Browse Rules

Search and filter across all detection sources

16 rules

panther high python

GitHub Repository Visibility Change

Detects when an organization repository visibility changes.

panther informational python

AWS S3 Bucket Policy Modified

An S3 Bucket was modified.

panther high python

Box Shield Detected Anomalous Download Activity

A user's download activity has altered significantly.

panther high python

CodeBuild Project made Public

An AWS CodeBuild Project was made publicly accessible

panther low python

AWS Network ACL Restricts Outbound Traffic

This policy validates that Network ACLs have some restrictions on outbound traffic.

panther low python

AWS Security Group Restricts Outbound Traffic

This policy validates that Security Groups have some restrictions on outbound traffic.

panther medium python

Box event triggered by unknown or external user

An external user has triggered a box enterprise event.

panther low python

AWS Security Group Tightly Restricts Outbound Traffic

This policy validates that Security Groups have restrictive controls on outbound traffic.

panther low python

Box Large Number of Downloads

A user has exceeded the threshold for number of downloads within a single time frame.

panther high python

AWS RDS Instance Public Access

This Policy checks that an RDS Instance is not accessible from the public internet.

panther low python

Snowflake User Daily Query Volume Spike

Returns instances where a user's cumulative daily query volume is much larger than normal. Could indicate exfiltration attempts.

panther high python

Slack Private Channel Made Public

Detects when a channel that was previously private is made public

panther high python

Azure Storage Account Public Network Access Enabled

Detects when an existing Azure storage account's network settings are modified to enable public network access. This could indicate a potential data exfiltration risk or misconfiguration.

panther critical python

AWS RDS Instance Snapshot Public Access

This policy validates that RDS Instance snapshots are not publicly restorable. This would allow anyone to restore an old version of your database and have full access to its contents.

panther medium python

AWS Security Group Restricts Traffic Leaving CDE

This policy validates that there are restrictions on what type of traffic may leave Security Groups that are considered with the scope of the PCI CDE. These restrictions help ensure that cardholder data does not leave the CDE.

panther high python

Azure VM Disk SAS URI Generated

Detects when a Shared Access Signature (SAS) URI is generated for an Azure VM disk. SAS URIs provide time-limited, unauthenticated access to download disk contents directly from Azure Storage. Adversaries can generate SAS URIs to exfiltrate entire virtual machine disks, including operating systems, applications, and all data. This allows offline analysis to extract credentials, secrets, and sensitive data without detection. This is a critical indicator of data exfiltration and should be investig