Browse Rules

Search and filter across all detection sources

112 rules

panther high python

MFA Disabled

Detects when Multi-Factor Authentication (MFA) is disabled

panther informational python

New AWS Account Created

A new AWS account was created

panther informational python

New User Account Created

A new account was created

panther informational python

Detection content has been deleted from Panther

Detection content has been removed from Panther.

panther high python

Panther SAML configuration has been modified

An Admin has modified Panther's SAML configuration.

panther medium python

Admin Role Assigned

Assigning an admin role manually could be a sign of privilege escalation

panther medium python

Sign In from Rogue State

Detects when an entity signs in from a nation associated with cyber attacks

panther informational python

Brute Force By IP

An actor user was denied login access more times than the configured threshold.

panther informational python

Brute Force By User

An actor user was denied login access more times than the configured threshold.

panther high python

Okta Support Reset Credential

A Password or MFA factor was reset by Okta Support

panther high python

A User Role with Sensitive Permissions has been Created

A Panther user role has been created that contains admin level permissions.

panther medium python

Okta Support Access Granted

An admin user has granted access to Okta Support to your account

panther high python

Okta MFA Globally Disabled

An admin user has disabled the MFA requirement for your Okta account

panther high python

VPC Flow Logs Inbound Port Allowlist

VPC Flow Logs observed inbound traffic violating the port allowlist.

panther high python

VPC Flow Logs Inbound Port Blocklist

VPC Flow Logs observed inbound traffic violating the port blocklist.

panther high python

A User's Panther Account was Modified

A Panther user's role has been modified. This could mean password, email, or role has changed for the user.

panther informational python

AWS VPC Healthy Log Status

Checks for the log status `SKIPDATA`, which indicates that data was lost either to an internal server error or due to capacity constraints.

panther medium python

VPC Flow Logs Unapproved Outbound DNS Traffic

Alerts if outbound DNS traffic is detected to a non-approved DNS server. DNS is often used as a means to exfiltrate data or perform command and control for compromised hosts. All DNS traffic should be routed through internal DNS servers or trusted 3rd parties.

splunk unknown spl

Windows Modify Registry Disable Toast Notifications

The following analytic detects modifications to the Windows registry that disable toast notifications. It leverages data from the Endpoint.Registry datamodel, specifically monitoring changes to the registry path "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\PushNotifications\\ToastEnabled*" with a value set to "0x00000000". This activity is significant because disabling toast notifications can prevent users from receiving critical system and application updates, which adversaries like Azorul

splunk unknown spl

Windows Modify Registry EnableLinkedConnections

The following analytic detects a suspicious modification to the Windows registry setting for EnableLinkedConnections. It leverages data from the Endpoint.Registry datamodel to identify changes where the registry path is "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLinkedConnections" and the value is set to "0x00000001". This activity is significant because enabling linked connections can allow network shares to be accessed with both standard and administrator-level privileges,

splunk unknown spl

Windows Modify Registry UpdateServiceUrlAlternate

The following analytic detects a suspicious modification to the Windows Update configuration registry key, specifically targeting the UpdateServiceUrlAlternate setting. It leverages data from the Endpoint.Registry datamodel to identify changes to this registry path. This activity is significant because adversaries, including malware like RedLine Stealer, exploit this technique to bypass detection and deploy additional payloads. If confirmed malicious, this modification could allow attackers to r

splunk unknown spl

SSL Certificates with Punycode

The following analytic detects SSL certificates with Punycode domains in the SSL issuer email domain, identified by the prefix "xn--". It leverages the Certificates Datamodel to flag these domains and uses CyberChef for decoding. This activity is significant as Punycode can be used for domain spoofing and phishing attacks. If confirmed malicious, attackers could deceive users and systems, potentially leading to unauthorized access and data breaches.

splunk unknown spl

Windows DisableAntiSpyware Registry

The following analytic detects the modification of the Windows Registry key "DisableAntiSpyware" being set to disable. This detection leverages data from the Endpoint.Registry datamodel, specifically looking for the registry value name "DisableAntiSpyware" with a value of "0x00000001". This activity is significant as it is commonly associated with Ryuk ransomware infections, indicating potential malicious intent to disable Windows Defender. If confirmed malicious, this action could allow attacke

splunk unknown spl

Windows Outlook LoadMacroProviderOnBoot Persistence

The following analytic detects the modification of the Windows Registry key "LoadMacroProviderOnBoot" under Outlook. This enables automatic loading of macros, which could allow malicious scripts to run without notice. This detection leverages data from the Endpoint.Registry datamodel to search for this key being enabled. This activity is significant as it is commonly associated with some malware infections, indicating potential malicious intent to harvest email information.

splunk unknown spl

Cisco IOS XE Implant Access

The following analytic identifies the potential exploitation of the Cisco IOS XE vulnerability, CVE-2023-20198, in the Web User Interface. It monitors POST requests to the "/webui/logoutconfirm.html?logon_hash=*" endpoint using the Web datamodel. This activity can be significant as it indicates potential access request to the implant If confirmed malicious, attackers could maintain privileged access, compromising the device's integrity and security.