Filter Usecases
×Level
Threat Category
MITRE ATT&CK
Primary data source
Filter applied :
Platform: Windows × Clear all
1-20 of 1247
Rule Name
Level
MITRE ATT&CK
Category
Last Updated
Transfer Data to Cloud Account
L2 - Investigation
T1537
Threat Intel
Last updated: March 18, 2026
View detailsAccount Manipulation
L2 - Investigation
T1098
Threat Intel
Last updated: March 18, 2026
View detailsExploit Public-Facing Application
L1 – Triage
T1190
Database
Last updated: March 18, 2026
View detailsSigned Binary Proxy Execution
L2 – Investigation
T1218
Sysmon
Last updated: March 18, 2026
View detailsExploit Public-Facing Application
L1 – Triage
T1190
Vulnerability Scanner
Last updated: March 18, 2026
View detailsShadow IT Monitoring
L2 - Investigation
T1087, T1046
Cloud and SaaS
Last updated: September 15, 2025
View detailsSecurity analytics – Process hunting lineage
L2 - Investigation
T1087, T1046
Cloud and SaaS
Last updated: September 15, 2025
View detailsColumn integrity monitoring
L2 - Investigation
T1565.001
Application and Data
Last updated: September 15, 2025
View detailsDark web - Corporate IDs in SaaS apps
L1 - Triage
T1589
Identity and Access
Last updated: September 15, 2025
View detailsShort lived admin accounts
L1 - Triage
T1098
Identity and Access
Last updated: September 15, 2025
View detailsAudit tampering
L3 – Incident
T1562.002
Application and Data
Last updated: September 15, 2025
View detailsFirewall rule changes
L2 – Investigation
T1562.004
Network
Last updated: September 15, 2025
View detailsImpossible travel
L1 – Triage
T1078
Identity and Access
Last updated: September 15, 2025
View detailsPrivilege escalation through service account misuse
L3 – Incident
T1078.004
Identity and Access
Last updated: September 15, 2025
View detailsUnauthorized PowerShell remote session
L2 – Investigation
T1059.001
Endpoint
Last updated: September 15, 2025
View detailsCross-site scripting (XSS) leading to session theft
L3 – Incident
T1056
Application and Data
Last updated: September 15, 2025
View details

