Browse Rules

Search and filter across all detection sources

71 rules

sentinel high kql

Claroty - Asset Down

'Triggers asset is down.'

sentinel low kql

Cyble Vision Alerts Assets

'Scheduled rule that creates incidents for asset alerts using saved parser Alerts_assets. Mandatory custom details: MappedSeverity, Status, AlertID, Service.'

sentinel medium kql

M2131_AssetStoppedLogging

'This alert is designed to monitor assets within the Maturity Model for Event Log Management (M-21-31) standard. The alert triggers when a monitored asset fails to provide a heartbeat within 24 hours.'

chronicle low yara-l

MITRE ATT&CK T1021.002 Windows Admin Share With Asset Entity

Net use commands for SMB/Windows admin shares based on asset entity group

sublime high mql

beta.DLP: Vehicle VIN

Detects messages containing Vehicle Identification Numbers (VIN).

sentinel high kql

CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert

"This rule detects high severity asset-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 80 or higher, excluding those categorized as 'ATTACK_SURFACE_VULNERABILITY', and generates alerts for assets that may be at risk."

sentinel medium kql

CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert

"This rule detects medium severity asset-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 50 or higher, excluding those categorized as 'ATTACK_SURFACE_VULNERABILITY', and generates alerts for assets that may be at risk."

elastic critical kql

Multiple Vulnerabilities by Asset via Wiz

This alert identifies assets with an elevated number of vulnerabilities reported by Wiz, potentially indicating weak security posture, missed patching, or active exposure. The rule highlights assets with a high volume of distinct vulnerabilities, the presence of exploitable vulnerabilities, or a combination of multiple severities, helping prioritize assets that pose increased risk.

sentinel medium kql

XbowNewAssetDiscovered

Alerts when a new asset is registered in XBOW for the first time. This is detected by matching assets whose CreatedAt timestamp falls within the current query window, indicating the asset was newly added rather than updated. This helps track shadow IT, new deployments, and any unexpected expansion of the external attack surface.

sentinel high kql

Claroty - New Asset

'Triggers when Claroty reports a new asset event in the environment, indicating that a previously unseen device or system has been discovered and should be reviewed for authorization, ownership, and expected network placement.'

sentinel medium kql

Radiflow - New Activity Detected

'Generates an incident when a new asset or MAC is detected either by Radiflow's iSID.'

sentinel medium kql

CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule

"This rule detects medium severity attack surface-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 50 or higher, excluding those categorized as 'ASSET_VULNERABILITY', and generates alerts for assets that may be at risk."

sentinel high kql

CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert

"This rule detects high severity attack surface-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 80 or higher, excluding those categorized as 'ASSET_VULNERABILITY', and generates alerts for assets that may be at risk."

panther low python

Connection to Embargoed Country

Detection to alert when internal asset is communicating with an sanctioned destination. This detection leverages Panther UDM and IPInfo enrichment.

elastic low kql

AWS RDS Snapshot Export

Identifies the export of an Amazon Relational Database Service (RDS) Aurora database snapshot.

sentinel informational kql

Sensitive Data Discovered in the Last 24 Hours

'Identifies all classifications that have been detected on assets during a scan by Microsoft Purview within the last 24 hours.'

sentinel low kql

Cyble Vision Alerts New Vulnerability Detected

'A newly detected CVE has been associated with a monitored keyword or asset. This may indicate exposure to newly published or exploited vulnerabilities.'

sigma medium sigma

Default Credentials Usage

Before deploying any new asset, change all default passwords to have values consistent with administrative level accounts. Sigma detects default credentials usage. Sigma for Qualys vulnerability scanner. Scan type - Vulnerability Management.

splunk unknown spl

Detect New Login Attempts to Routers

The following analytic identifies new login attempts to routers. It leverages authentication logs from the ES Assets and Identity Framework, focusing on assets categorized as routers. The detection flags connections that have not been observed in the past 30 days. This activity is significant because unauthorized access to routers can lead to network disruptions or data interception. If confirmed malicious, attackers could gain control over network traffic, potentially leading to data breaches o

splunk unknown spl

Detect Unauthorized Assets by MAC address

The following analytic identifies unauthorized devices attempting to connect to the organization's network by inspecting DHCP request packets. It detects this activity by comparing the MAC addresses in DHCP requests against a list of known authorized devices stored in the assets_by_str.csv file. This activity is significant for a SOC because unauthorized devices can pose security risks, including potential data breaches or network disruptions. If confirmed malicious, this activity could allow an

sentinel low kql

Cyble Vision Alerts OT/ICS Threat Activity Detected

'This alert indicates detection of OT/ICS-related network activity involving industrial control protocols (e.g., IEC104). May indicate probing, reconnaissance, or attempted access against critical infrastructure assets.'

sentinel informational kql

New service account gained access to IaaS resource

This policy detects when an application or service account gained new access to your assets. This policy is defined by Authomize and can be edited to change the configuration.

sentinel high kql

Critical Finding Overdue on Internet-Facing App

Detects Critical and High severity findings older than 7 days that remain open on internet-facing applications. Uses the InternetFacingApps watchlist to scope results to externally exposed assets requiring urgent remediation.

elastic low kql

Deprecated - AWS RDS Instance Creation

Identifies the creation of an Amazon Relational Database Service (RDS) Aurora database instance.

elastic medium kql

Azure Kubernetes Services (AKS) Kubernetes Pods Deleted

Identifies the deletion of Azure Kubernetes Pods. Adversaries may delete a Kubernetes pod to disrupt the normal behavior of the environment.