Skip to content

Security Alerts Rules

9 detection rules in this category.

RuleSeverityMITRESource
Command and controlCriticalT1071SecurityAlert
Credential theft activityCriticalT1003SecurityAlert
Data exfiltrationCriticalT1567SecurityAlert
High severity security alertCriticalVariousSecurityAlert
Lateral movementCriticalT1021SecurityAlert
Malware detectedCriticalT1204.002SecurityAlert
Medium severity security alertHighVariousSecurityAlert
Privilege escalationCriticalT1068SecurityAlert
Ransomware activityCriticalT1486SecurityAlert

Command and control

PropertyValue
Severity🔴 Critical
SourceSecurityAlert
MITRET1071 (Command and Control)

Command and control activity detected

Conditions
  • Match: all
  • category Contains CommandAndControl

Credential theft activity

PropertyValue
Severity🔴 Critical
SourceSecurityAlert
MITRET1003 (Credential Access)

Credential theft activity detected

Conditions
  • Match: all
  • category Contains CredentialAccess

Data exfiltration

PropertyValue
Severity🔴 Critical
SourceSecurityAlert
MITRET1567 (Exfiltration)

Potential data exfiltration detected

Conditions
  • Match: all
  • category Contains Exfiltration

High severity security alert

PropertyValue
Severity🔴 Critical
SourceSecurityAlert
MITREVarious (Multiple)

High severity Microsoft Defender alert

Conditions
  • Match: all
  • severity Equals high

Lateral movement

PropertyValue
Severity🔴 Critical
SourceSecurityAlert
MITRET1021 (Lateral Movement)

Lateral movement detected

Conditions
  • Match: all
  • category Contains LateralMovement

Malware detected

PropertyValue
Severity🔴 Critical
SourceSecurityAlert
MITRET1204.002 (Execution)

Malware detected by Microsoft Defender

Conditions
  • Match: all
  • category Contains Malware

Medium severity security alert

PropertyValue
Severity🟠 High
SourceSecurityAlert
MITREVarious (Multiple)

Medium severity Microsoft Defender alert

Conditions
  • Match: all
  • severity Equals medium

Privilege escalation

PropertyValue
Severity🔴 Critical
SourceSecurityAlert
MITRET1068 (Privilege Escalation)

Privilege escalation detected

Conditions
  • Match: all
  • category Contains PrivilegeEscalation

Ransomware activity

PropertyValue
Severity🔴 Critical
SourceSecurityAlert
MITRET1486 (Impact)

Potential ransomware activity detected

Conditions
  • Match: all
  • category Contains Ransomware