Search and filter across all detection sources
491 rules
[TRENDMICRO] Application Control Logs Detected
Event created in the application log
[DYNAMIC] AWS Application Insights logs detected via program.
[WINDOWS-SYSTEM] The Application log file was cleared
Web Application attack detected
Identifies Web application attack in Azure Firewall IDPS logs.
Okta: Application Modified or Deleted [snowflake-okta]
This use case looks for updates or removals of OKTA applications
Okta: API Token Created_Deleted [snowflake-okta]
This use-case will detect when API tokens are created or deleted in Okta
Okta: API Token Created_Deleted [splunk-okta]
Relevant Anti-Virus Signature Keywords In Application Log
Detects potentially highly relevant antivirus events in the application log based on known virus signature names and malware keywords.
[JUNIPER] Application-level distributed denial-of-service (AppDDoS) attack in a logical system
SenservaPro AD Applications Not Using Client Credentials
'Searches for logs of AD Applications without Client Credentials (Key or Secret)'
[JUNIPER] application-level distributed denial-of-service (AppDDoS) state transition occurred in logical system
[APACHE] Log4j exploit attempt - CVE-2021-44228
Okta: Profile Updated [snowflake-okta]
Okta user profile updated
Okta: Profile Updated [splunk-okta]
Okta: User Created [snowflake-okta]
Okta user account creation
Okta: User Created [splunk-okta]
Suspicious Execution of InstallUtil Without Log
Uses the .NET InstallUtil.exe application in order to execute image without log
[WEB-ATTACKS] Log4j exploit attempt - CVE-2021-44228
Push Security Authorized IdP Login
Login to application with unauthorized identity provider which could indicate a SAMLjacking attack.
Push Security Unauthorized IdP Login
[WEB-ATTACKS] Attempt to Access Default Cacti Login Page