Community Rules: David Alonso - Threat Hunting

July 10, 2026 · View on GitHub

Attribution

These analytical rules were authored by David Alonso and sourced from the Dalonso Security Repository. David maintains a comprehensive collection of Microsoft Sentinel threat-hunting detections across identity, endpoint, cloud, and network data sources.

License

All rules in this directory are released under The Unlicense (public domain). You are free to use, modify, and distribute them without restriction. See The Unlicense for full terms.

Deployment Note

These rules deploy as disabled by default. Enable individual rules in the Microsoft Sentinel portal after reviewing them against your environment's data sources, retention, and noise tolerance.

Categories

CategoryRule Count
AzureActivity12
CommonSecurityLog37
DNSEvents17
NonInteractiveSigninLogs23
SigninLogs22

AzureActivity

NameSeverityDescription
Azure - Automation Runbook Created or Published by First-Time CallerHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure Cryptojacking - High-Compute VM Deployed by New IdentityHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Diagnostic Settings Permanently Deleted Without RecreationHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Mass Deletion of Critical Resources (NSGs/VMs/Storage/VNETs/Key Vaults)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Mass Privileged Role Assignments by Single IdentityHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Mass Resource Creation Burst by New Identity (Cryptojacking / Persistence)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Privileged Management Operations from a New Source IP for Established IdentityMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Resource Lock or Policy Assignment DeletedMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Service Principal CA Bypass Sign-in Followed by Management OperationsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Service Principal Credential Added Then Privileged Role Assigned (Same Initiator, 60 min)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Storage Account SAS Token Bulk GenerationMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Azure - Threat Intelligence Match on Management Plane Caller IP (STIX)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.

CommonSecurityLog

NameSeverityDescription
Firewall Beaconing Detection - Regular Outbound ConnectionsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Firewall Anomalous Outbound Data Volume - Exfiltration RiskHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Firewall Traffic to Threat Intelligence Flagged IPHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Firewall Port Scan Detection - Vertical and Horizontal SweepsMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Firewall Allowed Traffic to High-Risk CountryMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Lateral Movement - Internal Host Port Sweep on Admin/Pivot PortsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Fortinet IPS - High-Frequency Intrusion Prevention AlertsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Palo Alto Networks - Threat Log Events (Spyware, Wildfire, Vulnerability)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Blocked Request to Malicious / C2 CategoryHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Shadow IT and Unauthorized File Sharing - High VolumeMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNS Tunneling Indicators - Anomalously Long HostnamesHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Firewall New First-Seen External IP ContactedMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Correlation: Firewall Allowed Traffic + Azure AD Sign-In from Same IPHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Correlation: Firewall Traffic + Active Security Alert - Shared IOC IPHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Correlation: Firewall Traffic Matching Threat Intelligence Domain / URLHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Palo Alto Networks - High-Volume Inter-Zone Policy DeniesMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Fortinet SSL-VPN and Admin Authentication Brute ForceHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Impossible Travel (Same User, Multiple Locations in 1 Hour)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Protocol Anomaly - HTTP or HTTPS on Non-Standard PortsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Correlation: Firewall Traffic from High-Risk Identity (IdentityInfo)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - DLP Policy Violation - Blocked Sensitive Data UploadHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Advanced Threat Protection (ATP) / Sandbox Malicious File BlockedHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Mass Cloud Storage Download - Data Staging RiskHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Uncategorized or Newly Registered Domain Request SpikeMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Tunnel, SOCKS Proxy, or SSL Bypass Category DetectedMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Off-Hours High-Volume Proxy Activity (Behavioral Anomaly)MediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Multi-User Phishing Campaign - Same Domain Hit by 3+ Users in 1 HourHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - High ThreatRiskLevel Browsing in Allowed TrafficHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Sudden Category Shift - User Accessing New High-Risk URL CategoriesMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA / ZPA - Visibility Loss - No Events Received in 2 HoursMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZPA - Access to Internal Application from Anomalous GeolocationHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZPA - Repeated Connection Failures - Possible Credential Spray Against Internal AppsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZPA - First-Time Access to Internal Application - Possible Lateral MovementMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZPA - App Access Volume Spike - User Accessing Significantly More Apps Than BaselineMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - Patient APT: Multi-Channel Low & Slow ExfiltrationHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZPA/ZIA - Perfect Impostor: Account Takeover Hiding Within Normal TrafficHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Zscaler ZIA - APT Control Evasion: Agent Tampering and Visibility DegradationHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.

DNSEvents

NameSeverityDescription
DNS Tunneling via High-Volume TXT Record QueriesHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNS C2 Beaconing — Low-TTL Periodic Domain LookupsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
ClickFix nslookup Payload Delivery via DNSHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DGA — High-Entropy Subdomain Pattern (Domain Generation Algorithm)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNS Zone Transfer (AXFR/IXFR) from Unauthorized Internal HostMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNS Amplification Attack — Open Resolver AbuseMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNS Rebinding — Rapid TTL Change for Same DomainMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNS Data Exfiltration via Long Subdomain LabelsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
WPAD Auto-Discovery DNS Lookup AbuseMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNS-Based Internal Network Reconnaissance SweepMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Certutil Decoding After DNS Lookup Chain (LOLBin DNS Staging)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DGA Confirmed — NXDOMAIN Flood with High-Entropy Domain PatternHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
NULL and ANY DNS Record Type Queries — Tunneling IndicatorMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNS MX Record Abuse for Payload StagingHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Subdomain Enumeration Burst — DNS Brute-Force ReconnaissanceMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
DNSAdmins Privilege Escalation via DLL Injection (dnscmd /serverlevelplugindll)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
AD-Integrated DNS Wildcard Record Abuse (ADIDNS Poisoning)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.

NonInteractiveSigninLogs

NameSeverityDescription
Token Theft - Refresh Token Replay from New LocationHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Non-Interactive Auth Followed by Privileged Audit ActionsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Non-Interactive Sign-In from Threat Intelligence IPHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Interactive to Non-Interactive Token Theft PivotHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Device Code Flow Authentication AbuseHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
ROPC Authentication Detected - Credential Pass-Through BypassHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Non-Interactive Sign-In via TOR or Anonymous ProxyHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Brute Force Success - Credential Stuffing SucceededHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
MFA Fatigue Attack - Push Bombing Followed by Silent Token AbuseHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Stale Token Used After Password Change or Auth Method UpdateHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Account Takeover - Email Forwarding Rule Created After Silent AuthHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
PIM Role Activation Followed by Non-Interactive Token UseHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
OAuth App Consent Followed by Immediate Silent AuthenticationHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Non-Interactive Auth Followed by Bulk Data DownloadHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Non-Interactive Sign-Ins by Identity Protection Risky UsersHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Password Spray Attack via Non-Interactive Sign-InsHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Impossible Travel - Non-Interactive Sign-Ins from Multiple CountriesMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Legacy Authentication Bypassing MFA and Conditional AccessMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
High-Frequency Token Refresh - Possible Session Hijack or Automated AbuseMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
New or Rogue OAuth Application First Seen in TenantMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Service Principal Authenticating from Anomalous IP SpreadMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Non-Interactive Sign-In from High-Risk CountryMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
Non-Interactive Brute Force - Single User Targeted by Multiple IPsMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.

SigninLogs

NameSeverityDescription
SigninLogs — Password Spray Attack (Single IP, Many Accounts)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Brute Force Success Chain (Possible Account Breach)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Credential Stuffing Attack (High-Velocity Invalid Credentials)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Impossible Travel (3+ Countries in 1 Hour)MediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Legacy Authentication Brute Force (IMAP/POP/SMTP)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Privileged Account Under Attack (Low-Threshold Failures)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Nation State IP Sign-In DetectedHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Attacker in the Middle (AiTM) Token Theft DetectedHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Distributed Coordinated Attack (Botnet, 10+ IPs per User)MediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — MFA Fatigue Attack (Push Bombardment)MediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Slow & Low Password Spray (Multi-Day Evasion)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Account Enumeration via Error Code FingerprintingHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Service Account Interactive Browser Sign-InHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Password Reset Followed by New-Country Sign-In (Account Takeover)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Off-Hours Sign-In by Privileged AccountMediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Concurrent Sessions from Multiple Countries (Same User)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Device Code Flow Authentication (Phishing Vector)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Legacy Auth First Appearance for Modern-Only AccountHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — High-Frequency Repeated Sign-Ins (Automated Credential Abuse)MediumCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — First New Country Sign-In for Privileged Account (Deterministic)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Conditional Access Policy Blocked then Successful BypassHighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.
SigninLogs — Fresh IP Authenticating Multiple Accounts (Compromised Proxy)HighCommunity rule by David Alonso (https://github.com/davidalonsod/Dalonso-Security-Repo). Licensed under The Unlicense.

Last synced: 03/26/2026 09:07:21

To re-import or update these rules, run:

.\Tools\Import-CommunityRules.ps1