Browse Rules

Search and filter across all detection sources

17 rules

anvilogic high spl

Auth0: MFA Device Update Failure [splunk-auth0]

Threat actors may use attempt to bypass MFA or establish persistence by linking a controlled device to a compromised account. This use case detects failed device authorization (fdeaz) and failed device activation (fdeac), which could indicate attempts to enroll a new device being blocked by security controls.

elastic low kql

New USB Storage Device Mounted

Identifies newly seen removable devices by device.serial_number and host.id using the Elastic Defend device mount events. While this activity is not inherently malicious, analysts can use those events to aid monitoring for data exfiltration over those devices.

anvilogic high spl

Auth0: MFA Device Updated [splunk-auth0]

Threat actors may update MFA device settings to replace the legitimate user’s authentication method with one they control, ensuring persistent access. This use case detects updates to MFA devices, which could indicate an attacker modifying authentication factors after compromising an account.

anvilogic high spl

Auth0: Device Rejected by User [splunk-auth0]

Threat actors may attempt to enroll a new MFA device but fail to complete the confirmation step, either due to security controls or lack of access to the legitimate user’s approval method. This use case detects instances where a user did not confirm a device enrollment, which could indicate an attacker trying to register an unauthorized MFA device.

elastic medium kql

Entra ID OAuth Device Code Grant by Microsoft Authentication Broker

Identifies device code authentication with an Azure broker client for Entra ID. Adversaries abuse Primary Refresh Tokens (PRTs) to bypass multi-factor authentication (MFA) and gain unauthorized access to Azure resources. PRTs are used in Conditional Access policies to enforce device-based controls. Compromising PRTs allows attackers to bypass these policies and gain unauthorized access. This rule detects successful sign-ins using device code authentication with the Entra ID broker client applica

elastic medium kql

Quick Assist Full Control Sharing Mode Enabled

Identifies when Microsoft Quick Assist sharing mode is set to FullControl on a Windows host. This grants the remote helper full interactive control of the target device and may indicate IT help desk fraud, unauthorized remote access, or lateral movement preparation.

anvilogic high spl

Auth0: MFA Enrollment Started [splunk-auth0]

Threat actors may attempt to enroll their own MFA device on a compromised account to establish persistence and bypass authentication controls. This use case detects the initiation of a new MFA enrollment, which could indicate legitimate user setup or an attacker attempting to register an unauthorized authentication method.

elastic high eql

Google Workspace Device Registration After OAuth from Suspicious ASN

Detects when a Google Workspace account completes OAuth authorization for a specific Google OAuth client from a high-risk autonomous system number (ASN), followed within 30 seconds by a device registration event with account state REGISTERED. This sequence can indicate device enrollment or join flows initiated from attacker-controlled or residential-proxy infrastructure after a user authorizes a sensitive client.

elastic medium eql

FortiGate Super Admin Account Creation

This rule detects the creation of an administrator account on a FortiGate device. Administrator account creation on these devices should be infrequent and tightly controlled. In the FG-IR-26-060 campaign, threat actors created super_admin accounts immediately after gaining initial access via FortiCloud SSO bypass to establish persistence.

anvilogic high spl

Auth0: MFA Enrollment Failed [splunk-auth0]

Threat actors may attempt to enroll a new MFA device on a compromised account but fail due to security controls, user intervention, or misconfiguration. This use case detects failed MFA enrollment attempts, which could indicate an attacker trying to register an unauthorized authentication method or issues with legitimate user enrollment.

anvilogic high spl

Auth0: WebAuthn Enrollment Failed [splunk-auth0]

Threat actors may attempt to enroll a rogue WebAuthn device on a compromised account but fail due to security controls, misconfiguration, or lack of proper credentials. This use case detects failed WebAuthn enrollment attempts, which could indicate an attacker attempting to register an unauthorized authentication method or legitimate user enrollment issues.

anvilogic high spl

Auth0: WebAuthn MFA Fail [splunk-auth0]

Threat actors may attempt to bypass WebAuthn-based MFA but fail due to incorrect credentials, lack of access to the required device, or security controls preventing authentication. This use case detects failed WebAuthn verification attempts, which could indicate an attacker attempting to gain unauthorized access or a legitimate user experiencing authentication issues.

anvilogic high spl

File Executed from INetCache [splunk-edr]

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer). This use case detects when a file was executed from the C:\Users\<user>\App

anvilogic high spl

File Executed from INetCache [splunk-sysmon]

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer). This use case detects when a file was executed from the C:\Users\<user>\App

elastic high kql

Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN

Detects Microsoft Entra ID sign-in activity where the Microsoft Authentication Broker requests the Device Registration Service from a source autonomous system number (ASN) associated with VPN, residential proxy, or hosting egress commonly observed in OAuth phishing and adversary-in-the-middle device registration flows. This pattern can indicate device join or primary refresh token acquisition staged from attacker-controlled infrastructure after a user completes authentication.

anvilogic high spl

File Executed from INetCache [splunk-winevent]

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer). This use case detects when a file was executed from the C:\Users\<user>\App

elastic low kql

Newly Observed IPSEC NAT Traversal Peer

This rule identifies outbound IPSEC NAT Traversal (NAT-T) traffic to an external destination IP that was not observed during the previous 5 days. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal encapsulates IPSEC ESP traffic in UDP and, once a NAT device is detected, both peers float to UDP port 4500 for the tunnel data channel. Newly observed external NAT-T peers may indicate unauthorized VPN use or an adversary tunneling command and co