IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Update v8.19.35

edit

This section lists all updates associated with version 8.19.35 of the Fleet integration Prebuilt Security Detection Rules.

Rule Description Status Version

AWS Audit or Security Service Tampering via CLI

Identifies use of the AWS CLI to disable, delete, or blind AWS audit logging and security monitoring services, including CloudTrail trails and event data stores, GuardDuty detectors, AWS Config recorders, Security Hub, Access Analyzer, Macie, and Inspector. Adversaries disable these controls early in a cloud intrusion so that subsequent credential abuse, data theft, and destruction go unrecorded. Because the endpoint sees the command as it is issued, this fires even when subsequent CloudTrail visibility is lost.

new

1

Cloud Offensive Framework Execution

Identifies execution of well-known cloud exploitation, enumeration, and attack-simulation frameworks on an endpoint. Adversaries run these after obtaining cloud credentials to map the compromised principal’s effective permissions, discover privilege escalation paths, and pivot to the console. Pacu is tracked by MITRE as software S1091. Real-world use on compromised hosts is documented in the AWS customer incident catalog, where both the Unit 42 SugarCRM zero-day response and the AWS CIRT federated-user compromise record Pacu and ScoutSuite scanning from access keys found on EC2 hosts. Covered frameworks include: Pacu, CloudFox, ScoutSuite, PMapper, Stratus Red Team, WeirdAAL, enumerate-iam, Prowler, CloudMapper, CloudSplaining, cloud_enum, CloudBrute, SkyArk, Leonidas, Halberd, Barq, Cartography, Nimbostratus, AWSBucketDump, dsnap, aws_consoler, Redboto, cloudjack, s3scanner, CloudSploit, aws-enumerator, iam-vulnerable, Fog, and SmogCloud. Secret scanners such as TruffleHog and Gitleaks are intentionally excluded because they run routinely in CI and pre-commit hooks; their credential-validation use is covered by CloudTrail and GitHub user-agent rules. Authorized red team and cloud audit activity uses the same tooling, so alerts should be correlated with known assessment windows and operators.

new

1

Potential Destructive AWS CLI Command Executed by GenAI Agent

Identifies a cloud CLI command that destroys infrastructure or identities, such as terminating EC2 instances, removing S3 buckets, or deleting IAM users, when it is spawned by a GenAI coding agent directly or through the agent’s shell wrapper. A compromised or prompt-injected agent can be steered into wiping the developer’s environment and cloud account using the credentials it already holds, as seen in the malicious Amazon Q Developer for VS Code v1.84.0 release (AWS-2025-015).

new

1

Anthropic Compliance Audit Log Export Accessed

An audit log export archive was accessed, meaning the actor downloaded exported audit activity. Attackers pull audit exports to see what defenders can observe, look for detection gaps, or remove evidence before making other control-plane changes.

new

1

Anthropic Organization Data Export Accessed

Starting an organization data export only signals intent. Accessing the export archive via its signed URL means the actor actually downloaded chats, projects, user metadata, and configuration. An attacker with administrative access can use this to exfiltrate intellectual property and credentials at scale.

new

1

Anthropic Activity from a Suspicious User Agent

Detects successful Anthropic audit activity where the user agent matches scripting HTTP clients, offensive scanners, or automation libraries (for example curl, python-requests, Go-http-client, axios, nuclei). Browser and first-party Claude clients normally present recognizable browser or product user agents; raw HTTP library agents on successful control-plane or product activity often indicate scripted access, stolen-session reuse, or unauthorized automation. Known benign automation patterns (axios or Go HTTP clients on file upload/delete, trusted device enrollment, and environment creation) are excluded.

new

1

Anthropic Multiple Authentication Failures

Detects at least five failed Anthropic authentication events for the same user email within one hour. Failures are matched by authentication category and failure outcome (for example magic-link or SSO login failures). That pattern fits repeated guessing, stale magic link abuse, or automated login attempts against one account.

new

1

Anthropic Compliance API Logging Disabled

Compliance API logging feeds the anthropic.audit dataset that Anthropic audit detections run on. An attacker with administrative access can disable it so later role grants, API key creation, exports, and authentication changes stop reaching this data source. This rule detects the disable action itself. Activity that happens after logging stops may not appear in logs-anthropic.audit-*.

new

1

Anthropic Excessive Chat Deletion

Detects an unusually high number of Claude chat deletion events for the same user email within a single calendar day. Mass chat deletion can indicate an attempt to remove conversation history, cover tracks after misuse of Claude, or automated cleanup following data staging or prompt abuse.

new

1

Anthropic Magic Link Second Factor Disabled

Magic link second factor adds an extra authentication step to passwordless sign-in for Anthropic. An attacker with administrative access can turn it off so magic link logins no longer require the second factor, which makes stolen or attacker-controlled mailboxes usable for interactive access. This often shows up alongside SSO weakening when the attacker wants a fallback authentication path outside the corporate IdP.

new

1

Anthropic Organization IP Restriction Deleted

Organization IP restrictions limit Anthropic administrative access to approved network ranges. Deleting one widens where a compromised admin session or API key can be used. The audit event does not always carry the deleted CIDR or restriction identifier, so treat this as an early signal and pivot to nearby IP restriction create or update events for the same organization.

new

1

Anthropic SSO Disabled or Connection Removed

SSO routes Anthropic authentication through the corporate identity provider. Disabling SSO, or deactivating or deleting an SSO connection, moves users onto alternate sign-in paths where IdP-enforced MFA, conditional access, and session policies no longer apply. That opens the door to password or magic-link accounts the attacker controls.

new

1

Anthropic Excessive Chat Access Failures

Detects a single authenticated user generating an unusually high number of denied Claude chat access attempts in a 24-hour window. That pattern fits automated chat enumeration or attempts to reach conversations outside the actor’s permissions. Unauthenticated shared-link actors lack user.id and are excluded.

new

1

Anthropic Organization Member and Group Enumeration

Detects a single user performing at least two distinct organization discovery actions within a 10-minute window: listing users, exporting members, or viewing groups. Chaining these read actions maps membership and group structure and commonly precedes targeted role grants, invites, or data collection against high-value accounts.

new

1

Anthropic Excessive Chat Snapshot Creation

Detects an unusually high number of successful Claude chat snapshot creation events for the same user email within a rolling 24-hour window. Chat snapshots package conversation content into shareable exports; sustained creation volume can indicate staging of organizational chat data for exfiltration via Anthropic’s web service or automated bulk export of sensitive prompts and responses.

new

1

Anthropic High File Upload Activity

Detects an unusually high volume of Claude file uploads from the same user email and source IP within a rolling 24-hour period. Sustained upload activity can indicate staging of sensitive documents in Claude chats for later retrieval, automated ingestion of data into LLM workflows, or abuse of organizational Claude access to move files into the cloud service.

new

1

Anthropic Admin API Key Deleted

Admin API keys grant programmatic access to organization and compliance APIs. An attacker can delete legitimate admin API keys to break security monitoring or integrations, or to cover tracks after creating replacement credentials they control. Deletion without a nearby rotation event points more at sabotage than routine key hygiene.

new

1

Anthropic Excessive Chat Creation

Detects an unusually high number of Claude chat creation events for the same user email within a 24-hour period. Burst chat creation can indicate automated LLM abuse, resource hijacking to burn organizational quotas, or scripted workflows used to stage many parallel conversations for data processing or prompt-injection campaigns.

new

1

Anthropic Extra Usage Spend Limit Deleted

Extra usage spend limits cap Anthropic organizational spend beyond included usage. Deleting a spend limit removes that cap and can enable unrestricted API or Claude consumption. An attacker who already has administrative or API access can delete the limit to burn budget, run large automated workloads, or stage resource abuse without the previous guardrail.

new

1

Anthropic Organization Deletion

Organization deletion and bulk delete remove tenant data, projects, and member access in a single administrative action. An attacker can use this to break AI-assisted workflows as an impact technique, to extort the organization, or to destroy evidence after finishing a data export. Once deletion progresses, recovery options shrink and earlier exfiltration activity is harder to reconstruct from the tenant itself.

new

1

Anthropic Admin API Key Created

Admin API keys grant programmatic access to organization and compliance APIs outside an interactive browser session. An attacker who creates one after compromise can automate role grants, exports, and logging changes without holding a user session that would time out under SSO. The key also survives password resets and IdP lockout if defenders revoke the interactive account but miss the API credential.

new

1

Anthropic Admin Role Assigned to User

The organization admin role controls organization settings, integrations, membership, and security configuration in Anthropic Claude for Enterprise. Membership role changes are reported as claude_user_role_updated with anthropic.audit.current_role. An attacker can promote a compromised or newly invited account to org admin to turn initial access into durable control-plane access. From admin, they can disable SSO, mint admin API keys for automation, start data exports, and weaken audit logging. Workspace-scoped role_assignment_granted grants (for example bare admin on a workspace) are out of scope for this rule.

new

1

Anthropic Compliance API Key Created

Compliance-scoped API keys read organization audit activity and compliance data. Once an attacker has administrative access, creating one gives them programmatic read of chats, files, and membership without an interactive session. This is separate from admin API key creation, which covers organization administration rather than compliance read scopes.

new

1

Anthropic MCP Server Created

Detects the first successful creation of a Model Context Protocol (MCP) server integration name in an Anthropic organization within the rule history window. MCP servers add external data pathways into Claude and can expose organizational data to third-party infrastructure. This is a New Terms rule keyed on organization.id and anthropic.audit.mcp_server_name so the same connector name can still alert in another tenant, while routine re-creation of an already-seen name in the same organization does not.

new

1

Anthropic Organization Domain Boundary Changed

Verified organization domains control which email addresses can join or be pulled into an Anthropic tenant. Verifying, claiming, adding, or removing a domain changes the tenant boundary and can pull in attacker-controlled mailboxes or push out legitimate corporate domains. These events are infrequent and affect organization-wide membership trust.

new

1

Anthropic Organization User Invite Sent

Sending an organization user invite creates a path for a new member to join the Anthropic tenant with a chosen role. An adversary who compromises an administrator or admin API key can invite a mailbox they control and accept the invite to gain durable access. Invites may target internal corporate addresses or external domains; this rule does not distinguish them because invite events do not carry verified organization domains for reliable comparison.

new

1

Anthropic Sensitive Claude Project Role Assigned to User

Detects when a Claude project owner or editor role is granted through a role_assignment_granted event. Project owners and editors can access project chats, artifacts, and knowledge bases that may hold sensitive data. An attacker with organization access can grant these roles to persist access to high-value project content without holding organization admin privileges.

new

1

Anthropic Primary Owner Transferred

Primary ownership is the highest administrative authority in an Anthropic organization, covering billing, membership, and organization-wide settings. Transferring ownership to an attacker-controlled account can lock out the legitimate administrator from recovery paths that depend on the original owner. Attackers often do this after role escalation so defenders cannot reverse earlier privilege changes through normal administration.

new

1

Persistence via a Hidden Plist Filename via macOS Security Events

Identifies the registration of a launch agent or launch daemon whose property list (plist) filename begins with a dot, using launch item registration messages collected by the macOS Security Events integration. An adversary may establish persistence by installing a launch agent or daemon that executes at login or boot; plist files with filenames starting with a dot are hidden from default directory listings and are particularly suspicious.

new

2

Launch Item Registration with Suspicious Executable Path via macOS Security Events

Identifies the registration of a launch agent or launch daemon whose target executable resides in a temporary or user-writable location, using launch item registration messages collected by the macOS Security Events integration. An adversary may establish persistence with a launch agent or daemon that runs a program staged in a world-writable or temporary directory, which is uncommon for legitimate software.

new

2

Excessive Sudo Authentication Failures via macOS Security Events

Identifies a high number of failed sudo password attempts on a macOS host within a short time window, using sudo messages collected by the Authentication data stream of the macOS Security Events integration. Repeated sudo authentication failures may indicate an adversary with access to a low-privileged account attempting to guess an administrator password to escalate privileges.

new

2

AWS SSM Agent Registered via Hybrid Activation

Identifies the Amazon SSM Agent invoked with "-register" and a hybrid activation argument on a Linux host. Hybrid activation is how non-EC2 hosts are onboarded as managed nodes, but adversaries with local access can repurpose the pre-installed, root-privileged SSM Agent as a covert remote access trojan by registering it to an attacker-controlled AWS account, gaining a persistent command channel that blends in with legitimate management traffic. On an EC2 instance that already runs the agent under an instance profile, a hybrid registration is highly unusual. The query cannot tell which account received the registration; the investigation guide explains how to confirm it.

new

1

Privilege Escalation via Parallels Appliance Extract Argument Injection

Identifies the Parallels Desktop root dispatcher (prl_disp_service) spawning tar/bsdtar with more arguments than its fixed extract command uses. The dispatcher always runs a 5-token command (tar -xf <archive> -C <dir>), so any additional arguments indicate an attacker-controlled folder name injecting extra tar flags. On macOS these flags let tar read or write attacker-chosen paths or execute an external program as root, resulting in local privilege escalation (CVE-2026-90894, Parallels Desktop < 27.0.0).

new

1

First Seen External MQTT Broker Connection

Identifies the first MQTT relationship from an internal source to an external broker that was not observed during the previous 14 days. MQTT is commonly used by IoT and messaging applications, but malware including BambooToken, IOCONTROL, MQsTTang, and WailingCrab has used publish/subscribe traffic for command and control.

new

1

Potential NetScaler Log Poisoning Command Injection Attempt

Detects shell syntax in NetScaler Pitboss records or in Citrix records that combine Pitboss, packet-engine, or core terminology with shell syntax. This may indicate that attacker-controlled data poisoned an appliance log consumed by a privileged script. The behavior includes CVE-2026-88771, but the detection is intended to identify similar NetScaler log-poisoning command-injection attempts without requiring a specific vulnerability, failure phrase, or command.

new

1

Potential ClickFix Command via Windows Run Dialog

Identifies suspicious commands written to the Windows Run dialog history (RunMRU) by explorer.exe. Adversaries socially engineer users to copy and paste malicious commands for execution, a pattern commonly seen in Fake CAPTCHA (ClickFix) campaigns. Investigate the process tree for a child of explorer.exe that matches the stored command.

new

1

Potential FileFix Command via Windows Explorer Address Bar

Identifies suspicious commands written to the Windows Explorer address bar history (TypedPaths). Adversaries socially engineer users to paste a command into the address bar of File Explorer or of a browser’s file upload dialog, a pattern known as FileFix; the writing process is therefore explorer.exe or the browser hosting the dialog. Stored commands that invoke PowerShell, cmd, mshta, msiexec, rundll32, or another living-off-the-land binary are unusual for this key, which normally contains file and folder paths. Investigate the process tree for a child of the writing process that matches the stored command.

new

1

Potential TerminalFix Cloudflare Lure in PowerShell

Identifies PowerShell script blocks that print a fake Cloudflare verification lure. TerminalFix pages instruct the victim to paste a command into Windows Terminal or PowerShell. The script presents messages such as "Cloudflare verification", "Cloudflare ID:", or "I am not a robot" while it stages a payload. Review the full script block for download, extraction, and follow-on execution.

new

1

Node.js Pre or Post-Install Script Execution

This rule detects the execution of Node.js pre or post-install scripts. These scripts are executed by the Node.js package manager (npm) during the installation of packages. Adversaries may abuse this technique to execute arbitrary commands on the system and establish persistence. This activity was observed in the wild as part of the Shai-Hulud worm.

update

6

Newly Observed Elastic Defend Behavior Alert

This rule detects Elastic Defend behavior alerts that are observed for the first time today when compared against the previous 5 days of alert history. It highlights low-volume, newly observed alerts tied to a specific detection rule, analysts can use this to prioritize triage and response.

update

5

Newly Observed High Severity Detection Alert

This rule detects Elastic SIEM high severity detection alerts that are observed for the first time in the previous 5 days of alert history. It highlights low-volume, newly observed alerts tied to a specific detection rule, analysts can use this to prioritize triage and response.

update

8

AWS Lambda Function Invoked by an Unusual Principal

Identifies the first time within the prior 14 days that a principal directly invokes an AWS Lambda function in an account, excluding invocations made on behalf of AWS services (normal event-source triggers). Adversaries who compromise credentials or move laterally may directly invoke functions to execute code, retrieve data returned by a function, or abuse an over-permissioned execution role. Direct, ad hoc invocation by a principal that does not normally call Lambda deviates from the usual event-driven invocation pattern and is worth reviewing. This rule relies on AWS Lambda data event logging, which is not enabled by default.

update

3

AWS Backup Recovery Point Deleted by Unusual User

Identifies when an unusual user deletes an AWS Backup recovery point via DeleteRecoveryPoint. A recovery point is a stored backup of a protected resource (EBS, RDS, DynamoDB, EFS, S3, and others). Deleting recovery points removes the ability to restore the associated data and is a core anti-recovery technique used in ransomware and data-destruction attacks to ensure victims cannot recover without paying or rebuilding. Routine lifecycle expirations are performed by the AWS Backup service itself; deletion by a non-service principal is rare and should be reviewed. This is a New Terms rule that uses "cloud.account.id", "user.name", and "aws.cloudtrail.flattened.request_parameters.backupVaultName" to alert on the first time a given identity in an account successfully deletes a recovery point from a specific backup vault within the history window.

update

3

AWS Lambda Function Deletion by Unusual User

Identifies when an unusual user deletes an AWS Lambda function. Deleting a function removes its code, configuration, versions, and aliases. Adversaries may delete functions to disrupt business operations and automated workflows, to destroy attacker-deployed backdoors and remove evidence after achieving their objective, or to inhibit incident response. Because function deletion is destructive and often irreversible without redeployment, deletions performed by unexpected principals or outside change windows should be reviewed. This is a New Terms rule that uses "cloud.account.id", "user.name", and "aws.cloudtrail.flattened.request_parameters.functionName" to alert on the first time a given identity in an account successfully deletes a specific Lambda function within the history window.

update

4

Unusual Azure VM Extension Detected

Identifies the first time a given VM extension name is created or updated on an Azure virtual machine or VM scale set within the rule’s lookback window. VM extensions run with high privilege on the guest (SYSTEM on Windows, root on Linux) and are a common code-execution and persistence primitive. The extension instance name is attacker-controlled and the Azure activity log records only that name, not the publisher or type, so the control plane cannot reliably identify the extension family (for example CustomScript). This rule therefore takes a type-agnostic ES

QL new-terms approach: it derives the host and the extension instance name from azure.resource.name and alerts the first time a given (host, extension name) pair is observed in the window, surfacing novel extension deployments while suppressing names a host routinely uses.

update

3

GKE API Request Failure Burst by User

Detects bursts of failed GKE API requests from a single user identity within a five-minute window. Repeated authorization failures across multiple actions can indicate credential stuffing, RBAC probing, or reconnaissance with stolen tokens.

update

3

Google Workspace Object Copied to External Drive with App Consent

Detects when a user copies a Google spreadsheet, form, document or script from an external drive. Sequence logic has been added to also detect when a user grants a custom Google application permission via OAuth shortly after. An adversary may send a phishing email to the victim with a Drive object link where "copy" is included in the URI, thus copying the object to the victim’s drive. If a container-bound script exists within the object, execution will require permission access via OAuth in which the user has to accept.

update

14

Linux User Account Creation

Identifies attempts to create new users. Attackers may add new users to establish persistence on a system.

update

12

Unusual File Creation via Web Server

This rule leverages the "new_terms" rule type to detect unusual file creations originating from web server processes on Linux systems. Attackers may exploit web servers to maintain persistence on a compromised system, often resulting in atypical file creations. As file creations from web server processes are common, the "new_terms" rule type approach helps to identify deviations from normal behavior.

update

4

Accepted Default Telnet Port Connection

This rule detects network events that may indicate the use of Telnet traffic. Telnet is commonly used by system administrators to remotely control older or embedded systems using the command line shell. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. As a plain-text protocol, it may also expose usernames and passwords to anyone capable of observing the traffic.

update

119

FortiGate FortiCloud SSO Login from Unusual Source

This rule detects the first successful FortiCloud SSO login from a previously unseen source IP address to a FortiGate device within the last 5 days. FortiCloud SSO logins from new source IPs may indicate exploitation of SAML-based authentication bypass vulnerabilities such as CVE-2026-24858, where crafted SAML assertions allow unauthorized access to FortiGate devices registered to other accounts. Environments that regularly use FortiCloud SSO will only alert on new source IPs not seen in the lookback window.

update

6

First-Time FortiGate Administrator Login

This rule detects the first observed successful login of a user with the Administrator role to the FortiGate management interface within the last 5 days. First-time administrator logins can indicate newly provisioned accounts, misconfigurations, or unauthorized access using valid credentials and should be reviewed promptly.

update

7

RPC (Remote Procedure Call) from the Internet

This rule detects network events that may indicate the use of RPC traffic from the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.

update

115

RPC (Remote Procedure Call) to the Internet

This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.

update

115

SMB (Windows File Sharing) Activity from the Internet

This rule detects network events that may indicate inbound Windows file sharing (SMB or CIFS) traffic originating from the Internet. SMB should never be directly reachable from the Internet, as it is a primary target for exploitation by threat actors seeking initial access. Inbound SMB from a public IP is a direct precondition for attacks such as EternalBlue (MS17-010) and related SMB remote code execution vulnerabilities.

update

4

SMB (Windows File Sharing) Activity to the Internet

This rule detects network events that may indicate the use of Windows file sharing (also called SMB or CIFS) traffic to the Internet. SMB is commonly used within networks to share files, printers, and other system resources amongst trusted systems. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector or for data exfiltration.

update

115

Microsoft Defender XDR Incident External Alerts

Generates a detection alert for each Microsoft Defender XDR incident written to the configured indices. Microsoft Defender emits multiple update events for the same incident as its member alerts and status evolve, all sharing a stable incident identifier. This rule suppresses those update events so that a single, continuous Elastic alert is maintained per Defender incident rather than a new alert per update. Enabling this rule allows you to immediately begin investigating Microsoft Defender XDR incidents in the app.

update

3

LSASS Process Access via Windows API

Identifies access attempts to the LSASS handle, which may indicate an attempt to dump credentials from LSASS memory.

update

21

Mark-of-the-Web Removal by an Unusual Process

Identifies an unusual process deleting the Zone.Identifier alternate data stream from an executable or Windows Installer package. Attackers can remove this stream to bypass Mark-of-the-Web protections.

update

3

Potential Execution via FileFix Phishing Attack

Identifies the execution of Windows commands or downloaded files via the browser’s dialog box. Adversaries may use phishing to instruct the victim to copy and paste malicious commands for execution via crafted phishing web pages.

update

6

Temporarily Scheduled Task Creation

Indicates the creation and deletion of a scheduled task within a short time interval. Adversaries can use these to proxy malicious execution via the schedule service and perform clean up.

update