Search and filter across all detection sources
126 rules
Configuration Required - Sensitive 1Password Item Accessed
Alerts when a user defined list of sensitive items in 1Password is accessed
Okta Login Without Push Marker
Snowflake Configuration Drift
Monitor for configuration drift made by malicious actors as part of ongoing cyber threat activity reported May 31st, 2024
AWS S3 Bucket Lifecycle Configuration
Verifies that the S3 Bucket Object Lifecycle configuration expires data within 90 and 365 days.
Configuration Backup Job Settings Updated
Detects when configuration backup job settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
GitHub Action Failed
A monitored github action has failed.
AWS Redshift Cluster Maintenance Window
This policy validates that Redshift Clusters have the correct preferred maintenance window configured.
Cisco Umbrella Suspicious Domains
Monitor suspicious or known malicious domains
Crowdstrike FDR LOLBAS
Living off the land binaries and script usage
Dropbox Many Deletes
Detects when a dropbox user deletes many documents.
Dropbox Many Downloads
Detects when a dropbox user downloads many documents.
AWS Resource Required Tags
This policy ensures that AWS resources have specific tags, dependent on their resource type.
AWS Console Sign-In WITHOUT Okta Redirect
A user has logged into the AWS console without authenticating via Okta. This rule requires AWS SSO via Okta and both log sources configured.
AWS Software Discovery
A user is obtaining a list of security software, configurations, defensive tools, and sensors that are in AWS.
MongoDB External User Invited
An external user has been invited to a MongoDB org.
ECR CRUD Actions
Unauthorized ECR Create, Read, Update, or Delete event occurred.
Lambda CRUD Actions
Unauthorized lambda Create, Read, Update, or Delete event occurred.
AWS Password Policy Complexity Guidelines
This policy validates that the account password policy enforces the recommended password complexity requirements.
GCP User Added to Privileged Group
A user was added to a group with special previleges
AWS ECR Events
An ECR event occurred outside of an expected account or region
AWS Modify Cloud Compute Infrastructure
Detection when EC2 compute infrastructure is modified outside of expected automation methods.
GSuite External Drive Document
A Google drive resource became externally accessible.
Malicious SSO DNS Lookup
The rule looks for DNS requests to sites potentially posing as SSO domains.
Cisco Umbrella Domain Name Fuzzy Matching
Identify lookups to suspicious domains that could indicate a phishing attack.
Push Security Authorized IdP Login
Login to application with unauthorized identity provider which could indicate a SAMLjacking attack.