Browse Rules

Search and filter across all detection sources

201 rules

sentinel medium kql

Google Threat Intelligence - Threat Hunting Domain

'Google Threat Intelligence domain correlation.'

sentinel medium kql

Google Threat Intelligence - Threat Hunting Hash

'Google Threat Intelligence hash correlation.'

sentinel medium kql

Google Threat Intelligence - Threat Hunting IP

'Google Threat Intelligence IP correlation.'

sentinel medium kql

Google Threat Intelligence - Threat Hunting Url

'Google Threat Intelligence Url correlation.'

panther high python

OTX Threat Intelligence Indicator Match

Detects when an IP address in any log event matches a known threat indicator from AlienVault OTX pulse intelligence. Severity is elevated when the pulse includes a named adversary or known malware families.

panther high python

GTI/VirusTotal Threat Intelligence Indicator Match

Detects when an IP address, domain, or file hash in any log event matches a known malicious indicator from Google Threat Intelligence (GTI) / VirusTotal enrichment. Severity is elevated based on GTI's threat severity verdict and the number of vendors flagging the indicator as malicious.

sentinel high kql

Google SecOps - GCTI Threat Intelligence Finding

Creates incidents in Microsoft Sentinel when Google Security Operations raises an active threat intelligence alert (GCTI_FINDING). These alerts are generated by Google's global threat intel corpus and represent high-confidence threats, distinct from customer-authored rule detections.

elastic low kql

M365 Threat Intelligence Signal

Identifies Microsoft 365 audit logs generated for Threat Intelligence signals by Microsoft Defender for Office 365. This includes phishing and malware events, campaign-related threat detections, file-based threats in SharePoint, OneDrive, and Teams, as well as Microsoft Threat Intelligence Center (MSTIC) signals. These events provide early indicators of compromise attempts and can be correlated with other signals for threat hunting and detection.

sentinel medium kql

Commvault Cloud Alert

'This query identifies Alerts from Commvault Cloud.'

hayabusa high sigma

GALLIUM Artefacts - Builtin

Detects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.

sigma high sigma

GALLIUM Artefacts - Builtin

Detects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.

bertjanp unknown kql

SignIn From Suspicious IP

This query combines threat intelligence feeds with Entra ID sign-in information.

sigma high sigma

GALLIUM IOCs

Detects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.

sentinel medium kql

Lumen TI domain in DnsEvents

This query searches for matches between Lumen threat intelligence domain indicators and DnsEvents.

elastic medium kql

AWS GuardDuty Threat Intelligence Set Deleted

Detects the deletion of an Amazon GuardDuty threat intelligence set. Threat intelligence sets are custom lists of known-malicious IP addresses or domains that GuardDuty uses to generate findings when monitored resources communicate with those indicators. Deleting a threat intel set degrades GuardDuty's detection capability for known adversary infrastructure, allowing communication with threat-actor-controlled IP ranges to go undetected.

hayabusa high sigma

GALLIUM IOCs

Detects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.

sigma high sigma

Azure AD Threat Intelligence

Indicates user activity that is unusual for the user or consistent with known attack patterns.

sentinel informational kql

Speculus - Threat intelligence feed outage

'Detects when no Speculus threat intelligence indicators have been received for more than 24 hours. The Speculus indexer refreshes continuously, so a silent day usually means an expired API key, a connector misconfiguration, or a feed-side outage rather than an empty feed.'

sentinel medium kql

Dataverse - TI map IP to DataverseActivity

Identifies a match in DataverseActivity from any IP IOC from Microsoft Sentinel Threat Intelligence.

sentinel medium kql

Dataverse - TI map URL to DataverseActivity

Identifies a match in DataverseActivity from any URL IOC from Microsoft Sentinel Threat Intelligence.

sigma high sigma

Potentially Suspicious Malware Callback Communication - Linux

Detects programs that connect to known malware callback ports based on threat intelligence reports.

bertjanp unknown kql

Visualize the Threat Intelligence Indicators by day for the last 30 days

This query visualizes the amount of IOCs that have triggerd each day for the last 30 days in a timechart. This could indicate spikes in malicious activities by users or give intsights in the value of Threat Intelligence feeds.

panther high python

GreyNoise V3 Malicious IP Activity

Detects when an IP address in any log event is classified as malicious or unknown by GreyNoise V3 internet scanner intelligence. Known business services and benign IPs are excluded.

sentinel low kql

Cyble Vision Alerts Flash Report

'Detects new threat intelligence flash reports from CybleVision. Extracts company-level context and report identifiers for triage.'

sentinel medium kql

GSA - TI Domain Entity

This query identifies Domain indicators of compromise (IOCs) from threat intelligence (TI) by searching for matches in GSA NetworkAccessTraffic.