Sigma non-Windows coverage
1,017 non-Windows Sigma detection rules across 14 platforms, grouped by MITRE ATT&CK technique within each platform. The Windows coverage matrix lives at /rules/sigma/; this page reorganizes the same corpus along platform × technique because non-Windows rules have no catalog event IDs to plot.
For coverage organized by each platform's native action vocabulary across all vendors, see the platform matrices: AWS, Azure AD, GCP, M365, Okta. This page is the vendor-organized browse of the same rules.
Linux
Reconnaissance
No specific technique 1 rule
Resource Development
Develop Capabilities T1587 2 rules
Initial Access
Exploit Public-Facing Application T1190 13 rules
- Apache Spark Shell Command Injection - ProcessCreation test
- Atlassian Confluence CVE-2022-26134 test
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux) test
- Linux Suspicious Child Process from Node.js - React2Shell experimental
- OMIGOD SCX RunAsProvider ExecuteScript test
- OMIGOD SCX RunAsProvider ExecuteShellCommand test
- Potential CVE-2023-2283 Exploitation test
- Potential SAP NetWeaver Webshell Creation - Linux experimental
- Suspicious Child Process of SAP NetWeaver - Linux experimental
- Suspicious Named Error test
- Suspicious OpenSSH Daemon Error test
- Suspicious SQL Query test
- Suspicious VSFTPD Error Messages test
Supply Chain Compromise: Compromise Software Supply Chain T1195.002 6 rules
- Axios NPM Compromise File Creation Indicators - Linux experimental
- Axios NPM Compromise Indicators - Linux experimental
- LiteLLM / TeamPCP Supply Chain Attack Indicators experimental
- Shai-Hulud 2.0 Malicious NPM Package Installation - Linux experimental
- Shai-Hulud Malicious Bun Execution - Linux experimental
- TeamPCP LiteLLM Supply Chain Attack Persistence Indicators experimental
Execution
Command and Scripting Interpreter T1059 17 rules
- Atlassian Confluence CVE-2022-26134 test
- BPFDoor Abnormal Process ID or Lock File Accessed test
- Capsh Shell Invocation - Linux test
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux) test
- Inline Python Execution - Spawn Shell Via OS System Library test
- Linux Suspicious Child Process from Node.js - React2Shell experimental
- Potential Netcat Reverse Shell Execution test
- Potential Xterm Reverse Shell test
- Python Spawning Pretty TTY Via PTY Module test
- Shai-Hulud Malware Indicators - Linux experimental
- Shell Execution via Git - Linux test
- Shell Execution via Rsync - Linux experimental
- Shell Invocation Via Ssh - Linux test
- Suspicious Invocation of Shell via AWK - Linux test
- Suspicious Invocation of Shell via Rsync experimental
- Suspicious Java Children Processes test
- Vim GTFOBin Abuse - Linux test
Command and Scripting Interpreter: Unix Shell T1059.004 16 rules
- Axios NPM Compromise Indicators - Linux experimental
- BPFtrace Unsafe Option Usage test
- Equation Group Indicators test
- Interactive Bash Suspicious Children test
- JexBoss Command Sequence test
- Linux Reverse Shell Indicator test
- Nohup Execution test
- Potential Abuse of Linux Magic System Request Key experimental
- Potentially Suspicious Long Filename Pattern - Linux experimental
- Script Interpreter Spawning Credential Scanner - Linux experimental
- Shell Invocation via Env Command - Linux test
- Suspicious Activity in Shell Commands test
- Suspicious Commands Linux test
- Suspicious Download and Execute Pattern via Curl/Wget experimental
- Suspicious Filename with Embedded Base64 Commands experimental
- Suspicious Reverse Shell Command Line test
Command and Scripting Interpreter: Hypervisor CLI T1059.012 9 rules
- ESXi Account Creation Via ESXCLI test
- ESXi Admin Permission Assigned To Account Via ESXCLI test
- ESXi Network Configuration Discovery Via ESXCLI test
- ESXi Storage Information Discovery Via ESXCLI test
- ESXi Syslog Configuration Change Via ESXCLI test
- ESXi System Information Discovery Via ESXCLI test
- ESXi VM Kill Via ESXCLI test
- ESXi VM List Discovery Via ESXCLI test
- ESXi VSAN Information Discovery Via ESXCLI test
Exploitation for Client Execution T1203 6 rules
- Antivirus Exploitation Framework Detection stable
- OMIGOD SCX RunAsProvider ExecuteScript test
- OMIGOD SCX RunAsProvider ExecuteShellCommand test
- Shai-Hulud Malicious Bun Execution - Linux experimental
- Suspicious Download and Execute Pattern via Curl/Wget experimental
- Suspicious Invocation of Shell via Rsync experimental
Scheduled Task/Job: Cron T1053.003 4 rules
- Modifying Crontab test
- New Cron File Created experimental
- Scheduled Cron Task/Job - Linux test
- Triple Cross eBPF Rootkit Default Persistence test
Command and Scripting Interpreter: Python T1059.006 3 rules
- Axios NPM Compromise Indicators - Linux experimental
- Python One-Liners with Base64 Decoding - Linux experimental
- Python Path Configuration File Creation - Linux test
Command and Scripting Interpreter: Windows Command Shell T1059.003 2 rules
- Potential SAP NetWeaver Webshell Creation - Linux experimental
- Suspicious Child Process of SAP NetWeaver - Linux experimental
Scheduled Task/Job: At T1053.002 1 rule
- Scheduled Task/Job At stable
User Execution T1204 1 rule
- Antivirus Hacktool Detection stable
No specific technique 15 rules
- Bash Interactive Shell test
- Enable BPF Kprobes Tracing test
- Execution Of Script Located In Potentially Suspicious Directory test
- Named Pipe Created Via Mkfifo test
- Potential Exploitation of CVE-2024-3094 - Suspicious SSH Child Process test
- Potential Perl Reverse Shell Execution test
- Potential PHP Reverse Shell test
- Potential Ruby Reverse Shell test
- Potentially Suspicious Named Pipe Created Via Mkfifo test
- Python Reverse Shell Execution Via PTY And Socket Modules test
- Shell Execution Of Process Located In Tmp Directory test
- Suspicious Nohup Execution test
- UNC4841 - Barracuda ESG Exploitation Indicators test
- UNC4841 - Email Exfiltration File Pattern test
- UNC4841 - Potential SEASPY Execution test
Persistence
Account Manipulation T1098 2 rules
Create Account T1136 1 rule
Create or Modify System Process: Windows Service T1543.003 1 rule
- Special File Creation via Mknod Syscall experimental
Power Settings T1653 1 rule
- Mask System Power Settings Via Systemctl experimental
Privilege Escalation
Exploitation for Privilege Escalation T1068 9 rules
- Buffer Overflow Attempts test
- Linux Sudo Chroot Execution experimental
- Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation experimental
- OMIGOD SCX RunAsProvider ExecuteScript test
- OMIGOD SCX RunAsProvider ExecuteShellCommand test
- Possible Coin Miner CPU Priority Param test
- Potential Nimbuspwn Exploit CVE-2022-29799 and CVE-2022-27800 test
- Sudo Privilege Escalation CVE-2019-14287 test
- Sudo Privilege Escalation CVE-2019-14287 - Builtin test
Abuse Elevation Control Mechanism T1548 6 rules
- Linux Capabilities Discovery test
- Linux Doas Conf File Creation stable
- Linux Doas Tool Execution stable
- Linux Setgid Capability Set on a Binary via Setcap Utility experimental
- Linux Setuid Capability Set on a Binary via Setcap Utility experimental
- Potential Exploitation of CVE-2025-5054 or CVE-2025-4598 experimental
No specific technique 2 rules
Stealth
Obfuscated Files or Information T1027 3 rules
- Decode Base64 Encoded Text test
- Potentially Suspicious Long Filename Pattern - Linux experimental
- Suspicious Filename with Embedded Base64 Commands experimental
Masquerading T1036 2 rules
Obfuscated Files or Information: Command Obfuscation T1027.010 1 rule
- Python One-Liners with Base64 Decoding - Linux experimental
Indicator Removal T1070 1 rule
Indicator Removal: File Deletion T1070.004 1 rule
- File Deletion stable
No specific technique 7 rules
- Enable BPF Kprobes Tracing test
- Potential Suspicious BPF Activity - Linux test
- Remove Scheduled Cron Task/Job test
- Triple Cross eBPF Rootkit Default LockFile test
- Triple Cross eBPF Rootkit Execve Hijack test
- UNC4841 - Barracuda ESG Exploitation Indicators test
- UNC4841 - Email Exfiltration File Pattern test
Defense Impairment
Disable or Modify Tools T1685 7 rules
- ASLR Disabled Via Sysctl or Direct Syscall - Linux experimental
- Auditing Configuration Changes on Linux Host test
- Disable Or Stop Services test
- ESXi Syslog Configuration Change Via ESXCLI test
- Kaspersky Endpoint Security Stopped Via CommandLine - Linux experimental
- Logging Configuration Changes on Linux Host test
- Terminate Linux Process Via Kill test
Credential Access
Unsecured Credentials: Credentials In Files T1552.001 5 rules
- Copy Passwd Or Shadow From TMP Path test
- Credentials In Files - Linux test
- Linux Recon Indicators test
- PUA - TruffleHog Execution - Linux experimental
- Shai-Hulud Malicious GitHub Workflow Creation experimental
OS Credential Dumping T1003 2 rules
Network Sniffing T1040 1 rule
Unsecured Credentials T1552 1 rule
Discovery
File and Directory Discovery T1083 11 rules
- Capabilities Discovery - Linux test
- File and Directory Discovery - Linux test
- Linux Capabilities Discovery test
- Potential Discovery Activity Using Find - Linux test
- PUA - TruffleHog Execution - Linux experimental
- Shell Execution GCC - Linux test
- Shell Execution via Find - Linux test
- Shell Execution via Flock - Linux test
- Shell Execution via Nice - Linux test
- Shell Invocation via Apt - Linux test
- Vim GTFOBin Abuse - Linux test
System Information Discovery T1082 9 rules
- Container Residence Discovery Via Proc Virtual FS test
- Docker Container Discovery Via Dockerenv Listing test
- OS Architecture Discovery Via Grep test
- Potential Container Discovery Via Inodes Listing test
- Potential GobRAT File Discovery Via Grep test
- System and Hardware Information Discovery stable
- System Info Discovery via Sysinfo Syscall experimental
- System Information Discovery stable
- System Information Discovery - Auditd test
System Service Discovery T1007 6 rules
Network Service Discovery T1046 3 rules
Process Discovery T1057 2 rules
- Process Discovery stable
- System Info Discovery via Sysinfo Syscall experimental
Collection
Clipboard Data T1115 3 rules
Data from Local System T1005 2 rules
- Script Interpreter Spawning Credential Scanner - Linux experimental
- Shai-Hulud NPM Package Malicious Exfiltration via Curl experimental
Screen Capture T1113 2 rules
Archive Collected Data: Archive via Utility T1560.001 2 rules
- Data Compressed test
- LiteLLM / TeamPCP Supply Chain Attack Indicators experimental
Automated Collection T1119 1 rule
- Shai-Hulud Malicious GitHub Workflow Creation experimental
Audio Capture T1123 1 rule
- Audio Capture test
Command & Control
Ingress Tool Transfer T1105 7 rules
- Axios NPM Compromise File Creation Indicators - Linux experimental
- Axios NPM Compromise Indicators - Linux experimental
- Curl Usage on Linux test
- Download File To Potentially Suspicious Directory Via Wget test
- Remote File Copy stable
- Suspicious Curl File Upload - Linux test
- Wget Creating Files in Tmp Directory test
Proxy T1090 3 rules
Web Service T1102 2 rules
Protocol Tunneling T1572 2 rules
No specific technique 1 rule
Exfiltration
Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 2 rules
- Data Exfiltration with Wget test
- Python WebServer Execution - Linux experimental
Impact
System Shutdown/Reboot T1529 3 rules
Data Destruction T1485 2 rules
Service Stop T1489 2 rules
- Disable Or Stop Services test
- Potential Abuse of Linux Magic System Request Key experimental
Resource Hijacking T1496 2 rules
Account Access Removal T1531 2 rules
Endpoint Denial of Service T1499 1 rule
- Potential Abuse of Linux Magic System Request Key experimental
No specific technique 1 rule
macOS
Resource Development
Initial Access
Execution
Command and Scripting Interpreter: AppleScript T1059.002 9 rules
- Atomic MacOS Stealer - FileGrabber Activity experimental
- Axios NPM Compromise Indicators - macOS experimental
- Clipboard Access Via OSAScript test
- JXA In-memory Execution Via OSAScript test
- MacOS Scripting Interpreter AppleScript test
- Osacompile Execution By Potentially Suspicious Applet/Osascript test
- OSACompile Run-Only Execution test
- Suspicious Execution via macOS Script Editor test
- Suspicious Microsoft Office Child Process - MacOS test
User Execution T1204 4 rules
- Antivirus Hacktool Detection stable
- macOS Gatekeeper User Override experimental
- macOS XProtect Malware Detection experimental
- Payload Decoded and Decrypted via Built-in Utilities test
Inter-Process Communication T1559 3 rules
- Connection to Suspicious XPC Service experimental
- macOS XPC Service Abuse experimental
- XPC Connection from Unusual Location experimental
Command and Scripting Interpreter: Unix Shell T1059.004 1 rule
- Axios NPM Compromise Indicators - macOS experimental
No specific technique 3 rules
- JAMF MDM Execution test
- JAMF MDM Potential Suspicious Child Process test
- macOS ESF Suspicious Process Execution experimental
Persistence
Create Account: Local Account T1136.001 2 rules
- Creation Of A Local User Account test
- macOS User Account Manipulation experimental
Boot or Logon Autostart Execution: Kernel Modules and Extensions T1547.006 2 rules
- Kernel Extension Loaded from Temporary Directory experimental
- Unsigned Kernel Extension Load Attempt experimental
Account Manipulation T1098 1 rule
- macOS User Account Manipulation experimental
Create or Modify System Process T1543 1 rule
- macOS ESF Launch Persistence Creation experimental
Boot or Logon Autostart Execution T1547 1 rule
- macOS Configuration Profile Installation experimental
No specific technique 1 rule
Privilege Escalation
Exploitation for Privilege Escalation T1068 2 rules
- macOS Setuid/Setgid Privilege Escalation experimental
- XPC Privilege Escalation Attempt experimental
Abuse Elevation Control Mechanism: Sudo and Sudo Caching T1548.003 2 rules
- macOS Multiple Failed Sudo Attempts experimental
- macOS Sudo Privilege Escalation Attempts experimental
Abuse Elevation Control Mechanism T1548 1 rule
- macOS TCC Privacy Bypass Attempt experimental
Abuse Elevation Control Mechanism: Setuid and Setgid T1548.001 1 rule
- macOS Setuid/Setgid Privilege Escalation experimental
No specific technique 1 rule
- macOS UL Sudo Command Execution experimental
Stealth
Impair Defenses: Disable or Modify Tools T1562.001 3 rules
- macOS System Integrity Protection Modification Attempt experimental
- macOS TCC Database Modification experimental
- SIGKILL Sent to Security Tools experimental
Indicator Removal: File Deletion T1070.004 2 rules
- macOS Data Destruction Tools experimental
- macOS ESF Deletion In Sensitive Directories experimental
Valid Accounts T1078 2 rules
- macOS Authentication Events experimental
- macOS Sudo Privilege Escalation Attempts experimental
Hide Artifacts: Hidden Files and Directories T1564.001 2 rules
- Atomic MacOS Stealer - Persistence Indicators experimental
- macOS ESF Rename To Hidden Dotfile experimental
Rootkit T1014 1 rule
- Suspicious Kernel Extension Names experimental
Valid Accounts: Cloud Accounts T1078.004 1 rule
- macOS SSH Connection Detection experimental
Impair Defenses: Disable or Modify System Firewall T1562.004 1 rule
- Firewall Disabled experimental
No specific technique 1 rule
- macOS ESF Suspicious W+X Memory Mapping experimental
Defense Impairment
File and Directory Permissions Modification T1222 2 rules
- macOS Code Signature Invalidation experimental
- macOS TCC Database Modification experimental
Subvert Trust Controls: Gatekeeper Bypass T1553.001 2 rules
- Gatekeeper Bypass via Xattr test
- macOS Gatekeeper User Override experimental
Domain or Tenant Policy Modification T1484 1 rule
- macOS MDM Profile Manipulation experimental
Subvert Trust Controls: Code Signing T1553.002 1 rule
- macOS Code Signature Invalidation experimental
Modify Authentication Process T1556 1 rule
- macOS Configuration Profile Installation experimental
Credential Access
Credentials from Password Stores: Keychain T1555.001 2 rules
- Credentials from Password Stores - Keychain test
- macOS Suspicious Keychain Access experimental
Network Sniffing T1040 1 rule
Brute Force T1110 1 rule
- macOS Multiple Failed Sudo Attempts experimental
Credentials from Password Stores T1555 1 rule
- macOS Authentication Events experimental
Discovery
No specific technique 1 rule
- macOS ESF Sensitive File Access experimental
Lateral Movement
Remote Services: SSH T1021.004 2 rules
- macOS File Transfer Tool Execution experimental
- macOS SSH Connection Detection experimental
Remote Service Session Hijacking T1563 2 rules
- macOS Remote Execution Tools experimental
- macOS Screen Sharing Session experimental
Remote Services T1021 1 rule
- macOS Remote Execution Tools experimental
Remote Services: SMB/Windows Admin Shares T1021.002 1 rule
- macOS Network Share Access experimental
Remote Services: VNC T1021.005 1 rule
- macOS Screen Sharing Session experimental
Lateral Tool Transfer T1570 1 rule
- macOS File Transfer Tool Execution experimental
Collection
Clipboard Data T1115 2 rules
Archive Collected Data: Archive via Utility T1560.001 2 rules
- Disk Image Mounting Via Hdiutil - MacOS test
- macOS Data Compression Tools experimental
Data from Network Shared Drive T1039 1 rule
- macOS Network Share Access experimental
Screen Capture T1113 1 rule
No specific technique 1 rule
- macOS UL Unusual TCC Access Request experimental
Command & Control
Ingress Tool Transfer T1105 6 rules
- Axios NPM Compromise File Creation Indicators - MacOS experimental
- Axios NPM Compromise Indicators - macOS experimental
- File Download Via Nscurl - MacOS test
- Hidden Flag Set On File/Directory Via Chflags - MacOS test
- macOS HTTP Tools with Protocol Indicators experimental
- Potential In-Memory Download And Compile Of Payloads test
Application Layer Protocol T1071 1 rule
- macOS Network Utility Tools for C2 experimental
Application Layer Protocol: DNS T1071.004 1 rule
- macOS DNS Query Tools for C2 experimental
Dynamic Resolution T1568 1 rule
- macOS DNS Query Tools for C2 experimental
Dynamic Resolution: Domain Generation Algorithms T1568.002 1 rule
- DNS Resolution Failure Spike experimental
No specific technique 4 rules
- macOS ESF Suspicious Curl Download experimental
- macOS ESF Suspicious Process Execution experimental
- Potential WizardUpdate Malware Infection test
- Potential XCSSET Malware Infection test
Exfiltration
Exfiltration Over C2 Channel T1041 1 rule
- macOS Network Upload Activity experimental
Transfer Data to Cloud Account T1537 1 rule
- macOS Cloud Storage Access Tools experimental
Exfiltration Over Web Service T1567 1 rule
- macOS Network Upload Activity experimental
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule
- macOS Cloud Storage Access Tools experimental
No specific technique 1 rule
Impact
Inhibit System Recovery T1490 3 rules
Data Encrypted for Impact T1486 2 rules
- Antivirus Ransomware Detection test
- macOS Encryption Tool Usage experimental
Service Stop T1489 2 rules
- macOS Service Disruption Activity experimental
- Mass Process Termination experimental
System Shutdown/Reboot T1529 2 rules
- macOS Service Disruption Activity experimental
- System Shutdown/Reboot - MacOs test
Data Destruction T1485 1 rule
- macOS Data Destruction Tools experimental
Data Manipulation: Stored Data Manipulation T1565.001 1 rule
- macOS Encryption Tool Usage experimental
No specific technique 1 rule
Untagged
- macOS ULS Gatekeeper Block (spctl) experimental
- macOS ULS Potential TCC Bypass Indicators experimental
- macOS ULS Quarantine or XProtect Detection experimental
- macOS ULS securityd CodeSignature Failure experimental
- macOS ULS Sudo Execution Logged experimental
- macOS ULS TCC Access Denied experimental
AWS
Reconnaissance
No specific technique 1 rule
- Many Recon Events test
Resource Development
Initial Access
No specific technique 3 rules
- Failed Console Login test
- Many Failed Logins test
- New AWS Lambda Function URL Configuration Created experimental
Execution
Persistence
Account Manipulation T1098 4 rules
Implant Internal Image T1525 1 rule
No specific technique 2 rules
- AWS EnableRegion Command Monitoring experimental
- Ingress Port 22 Opened test
Privilege Escalation
No specific technique 3 rules
Stealth
Valid Accounts: Cloud Accounts T1078.004 12 rules
- Attempt To Get Credentials For Identity experimental
- Attempt To Get Federation Token experimental
- Attempt To Get Signin Token experimental
- AWS IAM S3Browser LoginProfile Creation test
- AWS IAM S3Browser Templated S3 Bucket Policy Creation test
- AWS IAM S3Browser User or AccessKey Creation test
- AWS Root Credentials test
- AWS SAML Provider Deletion Activity experimental
- AWS Successful Console Login Without MFA experimental
- Get Credentials For Identity experimental
- Get Federation Token experimental
- Get Signin Token experimental
Valid Accounts T1078 4 rules
- AWS Key Pair Import Activity experimental
- AWS Suspicious SAML Activity test
- Console Login With MFA test
- Console Login Without MFA test
Indicator Removal T1070 1 rule
No specific technique 2 rules
- AWS Bucket Deleted experimental
- AWS VPC Flow Logs Deleted experimental
Defense Impairment
Disable or Modify Tools T1685 2 rules
Credential Access
Credentials from Password Stores T1555 2 rules
- EC2 Password Data Retrieved test
- PUA - AWS TruffleHog Execution experimental
OS Credential Dumping T1003 1 rule
- PUA - AWS TruffleHog Execution experimental
Brute Force T1110 1 rule
- AWS ConsoleLogin Failed Authentication experimental
Discovery
Account Discovery: Cloud Account T1087.004 3 rules
- AWS STS GetCallerIdentity Enumeration Via TruffleHog experimental
- Role Enumeration test
- User Enumeration test
No specific technique 1 rule
- Get Caller Identity test
Lateral Movement
Collection
Command & Control
No specific technique 1 rule
Exfiltration
Automated Exfiltration T1020 3 rules
No specific technique 1 rule
Impact
Account Access Removal T1531 3 rules
Data Destruction T1485 2 rules
Data Encrypted for Impact T1486 2 rules
- AWS EC2 Disable EBS Encryption stable
- AWS KMS Imported Key Material Usage experimental
Data Manipulation T1565 1 rule
No specific technique 1 rule
Azure
Reconnaissance
Execution
No specific technique 2 rules
- Public IP Created test
- Virtual Machine Created test
Persistence
Account Manipulation T1098 4 rules
No specific technique 3 rules
Privilege Escalation
No specific technique 1 rule
Stealth
Valid Accounts T1078 28 rules
- Account Created And Deleted Within A Close Time Frame test
- Activity From Anonymous IP Address test
- Application Using Device Code Authentication Flow test
- Applications That Are Using ROPC Authentication Flow test
- Atypical Travel test
- Authentications To Important Apps Using Single Factor Authentication test
- Azure AD Threat Intelligence test
- Azure Domain Federation Settings Modified test
- Azure Kubernetes Admission Controller test
- Azure Subscription Permission Elevation Via AuditLogs test
- Azure Unusual Authentication Interruption test
- Guest Users Invited To Tenant By Non Approved Inviters test
- Impossible Travel test
- Increased Failed Authentications Of Any Type test
- Invalid PIM License test
- Measurable Increase Of Successful Authentications test
- New Country test
- PIM Alert Setting Changes To Disabled test
- Roles Activated Too Frequently test
- Roles Activation Doesn't Require MFA test
- Roles Are Not Being Used test
- Roles Assigned Outside PIM test
- Stale Accounts In A Privileged Role test
- Suspicious Browser Activity test
- Suspicious SignIns From A Non Registered Device test
- Too Many Global Admins test
- Unfamiliar Sign-In Properties test
- User Added to an Administrator's Azure AD Role test
Valid Accounts: Cloud Accounts T1078.004 28 rules
- Account Disabled or Blocked for Sign in Attempts test
- Application AppID Uri Configuration Changes test
- Application URI Configuration Changes test
- Azure AD Only Single Factor Authentication Required test
- Azure Subscription Permission Elevation Via ActivityLogs test
- Bitlocker Key Retrieval test
- Changes To PIM Settings test
- Device Registration or Join Without MFA test
- Failed Authentications From Countries You Do Not Operate Out Of test
- Guest User Invited By Non Approved Inviters test
- Login to Disabled Account test
- Multifactor Authentication Denied test
- Multifactor Authentication Interrupted test
- Password Reset By User Account test
- PIM Approvals And Deny Elevation test
- Potential MFA Bypass Using Legacy Client Authentication test
- Privileged Account Creation test
- Sign-in Failure Due to Conditional Access Requirements Not Met test
- Sign-ins by Unknown Devices test
- Sign-ins from Non-Compliant Devices test
- Successful Authentications From Countries You Do Not Operate Out Of test
- Temporary Access Pass Added To An Account test
- Use of Legacy Authentication Protocols test
- User Access Blocked by Azure Conditional Access test
- User Added To Privilege Role test
- User State Changed From Guest To Member test
- Users Added to Global or Device Admin Roles test
- Users Authenticating To Other Azure AD Tenants test
No specific technique 3 rules
Defense Impairment
Modify Authentication Process T1556 8 rules
- CA Policy Removed by Non Approved Actor test
- CA Policy Updated by Non Approved Actor test
- Certificate-Based Authentication Enabled test
- Change to Authentication Method test
- Disabled MFA to Bypass Authentication Mechanisms test
- New Root Certificate Authority Added test
- User Added To Group With CA Policy Modification Access test
- User Removed From Group With CA Policy Modification Access test
Credential Access
Brute Force T1110 10 rules
- Account Lockout test
- Failed Authentications From Countries You Do Not Operate Out Of test
- Multifactor Authentication Denied test
- Multifactor Authentication Interrupted test
- Password Spray Activity test
- Potential MFA Bypass Using Legacy Client Authentication test
- Sign-in Failure Due to Conditional Access Requirements Not Met test
- Successful Authentications From Countries You Do Not Operate Out Of test
- Use of Legacy Authentication Protocols test
- User Access Blocked by Azure Conditional Access test
Unsecured Credentials T1552 2 rules
Adversary-in-the-Middle T1557 1 rule
- Azure Sign-In With Axios User Agent experimental
Forge Web Credentials T1606 1 rule
No specific technique 1 rule
Discovery
Collection
Command & Control
Impact
Data Destruction T1485 8 rules
- Azure Container Registry Created or Deleted test
- Azure Device or Configuration Modified or Deleted test
- Azure Kubernetes Cluster Created or Deleted test
- Azure Kubernetes Network Policy Change test
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted test
- Azure Kubernetes Secret or Config Object Access test
- Azure Kubernetes Sensitive Role Access test
- Azure Kubernetes Service Account Modified or Deleted test
Service Stop T1489 8 rules
- Azure Application Deleted test
- Azure Container Registry Created or Deleted test
- Azure Kubernetes Cluster Created or Deleted test
- Azure Kubernetes Network Policy Change test
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted test
- Azure Kubernetes Secret or Config Object Access test
- Azure Kubernetes Sensitive Role Access test
- Azure Kubernetes Service Account Modified or Deleted test
Resource Hijacking T1496 7 rules
- Azure Container Registry Created or Deleted test
- Azure Kubernetes Cluster Created or Deleted test
- Azure Kubernetes Network Policy Change test
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted test
- Azure Kubernetes Secret or Config Object Access test
- Azure Kubernetes Sensitive Role Access test
- Azure Kubernetes Service Account Modified or Deleted test
No specific technique 11 rules
- Azure Application Gateway Modified or Deleted test
- Azure Application Security Group Modified or Deleted test
- Azure Device No Longer Managed or Compliant test
- Azure Firewall Rule Configuration Modified or Deleted test
- Azure Kubernetes Pods Deleted test
- Azure Network Security Configuration Modified or Deleted test
- Azure Point-to-site VPN Modified or Deleted test
- Azure Suppression Rule Created test
- Azure Virtual Network Device Modified or Deleted test
- Azure Virtual Network Modified or Deleted test
- Azure VPN Connection Modified or Deleted test
GCP
Execution
No specific technique 1 rule
Persistence
Account Manipulation T1098 1 rule
No specific technique 1 rule
Privilege Escalation
No specific technique 1 rule
Stealth
Defense Impairment
Credential Access
No specific technique 2 rules
Discovery
No specific technique 1 rule
Collection
Impact
No specific technique 5 rules
Microsoft 365
Initial Access
Phishing: Spearphishing Attachment T1566.001 1 rule
- Suspicious Email Delivered In Microsoft 365 experimental
Phishing: Spearphishing Link T1566.002 1 rule
- Suspicious Email Delivered In Microsoft 365 experimental
Persistence
Stealth
Valid Accounts T1078 3 rules
Defense Impairment
Collection
Email Collection T1114 2 rules
Command & Control
Exfiltration
Automated Exfiltration T1020 2 rules
No specific technique 1 rule
Impact
No specific technique 1 rule
Google Workspace
Persistence
Account Manipulation T1098 2 rules
Stealth
Valid Accounts T1078 1 rule
- Google Workspace Government Attack Warning experimental
Collection
Impact
No specific technique 4 rules
Okta
Resource Development
Initial Access
Phishing T1566 1 rule
Persistence
No specific technique 2 rules
Stealth
Defense Impairment
Credential Access
No specific technique 4 rules
Command & Control
No specific technique 1 rule
Impact
No specific technique 7 rules
GitHub
Initial Access
Persistence
No specific technique 1 rule
- GitHub Repository Archive Status Changed experimental
Stealth
Defense Impairment
Disable or Modify Tools T1685 3 rules
No specific technique 1 rule
- GitHub Repository Archive Status Changed experimental
Discovery
Collection
Exfiltration
Automated Exfiltration T1020 2 rules
Impact
No specific technique 1 rule
- GitHub Repository Archive Status Changed experimental
Kubernetes
Execution
No specific technique 1 rule
Persistence
No specific technique 1 rule
Privilege Escalation
Escape to Host T1611 2 rules
No specific technique 3 rules
Stealth
Indicator Removal T1070 1 rule
Credential Access
No specific technique 1 rule
Discovery
Container and Resource Discovery T1613 1 rule
- Kubernetes Potential Enumeration Activity experimental
Impact
Network
Reconnaissance
Initial Access
No specific technique 3 rules
Execution
Scheduled Task/Job: At T1053.002 2 rules
Scheduled Task/Job T1053 1 rule
No specific technique 1 rule
Persistence
Create Account: Local Account T1136.001 3 rules
- Cisco Local Accounts test
- FortiGate - New Administrator Account Created experimental
- FortiGate - New Local User Created experimental
External Remote Services T1133 2 rules
- FortiGate - New VPN SSL Web Portal Added experimental
- FortiGate - VPN SSL Settings Modified experimental
Account Manipulation T1098 1 rule
- Cisco Local Accounts test
No specific technique 1 rule
- FortiGate - User Group Modified experimental
Privilege Escalation
No specific technique 2 rules
- Exploitation Indicators Of CVE-2023-20198 test
- FortiGate - User Group Modified experimental
Stealth
Valid Accounts T1078 4 rules
No specific technique 1 rule
Defense Impairment
Disable or Modify Tools T1685 4 rules
- Cisco Disabling Logging test
- Cisco Dot1x Disabled experimental
- FortiGate - Firewall Address Object Added experimental
- FortiGate - New Firewall Policy Added experimental
Credential Access
Brute Force T1110 4 rules
Adversary-in-the-Middle T1557 4 rules
Forced Authentication T1187 2 rules
Network Sniffing T1040 1 rule
- Cisco Sniffing test
No specific technique 2 rules
Discovery
Remote System Discovery T1018 1 rule
- Cisco Discovery test
System Owner/User Discovery T1033 1 rule
- Cisco Discovery test
Process Discovery T1057 1 rule
- Cisco Discovery test
System Information Discovery T1082 1 rule
- Cisco Discovery test
File and Directory Discovery T1083 1 rule
- Cisco Discovery test
System Time Discovery T1124 1 rule
- Cisco Discovery test
Password Policy Discovery T1201 1 rule
- Cisco Discovery test
Lateral Movement
Collection
Data from Local System T1005 1 rule
- Cisco Collect Data test
Data Staged T1074 1 rule
- Cisco Stage Data test
No specific technique 1 rule
Command & Control
Application Layer Protocol: Web Protocols T1071.001 2 rules
- Katz Stealer Suspicious User-Agent experimental
- Wannacry Killswitch Domain test
Ingress Tool Transfer T1105 2 rules
- Cisco Stage Data test
- Executable from Webdav test
Non-Standard Port T1571 1 rule
No specific technique 3 rules
Exfiltration
Impact
Resource Hijacking T1496 2 rules
Firmware Corruption T1495 1 rule
System Shutdown/Reboot T1529 1 rule
Web
Reconnaissance
Active Scanning T1595 1 rule
- Potential Hello-World Scraper Botnet Activity experimental
Resource Development
Initial Access
Exploit Public-Facing Application T1190 10 rules
- Apache Threading Error test
- F5 BIG-IP iControl Rest API Command Execution - Proxy test
- F5 BIG-IP iControl Rest API Command Execution - Webserver test
- Hack Tool User Agent test
- Java Payload Strings test
- JNDIExploit Pattern test
- Path Traversal Exploitation Attempts test
- SQL Injection Strings In URI test
- Successful IIS Shortname Fuzzing Scan test
- Suspicious User-Agents Related To Recon Tools test
Phishing T1566 3 rules
Execution
Persistence
Stealth
BITS Jobs T1197 2 rules
Credential Access
Brute Force T1110 1 rule
- Hack Tool User Agent test
Discovery
Lateral Movement
Collection
Command & Control
Application Layer Protocol: Web Protocols T1071.001 18 rules
- APT User Agent test
- Bitsadmin to Uncommon IP Server Address test
- Bitsadmin to Uncommon TLD test
- Crypto Miner User Agent test
- Exploit Framework User Agent test
- HackTool - BabyShark Agent Default URL Pattern test
- HackTool - CobaltStrike Malleable Profile Patterns - Proxy test
- HackTool - Empire UserAgent URI Combo test
- HTTP Request With Empty User Agent test
- Malware User Agent test
- Potential Base64 Encoded User-Agent test
- PwnDrp Access test
- Raw Paste Service Access test
- Suspicious Base64 Encoded User-Agent test
- Suspicious User Agent test
- Telegram API Access test
- Windows PowerShell User Agent test
- Windows WebDAV User Agent test
Web Service: Dead Drop Resolver T1102.001 2 rules
- PwnDrp Access test
- Raw Paste Service Access test
Exfiltration
Impact
Identity
Reconnaissance
No specific technique 1 rule
- Creation of large amount of unverified accounts experimental
Initial Access
Phishing T1566 1 rule
No specific technique 1 rule
- Successful Logins and Signups from Flagged IPs experimental
Persistence
Account Manipulation T1098 3 rules
Create Account T1136 3 rules
- Risk of signup fraud - rapid creation of fake accounts experimental
- Risk of signup fraud - rapid creation of fake accounts with disposable email domains experimental
- Risk of Tenant Takeover experimental
Privilege Escalation
Stealth
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 14 rules
- Attack protection features manipulation - some attack protection features have been disabled. experimental
- Bot detection - the feature is turned off completely or some policies. experimental
- Breached Password Detection - critical settings manipulated experimental
- Brute Force Protection - critical settings manipulated experimental
- Excessive or unexpected Management API scope grants on applications experimental
- Insecure OAuth2.x flows have been enabled for some applications experimental
- Loaded LiquidJS error page template contains XSS vulnerabilities experimental
- MFA downgrade - adaptive MFA risk assessment disabled experimental
- MFA downgrade - disable MFA policies by modifying the policies experimental
- MFA downgrade - disable strong factors experimental
- Risk for misconfiguration - use of Auth0 tenant name URL. experimental
- Suspicious IP Throttling - critical settings manipulated experimental
- Unauthorized or Unexpected Enabling of Cross-Origin Authentication (CORS) experimental
- Unrecognized IP in attack protection allowlists experimental
Valid Accounts T1078 3 rules
- Refresh Token Exchange from Excessive Locations experimental
- Refresh Token Exchange from Multiple User Agents experimental
- Refresh Token Reuse Detection experimental
Credential Access
Brute Force: Credential Stuffing T1110.004 2 rules
- Credential stuffing sttack risk experimental
- Successful login correlated with suspicious JA4/JA3 TLS fingerprint experimental
Brute Force T1110 1 rule
No specific technique 2 rules
- Creation of large amount of unverified accounts experimental
- Successful Logins and Signups from Flagged IPs experimental
Lateral Movement
Impact
Endpoint Denial of Service: Service Exhaustion Flood T1499.002 1 rule
- MFA attack - bombarding a user with SMS for MFA experimental
No specific technique 2 rules
Application
Reconnaissance
Resource Development
Initial Access
Exploit Public-Facing Application T1190 84 rules
- ADSelfService Exploitation test
- Apache Spark Shell Command Injection - Weblogs test
- Arcadyan Router Exploitations test
- Atlassian Bitbucket Command Injection Via Archive API test
- Cisco ASA Exploitation Activity - Proxy experimental
- Cisco ASA FTD Exploit CVE-2020-3452 test
- Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195 test
- Citrix Netscaler Attack CVE-2019-19781 test
- Confluence Exploitation CVE-2019-3398 test
- CVE-2010-5278 Exploitation Attempt test
- CVE-2020-0688 Exchange Exploitation via Web Log test
- CVE-2020-0688 Exploitation Attempt test
- CVE-2020-10148 SolarWinds Orion API Auth Bypass test
- CVE-2020-5902 F5 BIG-IP Exploitation Attempt test
- CVE-2021-21972 VSphere Exploitation test
- CVE-2021-21978 Exploitation Attempt test
- CVE-2021-33766 Exchange ProxyToken Exploitation test
- CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit test
- CVE-2021-41773 Exploitation Attempt test
- CVE-2022-31656 VMware Workspace ONE Access Auth Bypass test
- CVE-2022-31659 VMware Workspace ONE Access RCE test
- CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer AX21 test
- CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy) test
- CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver) test
- CVE-2023-46747 Exploitation Activity - Proxy test
- CVE-2023-46747 Exploitation Activity - Webserver test
- CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy test
- CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver test
- CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy test
- CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver test
- Django Framework Exceptions stable
- Exchange Exploitation CVE-2021-28480 test
- Exchange Exploitation Used by HAFNIUM test
- Exchange ProxyShell Pattern test
- Exploitation of CVE-2021-26814 in Wazuh test
- Fortinet CVE-2018-13379 Exploitation test
- Fortinet CVE-2021-22123 Exploitation test
- Grafana Path Traversal Exploitation CVE-2021-43798 test
- Log4j RCE CVE-2021-44228 Generic test
- Log4j RCE CVE-2021-44228 in Fields test
- OpenCanary - FTP Login Attempt test
- OpenCanary - HTTP GET Request test
- OpenCanary - HTTP POST Login Attempt test
- Oracle WebLogic Exploit test
- Oracle WebLogic Exploit CVE-2020-14882 test
- Oracle WebLogic Exploit CVE-2021-2109 test
- OWASSRF Exploitation Attempt Using Public POC - Proxy test
- OWASSRF Exploitation Attempt Using Public POC - Webserver test
- Potential Centos Web Panel Exploitation Attempt - CVE-2022-44877 test
- Potential CVE-2021-26084 Exploitation Attempt test
- Potential CVE-2021-27905 Exploitation Attempt test
- Potential CVE-2022-21587 Exploitation Attempt test
- Potential CVE-2022-46169 Exploitation Attempt test
- Potential CVE-2023-23752 Exploitation Attempt test
- Potential CVE-2023-25717 Exploitation Attempt test
- Potential CVE-2023-27997 Exploitation Indicators test
- Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE experimental
- Potential Information Disclosure CVE-2023-43261 Exploitation - Proxy test
- Potential Information Disclosure CVE-2023-43261 Exploitation - Web test
- Potential JNDI Injection Exploitation In JVM Based Application test
- Potential Local File Read Vulnerability In JVM Based Application test
- Potential OGNL Injection Exploitation In JVM Based Application test
- Potential OWASSRF Exploitation Attempt - Proxy test
- Potential OWASSRF Exploitation Attempt - Webserver test
- Potential RCE Exploitation Attempt In NodeJS test
- Potential SAP NetViewer Webshell Command Execution experimental
- Potential Server Side Template Injection In Velocity test
- Potential SpEL Injection In Spring Framework test
- Potential XXE Exploitation Attempt In JVM Based Application test
- Process Execution Error In JVM Based Application test
- ProxyLogon Reset Virtual Directories Based On IIS Log test
- Pulse Connect Secure RCE Attack CVE-2021-22893 stable
- Pulse Secure Attack CVE-2019-11510 test
- Python SQL Exceptions stable
- Rejetto HTTP File Server RCE test
- Ruby on Rails Framework Exceptions stable
- SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS experimental
- Sitecore Pre-Auth RCE CVE-2021-42237 test
- SonicWall SSL/VPN Jarrewrite Exploitation test
- Spring Framework Exceptions stable
- Suspicious SQL Error Messages test
- TerraMaster TOS CVE-2020-28188 test
- VMware vCenter Server File Upload CVE-2021-22005 test
- Zimbra Collaboration Suite Email Server Unauthenticated RCE test
No specific technique 7 rules
- .Class Extension URI Ending Request test
- CVE-2024-1212 Exploitation - Progress Kemp LoadMaster Unauthenticated Command Injection test
- CVE-2024-1709 - ScreenConnect Authentication Bypass Exploitation test
- Exploitation Indicator Of CVE-2022-42475 test
- Potential CVE-2023-25157 Exploitation Attempt test
- Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection test
- Successful Exchange ProxyShell Attack test
Execution
Scheduled Task/Job: At T1053.002 3 rules
No specific technique 1 rule
Persistence
Server Software Component: Web Shell T1505.003 8 rules
- CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit test
- DEWMODE Webshell Access test
- MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request test
- Oracle WebLogic Exploit test
- Potential Java WebShell Upload in SAP NetViewer Server experimental
- Potential SAP NetViewer Webshell Command Execution experimental
- Rejetto HTTP File Server RCE test
- Solarwinds SUPERNOVA Webshell Access test
External Remote Services T1133 4 rules
No specific technique 2 rules
Privilege Escalation
No specific technique 1 rule
Stealth
Valid Accounts T1078 3 rules
No specific technique 1 rule
Defense Impairment
Disable or Modify Tools T1685 6 rules
Credential Access
OS Credential Dumping T1003 4 rules
Discovery
Network Service Discovery T1046 5 rules
- OpenCanary - Host Port Scan (SYN Scan) experimental
- OpenCanary - NMAP FIN Scan experimental
- OpenCanary - NMAP NULL Scan experimental
- OpenCanary - NMAP OS Scan experimental
- OpenCanary - NMAP XMAS Scan experimental
No specific technique 5 rules
Lateral Movement
Remote Services T1021 6 rules
Remote Services: SSH T1021.004 2 rules
Remote Services: Remote Desktop Protocol T1021.001 1 rule
- OpenCanary - RDP New Connection Attempt experimental
No specific technique 3 rules
Collection
Data from Information Repositories T1213 7 rules
- Bitbucket User Details Export Attempt Detected test
- Bitbucket User Permissions Export Attempt test
- OpenCanary - GIT Clone Request test
- OpenCanary - MSSQL Login Attempt Via SQLAuth test
- OpenCanary - MSSQL Login Attempt Via Windows Authentication test
- OpenCanary - MySQL Login Attempt test
- OpenCanary - REDIS Action Command Attempt test
Audio Capture T1123 1 rule
Command & Control
Application Layer Protocol: DNS T1071.004 2 rules
- DNS Query To Katz Stealer Domains - Network experimental
- Low Reputation Effective Top-Level Domain (eTLD) experimental
Proxy T1090 1 rule
Dynamic Resolution T1568 1 rule
- Axios NPM Compromise Malicious C2 Domain DNS Query experimental
No specific technique 12 rules
- Devil Bait Potential C2 Communication Traffic test
- Goofy Guineapig Backdoor Potential C2 Communication test
- Potential Compromised 3CXDesktopApp Beaconing Activity - Proxy test
- Potential Compromised 3CXDesktopApp ICO C2 File Download test
- Potential CVE-2023-36884 Exploitation - File Downloads test
- Potential CVE-2023-36884 Exploitation - URL Marker test
- Potential CVE-2023-36884 Exploitation Pattern test
- Potential CVE-2303-36884 URL Request Pattern Traffic test
- Potential Operation Triangulation C2 Beaconing Activity - DNS test
- Potential Operation Triangulation C2 Beaconing Activity - Proxy test
- Potential Peach Sandstorm APT C2 Communication Activity test
- Small Sieve Malware Potential C2 Communication test