TA0001

Initial Access Detection Rules

The adversary is trying to get into your network. Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.

df00tech ships 222 production-ready detection rules mapped to the Initial Access tactic (TA0001). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.

Unlock the full Pro package

Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.

Upgrade to Pro

Initial Access detections (222)

Related tactics

All MITRE ATT&CK Tactics