- Users searching for VIP user activity
Data from Information Repositories T1213 23 rules
- CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule available
- CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule available
- CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule available
- CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule available
- Pathlock TDnR - HR User Master Change Requests available
- Pathlock TDnR - OData Application Log Events available
- Pathlock TDnR - SAP Read Access Logging Audit available
- Pathlock TDnR - SAP Read Access Logging Data available
- Pathlock TDnR - Spool Job Changes available
- Theom - Dev secrets exposed available
- Theom - Financial data exposed available
- Theom - Financial data unencrypted available
- Theom - Healthcare data exposed available
- Theom - Healthcare data unencrypted available
- Theom - National IDs exposed available
- Theom - National IDs unencrypted available
- Theom - Unencrypted public data stores available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
- Users searching for VIP user activity
Automated Collection T1119 19 rules
- API - API Scraping available
- CYFIRMA - Data Breach and Web Monitoring - Dark Web High Rule available
- CYFIRMA - Data Breach and Web Monitoring - Dark Web Medium Rule available
- New Sonrai Ticket available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
- Theom - Critical data in API headers or body available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Email Collection T1114 10 rules
- CYFIRMA - Attack Surface - Configuration High Rule available
- CYFIRMA - Attack Surface - Configuration Medium Rule available
- Mimecast Secure Email Gateway - Attachment Protect available
- Mimecast Secure Email Gateway - Attachment Protect
- Mimecast Secure Email Gateway - Impersonation Protect available
- Mimecast Secure Email Gateway - Impersonation Protect
- Mimecast Targeted Threat Protection - Impersonation Protect available
- Mimecast Targeted Threat Protection - Impersonation Protect
- Server Oriented Cmdlet And User Oriented Cmdlet used available
- VIP Mailbox manipulation available
Archive Collected Data T1560 10 rules
- Theom - Dark Data with large fin value available
- Theom - Least priv large value shadow DB available
- Theom - Overprovisioned Roles Shadow DB available
- Theom - Shadow DB large datastore value available
- Theom - Shadow DB with atypical accesses available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Data from Local System T1005 5 rules
- blacklens Insights available
- Contrast ADR - DLP SQL Injection Correlation available
- CybleVision Alerts Darkweb Marketplace Alerts available
- CybleVision Alerts Stealer Logs available
- SailPointIdentityNowAlertForTriggers available
Data Staged T1074 3 rules
Screen Capture T1113 2 rules
Input Capture T1056 1 rule
- Azure secure score MFA registration V2 available
Command & Control
Application Layer Protocol T1071 43 rules
- blacklens Insights available
- Cyble Vision Alerts IOC'S available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation Medium Rule available
- CYFIRMA - Attack Surface - Open Ports High Rule available
- CYFIRMA - Attack Surface - Open Ports Medium Rule available
- CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity Trojan File Hash Indicators with Monitor Action Rule
- Cyren High-Risk IP Indicators available
- Detect instances of multiple client errors occurring within a brief period of time (ASIM Web Session) available
- Detect known risky user agents (ASIM Web Session) available
- Detect potential file enumeration activity (ASIM Web Session) available
- Detect potential presence of a malicious file with a double extension (ASIM Web Session) available
- Detect requests for an uncommon resources on the web (ASIM Web Session) available
- Detect URLs containing known malicious keywords or commands (ASIM Web Session) available
- Netskope - Suspicious Network Context (Unusual IPs/Geo/Ports) available
- New Sonrai Ticket available
- Pathlock TDnR - SAP HTTP Webserver Events available
- Pathlock TDnR - SAP RFC Gateway Events available
- Pathlock TDnR - SAP Web Dispatcher HTTP Events available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI map Domain entity to PaloAlto CommonSecurityLog
- TI map Domain entity to PaloAlto CommonSecurityLog
- TI map IP entity to AppServiceHTTPLogs
- TI map IP entity to AppServiceHTTPLogs
- TI map IP entity to Azure Key Vault logs
- TI map IP entity to Azure Key Vault logs
- TI map IP entity to AzureNetworkAnalytics_CL (NSG Flow Logs)
- TI map IP entity to AzureNetworkAnalytics_CL (NSG Flow Logs)
- TI map IP entity to GitHub_CL
- TI map IP entity to GitHub_CL
- TI map IP entity to Workday(ASimAuditEventLogs)
- TI map IP entity to Workday(ASimAuditEventLogs)
Application Layer Protocol: Web Protocols T1071.001 22 rules
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation High Rule available
- CYFIRMA - Brand Intelligence - Domain Impersonation High Rule available
- CYFIRMA - Brand Intelligence - Domain Impersonation Medium Rule available
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Monitor Recommended Rule
- Detect presence of private IP addresses in URLs (ASIM Web Session) available
- The download of potentially risky files from the Discord Content Delivery Network (CDN) (ASIM Web Session) available
- Web sites blocked by Eset available
Proxy T1090 15 rules
- BitSight - drop in company ratings available
- BitSight - drop in the headline rating available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation Medium Rule available
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Monitor Recommended Rule
Fallback Channels T1008 9 rules
- Contrast ADR - DLP SQL Injection Correlation available
- Contrast ADR - EDR Alert Correlation available
- Contrast ADR - Exploited Attack Event available
- Contrast ADR - Exploited Attack in Production available
- Contrast ADR - Security Incident Alert available
- Contrast ADR - WAF Alert Correlation available
- Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution) available
- Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution) available
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution) available
Dynamic Resolution: Domain Generation Algorithms T1568.002 8 rules
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
Data Obfuscation T1001 6 rules
- Detect presence of private IP addresses in URLs (ASIM Web Session) available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Protocol Tunneling T1572 5 rules
- CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Monitor Recommended Rule
- Pathlock TDnR - SAP Router Log Events available
Proxy: Multi-hop Proxy T1090.003 4 rules
- CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Monitor Recommended Rule
Ingress Tool Transfer T1105 4 rules
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
Dynamic Resolution T1568 4 rules
- Cyren High-Risk IP Indicators available
- Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution) available
- Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution) available
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution) available
Encrypted Channel: Symmetric Cryptography T1573.001 4 rules
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
Web Service T1102 2 rules
Encrypted Channel T1573 2 rules
Non-Standard Port T1571 1 rule
No specific technique 1 rule
- Radiflow - Platform Alert available
Exfiltration
Exfiltration Over C2 Channel T1041 32 rules
- blacklens Insights available
- Contrast ADR - DLP SQL Injection Correlation available
- Cyble Vision Alerts Compromised Files available
- Cyble Vision Alerts Postman API Exposure Detection available
- CybleVision Alerts Darkweb Marketplace Alerts available
- CybleVision Alerts Stealer Logs available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation High Rule available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation Medium Rule available
- CYFIRMA - High severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - High severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Block Recommendation Rule
- CYFIRMA - Medium severity Command & Control Network Indicators with Monitor Recommendation Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Malicious Phishing Network Indicators - Monitor Recommended Rule
- Detect presence of private IP addresses in URLs (ASIM Web Session) available
- New Sonrai Ticket available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Exfiltration Over Web Service T1567 14 rules
- Netskope - Anomalous User Behavior (High Volume from Unmanaged Device) available
- Netskope - Data Movement Tracking (Upload/Download Monitoring) available
- Netskope - Heavy Personal Cloud Storage Usage (Shadow IT) available
- Netskope - Large Outbound Data Transfer / Sensitive Upload (DLP) available
- Netskope - Unsanctioned/Risky Cloud App Access (Shadow IT) available
- Power Automate - Departing employee flow activity available
- Power Platform - Connector added to a sensitive environment available
- ProofpointPOD - Email sender in TI list
- ProofpointPOD - Email sender IP in TI list
- ProofpointPOD - Multiple archived attachments to the same recipient available
- ProofpointPOD - Multiple large emails to the same recipient available
- ProofpointPOD - Multiple protected emails to unknown recipient available
- SOCRadar Alarm Volume Spike available
- Web sites blocked by Eset available
Exfiltration Over Alternative Protocol T1048 12 rules
- Cyble Vision Alerts Darkweb Data Breaches available
- CYFIRMA - Data Breach and Web Monitoring - Dark Web High Rule available
- CYFIRMA - Data Breach and Web Monitoring - Dark Web Medium Rule available
- Netskope - Large Outbound Data Transfer / Sensitive Upload (DLP) available
- Netskope - Repeated or Critical Policy Violations available
- Netskope - Suspicious Network Context (Unusual IPs/Geo/Ports) available
- Pathlock TDnR - OData Application Log Events available
- Pathlock TDnR - Outbound SAP SMTP Email available
- Pathlock TDnR - Outgoing Spool Print Job Events available
- Pathlock TDnR - SAP Download Observer Events available
- Pathlock TDnR - SAP Read Access Logging Data available
- Pathlock TDnR - SE16N Direct Table Change Documents available
Transfer Data to Cloud Account T1537 11 rules
- Cyble Vision Alerts Bitbucket available
- Cyble Vision Alerts Cloud Storage available
- Cyble Vision Alerts Docker available
- CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule available
- CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule available
- Power Platform - Connector added to a sensitive environment available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Automated Exfiltration T1020 5 rules
- API - BOLA available
- Server Oriented Cmdlet And User Oriented Cmdlet used available
- Third party integrated apps available
- Users searching for VIP user activity
- VIP Mailbox manipulation available
Data Transfer Size Limits T1030 5 rules
Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.002 4 rules
- CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity TOR Node Network Indicators - Monitor Recommended Rule
No specific technique 1 rule
- Radiflow - Platform Alert available
Impact
Data Manipulation T1565 27 rules
- Copilot - Jailbreak Attempt Detected available
- Dynatrace - Problem detection available
- Dynatrace Application Security - Attack detection available
- Dynatrace Application Security - Code-Level runtime vulnerability detection available
- Dynatrace Application Security - Non-critical runtime vulnerability detection available
- Dynatrace Application Security - Third-Party runtime vulnerability detection available
- F&O - Mass update or deletion of user records available
- F&O - Reverted bank account number modifications available
- Infoblox - SOC Insight Detected - API Source available
- Infoblox - SOC Insight Detected - API Source available
- Infoblox - SOC Insight Detected - CDC Source available
- Pathlock TDnR - Bank Master Data Changes available
- Pathlock TDnR - Business Partner Bank Data Changes available
- Pathlock TDnR - Credit Card Data Changes available
- Pathlock TDnR - Debitor Change Documents available
- Pathlock TDnR - G/L Account Changes available
- Pathlock TDnR - Generic SAP Change Documents available
- Pathlock TDnR - Generic Table Content Changes available
- Pathlock TDnR - HR User Master Change Requests available
- Pathlock TDnR - IBAN Change Documents available
- Pathlock TDnR - Payment Request Changes available
- Pathlock TDnR - Vendor Change Documents available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Endpoint Denial of Service T1499 19 rules
- API - Rate limiting available
- Cyble Vision Alerts Domain Expiry Alert available
- Cyble Vision Alerts SSL Certificate Expiry available
- CYFIRMA - Attack Surface - Domain/IP Vulnerability Exposure High Rule available
- CYFIRMA - Attack Surface - Domain/IP Vulnerability Exposure Medium Rule available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation High Rule available
- CYFIRMA - Attack Surface - Malicious Domain/IP Reputation Medium Rule available
- D3 Smart SOAR - High or critical severity incident detected available
- Missing Domain Controller Heartbeat
- New Sonrai Ticket available
- Red Canary Threat Detection
- Sonrai Ticket Assigned available
- Sonrai Ticket Closed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Escalation Executed available
- Sonrai Ticket Reopened available
- Sonrai Ticket Risk Accepted available
- Sonrai Ticket Snoozed available
- Sonrai Ticket Updated available
Data Destruction T1485 18 rules
- BTP - Mass user deletion in a sub account available
- BTP - Mass user deletion in SAP Cloud Identity Service available
- CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action and Malware
- Employee account deleted available
- F&O - Mass update or deletion of user records available
- Power Apps - Multiple apps deleted available
- Power Automate - Departing employee flow activity available
- Power Automate - Unusual bulk deletion of flow resources available
- SenservaPro AD Applications Not Using Client Credentials available
- SOCRadar Alarm Volume Spike available
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
- TI map IP entity to LastPass data available
- Unusual Volume of Password Updated or Removed available
Data Encrypted for Impact T1486 18 rules
- Cyble Vision Alerts Darkweb Ransomware Leak available
- Cyble Vision Alerts IOC'S available
- Cyble Vision Alerts Physical Threat Alert available
- CYFIRMA - Data Breach and Web Monitoring - Dark Web High Rule available
- CYFIRMA - Data Breach and Web Monitoring - Dark Web Medium Rule available
- CYFIRMA - High severity File Hash Indicators with Block Action and Malware
- CYFIRMA - High severity File Hash Indicators with Block Action Rule
- CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - High severity File Hash Indicators with Monitor Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Block Action Rule
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action and Malware
- CYFIRMA - Medium severity File Hash Indicators with Monitor Action Rule
- Theom Critical Risks available
- Theom High Risks available
- Theom Insights available
- Theom Low Risks available
- Theom Medium Risks available
Defacement T1491 10 rules
- BitSight - new alert found available
- BitSight - new breach found available
- Cyble Vision Alerts Hacktivism available
- Cyble Vision Alerts Website Defacement Content available
- Cyble Vision Alerts Website Defacement Keyword available
- Cyble Vision Alerts Website Defacement URL available
- CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule available
- CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule available
- F&O - Mass update or deletion of user records available
- Power Automate - Departing employee flow activity available
Network Denial of Service T1498 10 rules
- Azure secure score admin MFA available
- Cyble Vision Alerts Hacktivism available
- CYFIRMA - High severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - High severity Malicious Network Indicators with Monitor Action Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Block Action Rule
- CYFIRMA - Medium severity Malicious Network Indicators with Monitor Action Rule
- Detect instances of multiple server errors occurring within a brief period of time (ASIM Web Session) available
- Infoblox - SOC Insight Detected - API Source available
- Infoblox - SOC Insight Detected - API Source available
- Infoblox - SOC Insight Detected - CDC Source available
System Shutdown/Reboot T1529 8 rules
- Azure secure score admin MFA available
- Azure secure score one admin available
- Azure secure score role overlap available
- Azure Secure Score Self Service Password Reset available
- Azure secure score sign in risk policy available
- Azure secure score user risk policy available
- OCI - Multiple instances terminated available
- SenservaPro AD Applications Not Using Client Credentials available
Resource Hijacking T1496 6 rules
- CYFIRMA - High severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - High severity Trojan Network Indicators - Monitor Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Block Recommended Rule
- CYFIRMA - Medium severity Trojan Network Indicators - Monitor Recommended Rule
- F&O - Reverted bank account number modifications available
- OCI - Multiple instances launched available
Account Access Removal T1531 6 rules
- BTP - Build Work Zone unauthorized access and role tampering available
- BTP - Mass user deletion in a sub account available
- BTP - Mass user deletion in SAP Cloud Identity Service available
- Commvault Cloud Alert available
- Valimail Enforce - High-Value User Management Event available
- Valimail Enforce - Unusual Rate of Configuration Changes or User Additions available
Service Stop T1489 2 rules
Financial Theft T1657 1 rule
No specific technique 1 rule
Untagged
- AIShield - Image classification AI Model Evasion high suspicious vulnerability detection available
- AIShield - Image classification AI Model Evasion low suspicious vulnerability detection available
- AIShield - Image classification AI Model extraction high suspicious vulnerability detection available
- AIShield - Image Segmentation AI Model extraction high suspicious vulnerability detection available
- AIShield - Natural language processing AI model extraction high suspicious vulnerability detection available
- AIShield - Tabular classification AI Model Evasion high suspicious vulnerability detection available
- AIShield - Tabular classification AI Model Evasion low suspicious vulnerability detection available
- AIShield - Tabular classification AI Model extraction high suspicious vulnerability detection available
- AIShield - Timeseries Forecasting AI Model extraction high suspicious vulnerability detection available
- Anvilogic Alert available
- Armorblox Needs Review Alert available
- Atlassian Beacon Alert available
- Best Practice Compliance Check Not Passed available
- Configuration Backup Failed available
- Cortex XDR Incident - High
- Cortex XDR Incident - Low
- Cortex XDR Incident - Medium
- Darktrace AI Analyst
- Darktrace Model Breach
- Darktrace System Status
- Digital Shadows Incident Creation for exclude-app
- Digital Shadows Incident Creation for include-app
- Forescout-DNS_Sniff_Event_Monitor
- Guardian- Additional check JSON Policy Violation Detection available
- Guardian- Ban Topic Policy Violation Detection available
- Guardian- BII Detection Policy Violation Detection available
- Guardian- Block Competitor Policy Violation Detection available
- Guardian- Blocks specific strings of text Policy Violation Detection available
- Guardian- Code Detection Policy Violation Detection available
- Guardian- Content Access Control Allowed List Policy Violation Detection available
- Guardian- Content Access Control Blocked List Policy Violation Detection available
- Guardian- Content Safety Profanity Policy Violation Detection available
- Guardian- Content Safety Toxicity Policy Violation Detection. available
- Guardian- Gender Bias Policy Violation Detection available
- Guardian- Input Output Relevance Policy Violation Detection available
- Guardian- Input Rate Limiter Policy Violation Detection available
- Guardian- Invisible Text Policy Violation Detection available
- Guardian- Language Detection Policy Violation Detection available
- Guardian- Malicious URL Policy Violation Detection available
- Guardian- No LLM Output Policy Violation Detection available
- Guardian- Not Safe For Work Policy Violation Detection available
- Guardian- Privacy Protection PII Policy Violation Detection available
- Guardian- Racial Bias Policy Violation Detection available
- Guardian- Regex Policy Violation Detection available
- Guardian- Same Input/Output Language Detection Policy Violation Detection available
- Guardian- Secrets Policy Violation Detection available
- Guardian- Security Integrity Checks Prompt Injection Policy Violation Detection available
- Guardian- Sentiment Policy Violation Detection available
- Guardian- Special PII Detection Policy Violation Detection available
- Guardian- Token Limit Policy Violation Detection available
- Guardian- URL Detection Policy Violation Detection available
- Guardian- URL Reachability Policy Violation Detection available
- Hunt Device Discovery Subnet Ranges
- Hunt devices supporting MDE Containment
- Hunt for Defender for Identity not installed but eligible
- Hunt for devices organized by subnet
- Jamf Protect - Alerts available
- Jamf Protect - Unified Logs available
- Malware Event Detected available
- Samsung Knox - Peripheral Access Detection with Camera Events available
- Samsung Knox - Peripheral Access Detection with Mic Events available
- Samsung Knox - Security Log Full Events available
- SAP ETD - Synch alerts available
- SAP ETD - Synch investigations available
- Tanium Threat Response Alerts
- Valence Security Alerts available
- Veeam ONE Application with No Recent Data Backup Sessions available
- Veeam ONE Backup Copy RPO available
- Veeam ONE Backup Server Security and Compliance State available
- Veeam ONE Computer with No Backup available
- Veeam ONE Immutability Change Tracking available
- Veeam ONE Immutability State available
- Veeam ONE Job Disabled available
- Veeam ONE Job Disabled (Veeam Backup for Microsoft 365) available
- Veeam ONE Malware Detection Change Tracking available
- Veeam ONE Possible Ransomware Activity (Hyper-V) available
- Veeam ONE Possible Ransomware Activity (vSphere) available
- Veeam ONE Suspicious Incremental Backup Size available
- Veeam ONE Unusual Job Duration available
- Veeam ONE Unusual Job Duration (Veeam Backup for Microsoft 365) available
- Veeam ONE VM with No Backup available
- Veeam ONE VM with No Backup (Hyper-V) available
- Veeam ONE VM with No Replica available
- Veeam ONE VM with No Replica (Hyper-V) available