Browse Rules

Search and filter across all detection sources

745 rules

sentinel medium kql

OCI - Discovery activity

'Detects possible discovery activity.'

sentinel medium kql

Snowflake - Possible discovery activity

'Detects possible discovery activity.'

sigma informational sigma

System Information Discovery

Detects system information discovery commands

sentinel high kql

ApexOne - Attack Discovery Detection

'Detects Attack Discovery Detection events.'

sigma low sigma

Password Policy Discovery - Linux

Detects password policy discovery commands

sigma low sigma

System Information Discovery - Auditd

Detects System Information Discovery commands

sagan unknown other

[AWS-SES] Simple Email Service Discovery Event Detected (GetAccount)

[AWS-SES] Simple Email Service Discovery Event Detected (GetAccount)

sagan unknown other

[AWS-SES] Simple Email Service Discovery Event Detected (GetAccountSendingEnabled)

[AWS-SES] Simple Email Service Discovery Event Detected (GetAccountSendingEnabled)

sagan unknown other

[AWS-SES] Simple Email Service Discovery Event Detected (ListIdentities)

[AWS-SES] Simple Email Service Discovery Event Detected (ListIdentities)

sagan unknown other

[AWS-SES] Simple Email Service Discovery Event Detected (ListVerifiedEmailAddresses)

[AWS-SES] Simple Email Service Discovery Event Detected (ListVerifiedEmailAddresses)

panther medium python

AWS EC2 Download Instance User Data

An entity has accessed the user data scripts of multiple EC2 instances.

panther medium python

AWS CloudTrail SES Enumeration

sagan medium other

[MICROSOFT-ATP] Discovery alert

[MICROSOFT-ATP] Discovery alert

sagan medium other

[PASSWORDSTATE] Discovery Job Deleted

[PASSWORDSTATE] Discovery Job Deleted

sagan medium other

[PASSWORDSTATE] Discovery Job Removed

[PASSWORDSTATE] Discovery Job Removed

sagan medium other

[PASSWORDSTATE] Discovery Job Updated

[PASSWORDSTATE] Discovery Job Updated

sentinel medium kql

Snowflake - Possible privileges discovery activity

'Detects possible privileges discovery activity.'

sigma informational sigma

System and Hardware Information Discovery

Detects system information discovery commands

panther informational python

AWS EC2 Discovery Commands Executed

Multiple different discovery commands were executed by the same EC2 instance. This could indicate a compromised instance.

sagan unknown other

[AWS-SES] Simple Email Service Discovery Command Event Detected (GetSendQuota)

[AWS-SES] Simple Email Service Discovery Command Event Detected (GetSendQuota)

sagan low other

[MCAS] ALERT_DISCOVERY_ANOMALY_DETECTION

[MCAS] ALERT_DISCOVERY_ANOMALY_DETECTION

sagan unknown other

[PASSWORDSTATE] Discovery Job Permissions Added

[PASSWORDSTATE] Discovery Job Permissions Added

sagan high other

[SCREENCONNECT] Suspicious Discovery Command (ipconfig)

[SCREENCONNECT] Suspicious Discovery Command (ipconfig)

sagan high other

[SCREENCONNECT] Suspicious Discovery Command (net)

[SCREENCONNECT] Suspicious Discovery Command (net)

sagan high other

[SCREENCONNECT] Suspicious Discovery Command (systeminfo)

[SCREENCONNECT] Suspicious Discovery Command (systeminfo)