BLUE TEAM DETECTION LAB

Detection Engineering Rule Hub

Curated, production-tested detection logic in Sigma (YAML), Splunk SPL, Microsoft Sentinel KQL, Elastic EQL, and Falcon LogScale. Every rule is directly mapped to MITRE ATT&CK techniques and verified from primary court filings.

T1078: Valid Accounts (Defense Evasion & Persistence)

Identity Provider Help Desk MFA Reset & IdP Tampering

Cloud / Identity Actor: Scattered Spider High

Detects help desk initiated reset of multi-factor authentication factors followed rapidly by administrator session activity or identity federation changes.

title: Identity Provider Admin MFA Reset Followed By Session Creation
status: production
description: Detects help desk initiated reset of administrator MFA tokens in Okta/Entra ID.
logsource:
    service: okta
detection:
    selection_reset:
        eventType:
            - 'user.mfa.factor.reset'
            - 'user.mfa.factor.deactivate'
    selection_target:
        target.alternateId|endswith: '@domain.com'
    condition: selection_reset and selection_target
level: high
Observed In Real-World Court Dossiers:

VMware ESXi Hypervisor Encryption Script Execution

Linux / ESXi Actor: ALPHV / BlackCat & LockBit Critical

Detects execution of shell scripts or native Linux binaries targeting VMware ESXi datastores (/vmfs/volumes) to encrypt virtual disks (.vmdk) and terminate VM processes.

title: ESXi Hypervisor Mass Virtual Machine Process Kill and Encryption
status: production
description: Detects command line kill of ESXi vmx processes and bulk file encryption.
logsource:
    category: process_creation
    product: linux
detection:
    selection_kill:
        CommandLine|contains:
            - 'esxcli vm process kill'
            - 'killall -9 vmx'
            - '/vmfs/volumes'
    condition: selection_kill
level: critical
Observed In Real-World Court Dossiers:

Citrix NetScaler ADC Session Hijack & Memory Dump (CVE-2023-4966)

Network / Gateway Actor: LockBit & Nation-State Affiliates Critical

Detects HTTP GET requests to vulnerable Citrix NetScaler /oauth/idp endpoints generating oversized HTTP response payloads containing dumped process memory and session tokens.

title: Citrix NetScaler ADC Bleed Memory Leak Exploitation (CVE-2023-4966)
status: production
description: Identifies attempts to exploit CVE-2023-4966 on Citrix ADC gateways.
logsource:
    category: webserver
detection:
    selection:
        cs-method: 'GET'
        cs-uri-stem|startswith: '/oauth/idp/.well-known/openid-configuration'
    condition: selection
level: critical
Observed In Real-World Court Dossiers:

Cloud Data Exfiltration via Rclone / MegaSync Tools

Windows / Linux Actor: BlackCat, LockBit, Scattered Spider High

Detects command-line execution of known cloud storage synchronization utilities such as rclone, megasync, or customized curl scripts transmitting bulk file archives.

title: Common Cloud Storage Tool Exfiltration Execution
status: production
description: Detects command lines invoking Rclone, Megasync, or AWS CLI with copy parameters.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith:
            - '\rclone.exe'
            - '\megasync.exe'
        CommandLine|contains:
            - 'copy'
            - 'sync'
            - '--config'
    condition: selection
level: high
Observed In Real-World Court Dossiers:

Volume Shadow Copy & Windows Backup Deletion

Windows Actor: All Major Ransomware Families Critical

Detects invocations of vssadmin.exe, wmic.exe, or bcdedit.exe used by ransomware operators to inhibit system recovery prior to encryption.

title: Shadow Copies Deletion Using Operating System Utilities
status: production
description: Detects execution of vssadmin or wmic commands used to delete volume shadow copies.
logsource:
    category: process_creation
    product: windows
detection:
    selection_vss:
        CommandLine|contains|all:
            - 'vssadmin'
            - 'delete'
            - 'shadows'
    selection_wmic:
        CommandLine|contains|all:
            - 'shadowcopy'
            - 'delete'
    condition: selection_vss or selection_wmic
level: critical
Observed In Real-World Court Dossiers: