Detection Engineering Rule Hub
Curated, production-tested detection logic in Sigma (YAML), Splunk SPL, Microsoft Sentinel KQL, Elastic EQL, and Falcon LogScale. Every rule is directly mapped to MITRE ATT&CK techniques and verified from primary court filings.
Identity Provider Help Desk MFA Reset & IdP Tampering
Detects help desk initiated reset of multi-factor authentication factors followed rapidly by administrator session activity or identity federation changes.
title: Identity Provider Admin MFA Reset Followed By Session Creation
status: production
description: Detects help desk initiated reset of administrator MFA tokens in Okta/Entra ID.
logsource:
service: okta
detection:
selection_reset:
eventType:
- 'user.mfa.factor.reset'
- 'user.mfa.factor.deactivate'
selection_target:
target.alternateId|endswith: '@domain.com'
condition: selection_reset and selection_target
level: high VMware ESXi Hypervisor Encryption Script Execution
Detects execution of shell scripts or native Linux binaries targeting VMware ESXi datastores (/vmfs/volumes) to encrypt virtual disks (.vmdk) and terminate VM processes.
title: ESXi Hypervisor Mass Virtual Machine Process Kill and Encryption
status: production
description: Detects command line kill of ESXi vmx processes and bulk file encryption.
logsource:
category: process_creation
product: linux
detection:
selection_kill:
CommandLine|contains:
- 'esxcli vm process kill'
- 'killall -9 vmx'
- '/vmfs/volumes'
condition: selection_kill
level: critical Citrix NetScaler ADC Session Hijack & Memory Dump (CVE-2023-4966)
Detects HTTP GET requests to vulnerable Citrix NetScaler /oauth/idp endpoints generating oversized HTTP response payloads containing dumped process memory and session tokens.
title: Citrix NetScaler ADC Bleed Memory Leak Exploitation (CVE-2023-4966)
status: production
description: Identifies attempts to exploit CVE-2023-4966 on Citrix ADC gateways.
logsource:
category: webserver
detection:
selection:
cs-method: 'GET'
cs-uri-stem|startswith: '/oauth/idp/.well-known/openid-configuration'
condition: selection
level: critical Cloud Data Exfiltration via Rclone / MegaSync Tools
Detects command-line execution of known cloud storage synchronization utilities such as rclone, megasync, or customized curl scripts transmitting bulk file archives.
title: Common Cloud Storage Tool Exfiltration Execution
status: production
description: Detects command lines invoking Rclone, Megasync, or AWS CLI with copy parameters.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\rclone.exe'
- '\megasync.exe'
CommandLine|contains:
- 'copy'
- 'sync'
- '--config'
condition: selection
level: high Volume Shadow Copy & Windows Backup Deletion
Detects invocations of vssadmin.exe, wmic.exe, or bcdedit.exe used by ransomware operators to inhibit system recovery prior to encryption.
title: Shadow Copies Deletion Using Operating System Utilities
status: production
description: Detects execution of vssadmin or wmic commands used to delete volume shadow copies.
logsource:
category: process_creation
product: windows
detection:
selection_vss:
CommandLine|contains|all:
- 'vssadmin'
- 'delete'
- 'shadows'
selection_wmic:
CommandLine|contains|all:
- 'shadowcopy'
- 'delete'
condition: selection_vss or selection_wmic
level: critical