Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
4 rules
Potential Execution of DenoGate Backdoor via Microsoft Teams Delivery
mediumDetects suspicious execution of 'deno.exe' with indicators suggesting DenoGate backdoor, particularly when delivered through Microsoft Teams.
sigmaWindowsPaid2026-07-28Suspicious Use of Windows Quick Assist as Observed in UNC6692 Attacks
mediumDetects the execution of Quick Assist, as leveraged by UNC6692 for post-phishing IT impersonation and lateral movement.
sigmaWindowsPaid2026-07-28Potential Unauthorized Use of ATLAS AI SOC Customizations
mediumDetects when potentially unauthorized or risky customizations to ATLAS AI-driven SOC response workflows are made, which could indicate adversary abuse of automation.
sigmaWindowsPaid2026-07-28Microsoft Quick Assist Unsolicited Launch
mediumsigmaWindowsPaid2026-07-28