Content pack

The detections shipped with the platform, by name and technique.

What ships

The content pack is a set of curated rules for common Windows and Linux techniques. Every rule is tagged with its ATT&CK technique and ships with test events that prove it fires. Import it from Detections › Import content pack; rules arrive disabled so you can enable those that match the sources you have.

RuleTechniqueNeeds
Encoded PowerShell commandT1059.001Windows process creation
LSASS memory accessT1003.001Sysmon
certutil downloadT1105Windows process creation
Scheduled task persistenceT1053.005Windows process creation or Security log
regsvr32 remote scriptT1218.010Windows process creation
WMIC process creationT1047Windows process creation
Local account addedT1136.001Windows Security log
Event log clearedT1070.001Windows Security log
Authentication brute forceT1110Windows Security log or Linux auth
KerberoastingT1558.003Windows Security log
Defender real-time protection disabledT1562.001Microsoft Defender
Admin share accessT1021.002Windows Security log
Office application spawns shellT1566.001Windows process creation
Linux pipe to shellT1059.004Linux auditd
Credential-dumping tool stringsT1003Windows process creation
Parent PID spoofingT1134.004Sysmon
Brute force followed by successT1110, T1078Windows Security log or Linux auth
Failed logons followed by service installT1110, T1543.003Windows Security log
Ransomware canary modifiedT1486Sysmon or auditd

The last three are sequence rules.

Tuning

Content-pack rules are a starting point. Expect to add exceptions for your environment's legitimate administration tooling in the first two weeks; see Exceptions and suppressions. The rule inspector's false-positive rate tells you which rules need attention.

Updates

New pack versions arrive with platform updates. Re-importing updates the rules and keeps your exceptions, bindings and enabled state. Rules you edited are shown as overridden and are not replaced.