Browse Rules

Search and filter across all detection sources

64 rules

hayabusa medium sigma

Powershell LocalAccount Manipulation

Adversaries may manipulate accounts to maintain access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups

sigma medium sigma

Powershell LocalAccount Manipulation

Adversaries may manipulate accounts to maintain access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups

hayabusa high sigma

Suspicious Manipulation Of Default Accounts Via Net.EXE

Detects suspicious manipulations of default accounts such as 'administrator' and 'guest'. For example 'enable' or 'disable' accounts or change the password...etc

sigma high sigma

Suspicious Manipulation Of Default Accounts Via Net.EXE

Detects suspicious manipulations of default accounts such as 'administrator' and 'guest'. For example 'enable' or 'disable' accounts or change the password...etc

hayabusa high sigma

Suspicious Manipulation Of Default Accounts Via Net.EXE

Detects suspicious manipulations of default accounts such as 'administrator' and 'guest'. For example 'enable' or 'disable' accounts or change the password...etc

panther high python

An administrator account was created, deleted, or modified.

An administrator account was created, deleted, or modified.

panther high python

GCP Inbound SSO Profile Created

panther high python

GCP Workforce Pool Created or Updated

panther high python

GCP Workload Identity Pool Created or Updated

hayabusa medium sigma

Remove Account From Domain Admin Group

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts.

sigma medium sigma

Remove Account From Domain Admin Group

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts.

mdecrevoisier high sigma

Computer account manipulation for delegation (RBCD)

Detects scenarios where an attacker manipulate a computer object and updates its attribute 'msDS-AllowedToActOnBehalfOfOtherIdentity' to enable a resource to impersonate and authenticate any domain user.

panther medium python

GitHub Org IP Allow List modified

Detects changes to a GitHub Org IP Allow List

panther high python

Root Password Changed

Someone manually changed the Root console login password.

sentinel medium kql

Pathlock TDnR - G/L Account Changes

Detects changes to General Ledger (G/L) accounts in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized modifications to G/L accounts may indicate financial data manipulation, accounting fraud, or attempts to conceal unauthorised transactions.

panther medium python

Azure Storage Account Shared Key Access Enabled

Detects when an existing Azure storage account's shared key access is enabled (allowSharedKeyAccess: true). Shared key access uses storage account keys for authentication, which is less secure than Azure AD-based authentication.

panther high python

Carbon Black Admin Role Granted

Detects when a user is granted Admin or Super Admin permissions.

panther medium python

Slack App Access Expanded

Detects when a Slack App has had its permission scopes expanded

panther high python

Slack User Privilege Escalation

Detects when a Slack user gains escalated privileges

panther high python

A User's Panther Account was Modified

A Panther user's role has been modified. This could mean password, email, or role has changed for the user.

panther informational python

Azure Storage Account Key Regenerated

Detects when an Azure storage account access key is regenerated. Key regeneration is a normal operational activity but may indicate an attacker attempting to maintain persistence or rotate credentials after compromise.

panther informational python

New IAM Credentials Updated

A console password, access key, or user has been created.

elastic high kql

AWS GuardDuty Member Account Manipulation

Detects attempts to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization. In multi-account GuardDuty deployments, a delegated administrator account aggregates findings from member accounts. Adversaries may attempt to disassociate member accounts, delete member relationships, stop monitoring members, or delete pending invitations to break this centralized visibility. These actions can be precursors to or alternatives for deleting GuardDuty detectors entirely, all

panther medium python

AWS Network ACL Overly Permissive Entry Created

A Network ACL entry that allows access from anywhere was added.

anvilogic critical other

AWS S3 Bucket Manipulation [snowflake-awscloudtrail]

Detect when various S3 bucket manipulation events occur within an AWS environment which can be indicative of malicious behavior being performed from a compromised account or an insider threat.