Browse Rules

Search and filter across all detection sources

244 rules

panther medium python

ZIA Cloud Account Created

This rule detects when new cloud account was created.

sentinel medium kql

Pathlock TDnR - SAP Cloud Account Administration Events

Detects account administration events in SAP Cloud environments, forwarded by Pathlock Threat Detection and Response. Suspicious cloud account activities may indicate unauthorized provisioning, privilege escalation, or account takeover in SAP cloud tenants.

sigma medium sigma

Google Cloud Service Account Modified

Identifies when a service account is modified in Google Cloud.

sagan critical other

[CISCO-SCA] Azure Transfer Data To Cloud Account

[CISCO-SCA] Azure Transfer Data To Cloud Account

sigma medium sigma

Google Cloud Service Account Disabled or Deleted

Identifies when a service account is disabled or deleted in Google Cloud.

chronicle medium yara-l

Google Cloud Service Account Key Created or Uploaded

Detects when a service account key is created in or uploaded to a monitored Google Cloud project.

anvilogic low other

AWS Account Discovery [snowflake-awscloudtrail]

Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. -- Threat Actor Association: GUI-vil

anvilogic low spl

AWS Account Discovery [splunk-awscloudtrail]

Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. -- Threat Actor Association: GUI-vil

elastic medium kql

GCP Service Account Deletion

Identifies when a service account is deleted in Google Cloud Platform (GCP). A service account is a special type of account used by an application or a virtual machine (VM) instance, not a person. Applications use service accounts to make authorized API calls, authorized as either the service account itself, or as G Suite or Cloud Identity users through domain-wide delegation. An adversary may delete a service account in order to disrupt their target's business operations.

bertjanp unknown kql

Disabled Account Attack Disruption

Attack disruption disabled a cloud/hybrid account due to suspicious activities. The query lists the accounts that have been disabled by MDI.

panther medium python

Snowflake External Data Share

Detect when an external share has been initiated from one source cloud to another target cloud.

elastic medium kql

GCP Service Account Disabled

Identifies when a service account is disabled in Google Cloud Platform (GCP). A service account is a special type of account used by an application or a virtual machine (VM) instance, not a person. Applications use service accounts to make authorized API calls, authorized as either the service account itself, or as G Suite or Cloud Identity users through domain-wide delegation. An adversary may disable a service account in order to disrupt to disrupt their target's business operations.

panther high python

GCP Inbound SSO Profile Created

elastic low kql

GCP Service Account Creation

Identifies when a new service account is created in Google Cloud Platform (GCP). A service account is a special type of account used by an application or a virtual machine (VM) instance, not a person. Applications use service accounts to make authorized API calls, authorized as either the service account itself, or as G Suite or Cloud Identity users through domain-wide delegation. If service accounts are not tracked and managed properly, they can present a security risk. An adversary may create

panther high python

GCP Workforce Pool Created or Updated

panther high python

GCP CloudBuild Potential Privilege Escalation

Detects privilege escalation attacks designed to gain access to the Cloud Build Service Account. A user with permissions to start a new build with Cloud Build can gain access to the Cloud Build Service Account and abuse it for more access to the environment.

panther high python

GCP Workload Identity Pool Created or Updated

elastic high kql

GCP Service Account Key Creation

Identifies when a new key is created for a service account in Google Cloud Platform (GCP). A service account is a special type of account used by an application or a virtual machine (VM) instance, not a person. Applications use service accounts to make authorized API calls, authorized as either the service account itself, or as G Suite or Cloud Identity users through domain-wide delegation. If private keys are not tracked and managed properly, they can present a security risk. An adversary may c

panther low python

Suspicious Snowflake Sessions - Unusual Application

Detects unusual (non-common) applications and client characteristics that have been used to connect to a Snowflake account

panther high python

AWS RDS Snapshot Shared

An RDS snapshot was shared with another account. This could be an indicator of exfiltration.

sentinel medium kql

Pathlock TDnR - SAP BTP Cloud Foundry Events

Detects security events from SAP BTP Cloud Foundry environments, forwarded by Pathlock Threat Detection and Response. Anomalous BTP Cloud Foundry activity may indicate unauthorized application deployments, service account abuse, or data exfiltration from cloud-native SAP workloads.

elastic low kql

GCP IAM Service Account Key Deletion

Identifies the deletion of an Identity and Access Management (IAM) service account key in Google Cloud Platform (GCP). Each service account is associated with two sets of public/private RSA key pairs that are used to authenticate. If a key is deleted, the application will no longer be able to access Google Cloud resources using that key. A security best practice is to rotate your service account keys regularly.

panther high python

GCP storage hmac keys create

There is a feature of Cloud Storage, “interoperability”, that provides a way for Cloud Storage to interact with storage offerings from other cloud providers, like AWS S3. As part of that, there are HMAC keys that can be created for both Service Accounts and regular users. We can escalate Cloud Storage permissions by creating an HMAC key for a higher-privileged Service Account.

panther medium python

AWS Snapshot Made Public

An AWS storage snapshot was made public.

sentinel medium kql

Palo Alto Prisma Cloud - Multiple failed logins for user

'Detects multiple failed logins for the same user account.'