Search and filter across all detection sources
73 rules
AWS DNS Logs Deleted
Detects when logs for a DNS Resolver have been removed.
AWS VPC Flow Logs Removed
Detects when logs for a VPC have been removed.
CloudTrail Stopped
A CloudTrail Trail was modified.
EC2 VPC Modified
An EC2 VPC was modified.
Account Security Configuration Changed
An account wide security configuration was changed.
AWS CloudTrail Retention Lifecycle Too Short
Detects when an S3 bucket containing CloudTrail logs has been modified to delete data after a short period of time.
EC2 Network ACL Modified
An EC2 Network ACL was modified.
EC2 Network Gateway Modified
An EC2 Network Gateway was modified.
EC2 Security Group Modified
An EC2 Security Group was modified.
GSuite User Advanced Protection Change
A user disabled advanced protection for themselves.
Detection content has been deleted from Panther
Detection content has been removed from Panther.
Panther SAML configuration has been modified
An Admin has modified Panther's SAML configuration.
Azure Alert Rules Deleted
Detects when Azure alert rules are deleted. Deleting alert rules disables security notifications and is a common defense evasion technique.
OSQuery Reports Application Firewall Disabled
Verifies that MacOS has automatic software updates enabled.
Slack Legal Hold Policy Modified
Detects changes to configured legal hold policies
AWS CloudTrail Log Validation
This policy ensures that CloudTrail logs have file integrity validation enabled.
AWS Config Service Disabled
An AWS Config Recorder or Delivery Channel was disabled or deleted
Slack Information Barrier Modified
Detects when a Slack information barrier is deleted/updated
AWS S3 Bucket Logging
Ensures that a logging policy is set for the S3 bucket.
AWS EC2 Instance Detailed Monitoring
This policy ensures that the AWS Instance has Detailed Monitoring Enabled
AWS Redshift Cluster Logging
This policy validates that Redshift Cluster have logging enabled. This includes audit logs.
Carbon Black Data Forwarder Stopped
Detects when a user disables or deletes a Data Forwarder.
AWS CloudTrail Least Privilege Access
Users with permissions to disable or reconfigure CloudTrail should be limited.
AWS VPC Flow Logs
This policy validates that AWS VPCs (Virtual Private Clouds) have network flow logging enabled.
Azure Log Analytics Workspace Deleted
Detects when an Azure Log Analytics Workspace is deleted. Deleting a Log Analytics Workspace destroys centralized logging infrastructure and is a defense evasion technique.