Browse Rules

Search and filter across all detection sources

133 rules

elastic low kql

Deprecated - Unusual Discovery Activity by User

This rule leverages alert data from various Discovery building block rules to alert on signals with unusual unique host.id and user.id entries.

elastic low eql

GitHub Repo Created

A new GitHub repository was created.

elastic low eql

GitHub PAT Access Revoked

Access to private GitHub organization resources was revoked for a PAT.

elastic low eql

GitHub User Blocked From Organization

A GitHub user was blocked from access to an organization.

elastic low eql

New User Added To GitHub Organization

A new user was added to a GitHub organization.

elastic low eql

Unusual Process Extension

Identifies processes running with unusual extensions that are not typically valid for Windows executables.

elastic low eql

Member Removed From GitHub Organization

A member was removed or their invitation to join was removed from a GitHub Organization.

elastic low kql

New Okta Authentication Behavior Detected

Detects events where Okta behavior detection has identified a new authentication behavior.

elastic low kql

System Network Connections Discovery

Adversaries may attempt to get a listing of network connections to or from a compromised system.

elastic low kql

Execution of an Unsigned Service

This rule identifies the execution of unsigned executables via service control manager (SCM). Adversaries may abuse SCM to execute malware or escalate privileges.

elastic low eql

Compression DLL Loaded by Unusual Process

Identifies the image load of a compression DLL. Adversaries will often compress and encrypt data in preparation for exfiltration.

elastic low eql

File with Suspicious Extension Downloaded

Identifies unusual files downloaded from outside the local network that have the potential to be abused for code execution.

elastic low eql

Archive File with Unusual Extension

Identifies the creation of an archive file with an unusual extension. Attackers may attempt to evade detection by masquerading files using the file extension values used by image, audio, or document file types.

elastic low eql

Memory Dump File with Unusual Extension

Identifies the creation of a memory dump file with an unusual extension, which can indicate an attempt to disguise a memory dump as another file type to bypass security defenses.

elastic low kql

First Occurrence of GitHub User Interaction with Private Repo

Detects a new private repo interaction for a GitHub user not seen in the last 14 days.

elastic low eql

Windows Account or Group Discovery

This rule identifies the execution of commands that enumerates account or group information. Adversaries may use built-in applications to get a listing of local system or domain accounts and groups.

elastic low kql

First Occurrence of IP Address For GitHub User

Detects a new IP address used for a GitHub user not previously seen in the last 14 days.

elastic low eql

Remote System Discovery Commands

Discovery of remote system information using built-in commands, which may be used to move laterally.

elastic low eql

Shortcut File Written or Modified on Startup Folder

Identifies shortcut files written to or modified in the startup folder. Adversaries may use this technique to maintain persistence.

elastic low eql

Executable File with Unusual Extension

Identifies the creation or modification of an executable file with an unexpected file extension. Attackers may attempt to evade detection by masquerading files using the file extension values used by image, audio, or document file types.

elastic low kql

Account or Group Discovery via Built-In Tools

Adversaries may use built-in applications to get a listing of local system or domain accounts and groups.

elastic low eql

Deprecated - Creation of Kernel Module

Identifies activity related to loading kernel modules on Linux via creation of new ko files in the LKM directory.

elastic low kql

First Occurrence GitHub Event for a Personal Access Token (PAT)

Detects a first occurrence event for a personal access token (PAT) not seen in the last 14 days.

elastic low kql

First Occurrence of User-Agent For a GitHub User

Detects a new user agent used for a GitHub user not previously seen in the last 14 days.

elastic low eql

Image Loaded with Invalid Signature

Identifies binaries that are loaded and with an invalid code signature. This may indicate an attempt to masquerade as a signed binary.