Browse Rules

Search and filter across all detection sources

732 rules

panther medium python

GCP Access Attempts Violating IAP Access Controls

GCP Access Attempts Violating IAP Access Controls

sagan high other

[Barracuda] WAF Access Control access denied

[Barracuda] WAF Access Control access denied

sagan high other

[Barracuda] WAF Access Control cookie expired

[Barracuda] WAF Access Control cookie expired

sagan high other

[Barracuda] WAF Access Control cookie invalid

[Barracuda] WAF Access Control cookie invalid

panther medium python

GCP Access Attempts Violating VPC Service Controls

An access attempt violating VPC service controls (such as Perimeter controls) has been made.

sagan high other

[Barracuda] WAF Access Control no cookie found

[Barracuda] WAF Access Control no cookie found

sagan critical other

[CISCO-SCA] Permissive AWS S3 Access Control List

[CISCO-SCA] Permissive AWS S3 Access Control List

sagan critical other

[IMPERVA] Bot Access Control Detected and Not Blocked

[IMPERVA] Bot Access Control Detected and Not Blocked

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - Process Escalated Privileges Possible Access Control Bypass

[CROWDSTRIKE] Possible Privilege Escalation Detected - Process Escalated Privileges Possible Access Control Bypass

sentinel low kql

Guardian- Content Access Control Allowed List Policy Violation Detection

'This alert creates an incident when Content Access Control Allowed List Policy Violation detected from the Guardian.'

sentinel medium kql

Guardian- Content Access Control Blocked List Policy Violation Detection

'This alert creates an incident when Content Access Control Blocked List Policy Violation detected from the Guardian.'

sagan medium other

[CROWDSTRIKE] Possible Command And Control Blocked -Network Access In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Blocked -Network Access In A Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Detected - Network Access In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Detected - Network Access In A Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Killed - Network Access In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Killed - Network Access In A Detection Summary Event

yara unknown yara

disable_uax [antidebug_antivm]

Disable User Access Control

sagan informational other

[CARBONBLACK-APP-CONTROL] Exclusive access to a file was blocked because of tamper protection

[CARBONBLACK-APP-CONTROL] Exclusive access to a file was blocked because of tamper protection

sagan medium other

[CROWDSTRIKE] Possible Command And Control Blocked - Network Access In An Epp Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Blocked - Network Access In An Epp Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Detected - Network Access In An Epp Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Detected - Network Access In An Epp Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Killed - Network Access In An Epp Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Killed - Network Access In An Epp Detection Summary Event

sentinel high kql

Pathlock TDnR - Dynamic Access Control Events

Detects events from Pathlock Dynamic Access Control (DAC) for SAP, forwarded to Microsoft Sentinel. DAC events capture real-time access policy decisions and violations, including blocked transactions, emergency access grants, and policy bypass attempts that require immediate investigation.

sentinel medium kql

Pathlock TDnR - GRC Access Control Change Documents

Detects changes to SAP GRC (Governance, Risk, and Compliance) access control configuration, forwarded by Pathlock Threat Detection and Response. Modifications to GRC settings may indicate attempts to bypass segregation of duties controls or disable risk monitoring.

wazuh medium xml

Auditd: maximum amount of Discretionary Access Control (DAC) or Mandatory Access Control (MAC) failures reached

Auditd: maximum amount of Discretionary Access Control (DAC) or Mandatory Access Control (MAC) failures reached

panther high python

Snyk System External Access Settings Changed

Detects when Snyk Settings that control access for external parties have been changed.

splunk unknown spl

AWS Network Access Control List Deleted

The following analytic detects the deletion of AWS Network Access Control Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes a network ACL entry. This activity is significant because deleting a network ACL can remove critical access restrictions, potentially allowing unauthorized access to cloud instances. If confirmed malicious, this action could enable attackers to bypass network security controls, leading to unauthorized access, data exfiltration, or furthe

sentinel high kql

SAP BTP - Cloud Integration access policy tampering

Identifies changes to access policies in SAP Cloud Integration. Access policies control authorization for integration artifacts, defining which users and roles can access specific integration flows and related content. Unauthorized access policy manipulation could indicate: - Attacker granting themselves access to sensitive integration artifacts - Removal of security controls to enable further malicious activity - Defense evasion by modifying artifact references to hide unauthorized access