Browse Rules

Search and filter across all detection sources

10 rules

panther high python

Carbon Black Data Forwarder Stopped

Detects when a user disables or deletes a Data Forwarder.

panther high python

Slack EKM Config Changed

Detects when the logging settings for a workspace's EKM configuration has changed

panther informational python

AWS DNS Logs Deleted

Detects when logs for a DNS Resolver have been removed.

panther informational python

AWS VPC Flow Logs Removed

Detects when logs for a VPC have been removed.

panther informational python

AWS CloudTrail Retention Lifecycle Too Short

Detects when an S3 bucket containing CloudTrail logs has been modified to delete data after a short period of time.

panther informational python

AWS CloudTrail Attempt To Leave Org

Detects when an actor attempts to remove an AWS account from an Organization. Security configurations are often defined at the organizational level. Leaving the organization can disrupt or totally shut down these controls.

anvilogic high other

GCP: Firewall Rule Modified [snowflake-gcpaudit]

Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud environments typically utilize restrictive security groups and firewall rules that only allow network activity from trusted IP addresses via expected ports and protocols. An adversary may introduce new firewall rules or policies to allow access into a victim cloud environment. For example, an adversary may use a script or utility that creates new ingress rules in

anvilogic high spl

GCP: Firewall Rule Modified [splunk-gcpaudit]

Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud environments typically utilize restrictive security groups and firewall rules that only allow network activity from trusted IP addresses via expected ports and protocols. An adversary may introduce new firewall rules or policies to allow access into a victim cloud environment. For example, an adversary may use a script or utility that creates new ingress rules in

elastic high kql

AWS CloudTrail Log Updated

Detects updates to an existing CloudTrail trail via UpdateTrail API which may reduce visibility, change destinations, or weaken integrity (e.g., removing global events, moving the S3 destination, or disabling validation). Adversaries can modify trails to evade detection while maintaining a semblance of logging. Validate any configuration change against approved baselines.

elastic high kql

AWS Bedrock Model Invocation Logging Disabled or Modified

Detects when an AWS Bedrock model invocation logging configuration is deleted or overwritten via the DeleteModelInvocationLoggingConfiguration or PutModelInvocationLoggingConfiguration API calls. Model invocation logging is the source that feeds the logs-aws_bedrock.invocation-* dataset relied upon by all data-plane Bedrock detections. An adversary who has gained access to a Bedrock environment can blind defenders by deleting this configuration, or by using the Put API to redirect logs to an att