Browse Rules

Search and filter across all detection sources

863 rules

panther medium python

Okta Password Accessed

User accessed another user's application password

panther medium python

OneLogin Password Access

User accessed another user's application password

mdecrevoisier medium sigma

Vault credentials manager accessed

Detects scenarios where an attacker attempts to access vault credentials

mdecrevoisier high sigma

Vault credentials manager accessed

Detects scenarios where an attacker attempts to access vault credentials.

sagan critical other

[CISCO-SCA] AWS ECS Credential Access

[CISCO-SCA] AWS ECS Credential Access

sagan critical other

[WINDOWS-SECURITY] Credential Access - Copy NTDS file

[WINDOWS-SECURITY] Credential Access - Copy NTDS file

sagan unknown other

[SONICWALL] Administrator Access denied due to bad credentials

[SONICWALL] Administrator Access denied due to bad credentials

sigma low sigma

Suspicious File Access to Browser Credential Storage

Detects file access to browser credential storage paths by non-browser processes, which may indicate credential access attempts. Adversaries may attempt to access browser credential storage to extract sensitive information such as usernames and passwords or cookies. This behavior is often commonly observed in credential stealing malware.

panther low python

Configuration Required - Sensitive 1Password Item Accessed

Alerts when a user defined list of sensitive items in 1Password is accessed

panther low python

BETA - Sensitive 1Password Item Accessed

Alerts when a user defined list of sensitive items in 1Password is accessed

panther medium python

Databricks Repeated Access to Secrets

Detects repeated secret access (≥10 times in 60 minutes) which may indicate credential harvesting or unauthorized secret enumeration.

panther medium python

Unusual 1Password Client Detected

Detects when unusual or undesirable 1Password clients access your 1Password account

elastic high eql

Potential Remote Credential Access via Registry

Identifies remote access to the registry to potentially dump credential data from the Security Account Manager (SAM) registry hive in preparation for credential access and privileges elevation.

panther medium python

Databricks Repeated Failed Login Attempts

Detects repeated failed login attempts within a 60-minute window, which may indicate credential stuffing, brute force attacks, or compromised credentials.

panther high python

Okta SWA Off-Hours Credential Access - Behavioral

Detects Okta SWA credential access occurring outside normal business hours using behavioral z-score analysis on temporal patterns. Compromised admin accounts often access SWA credentials at unusual times - late at night, during weekends, or from a different geographic location than normal. This detection builds a 90-day baseline for each admin's temporal credential access patterns, then identifies anomalous shifts toward off-hours, late-night, and weekend activity in the last 7 days. **Detecti

panther high python

AWS Compromised IAM Key Quarantine

Detects when an IAM user has the AWSCompromisedKeyQuarantineV2 policy attached to their account.

panther high python

Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral

Detects Okta SWA (Secure Web Authentication) bulk credential extraction, abuse, and access from previously unseen IP addresses or user agents using behavioral z-score and source novelty analysis. SWA apps store credentials in Okta's encrypted vault. Admin accounts with SWA access can view or rotate credentials for users across many apps. This detection builds a 90-day behavioral baseline for each admin's SWA access, credential change patterns, and known source IPs/user agents, then identifies a

elastic-protections high eql

Potential Credential Access via Windows Credential History

Identifies an unusual process accessing Users Windows Credential History File. The CREDHIST file contains previous password related master key hashes used by Microsoft's DPAPI. Adversaries may acquire credentials from the Windows Credential Manager.

sublime high mql

beta.DLP: AWS Access Key

Detects messages containing AWS access keys.

sigma low sigma

Access To Browser Credential Files By Uncommon Applications

Detects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage

hayabusa medium sigma

Windows Credential Manager Access via VaultCmd

List credentials currently stored in Windows Credential Manager via the native Windows utility vaultcmd.exe

sigma medium sigma

Windows Credential Manager Access via VaultCmd

List credentials currently stored in Windows Credential Manager via the native Windows utility vaultcmd.exe

panther low python

AWS KMS CMK Key Rotation

This policy validates that customer master keys (CMKs) have automatic key rotation enabled.

sublime high mql

beta.DLP: Slack Access Token

Detects messages containing Slack access tokens.

elastic-protections high eql

Sensitive File Access - Cloud Credentials

Identifies an unusual process accessing common cloud providers credential files. Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.