Browse Rules

Search and filter across all detection sources

15 rules

sublime high mql

beta.DLP: Australia Medicare

Detects messages containing Australian Medicare numbers.

sublime high mql

beta.DLP: Hungary TAJ

Detects messages containing Hungarian social security (TAJ) numbers.

sublime high mql

beta.DLP: Canada Health Service Number

Detects messages containing Canadian health service numbers.

sublime high mql

beta.DLP: Canada PHIN

Detects messages containing Canadian Personal Health Identification Numbers (PHIN).

sublime high mql

beta.DLP: Finland European Health Insurance

Detects messages containing Finnish European Health Insurance card numbers.

sublime high mql

beta.DLP: National Provider Identifier (NPI)

Detects messages containing US National Provider Identifier (NPI) numbers.

sublime high mql

beta.DLP: New Zealand MOH

Detects messages containing New Zealand Ministry of Health numbers.

sublime medium mql

Brand impersonation: United Healthcare

Detects messages impersonating United Healthcare (UHC) by analyzing display names that contain variations of 'United Healthcare' or 'UHC', including those with character substitutions. The rule excludes legitimate messages from verified UHC domains that pass DMARC authentication and handles high-trust sender domains appropriately.

sentinel high kql

Theom - Healthcare data unencrypted

"Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0004 (Healthcare data has been observed in unencrypted data stores. Encrypt data at rest to comply with this CIS requirement)"

sentinel high kql

Theom - Healthcare data exposed

"Creates Sentinel incidents for critical/high Theom risks, associated with ruleId TRIS0015 (Theom has observed healthcare data in a data store that is publicly exposed. As per this requirement, use this information to apply data access control lists or access permissions to secure your data)"

sublime high mql

beta.DLP: DEA Number

Detects messages containing US Drug Enforcement Administration (DEA) numbers.

sublime high mql

beta.DLP: US Medicare Beneficiary ID

Detects messages containing US Medicare Beneficiary Identification numbers.

sublime high mql

Benefits enrollment impersonation

Detects messages about benefit enrollment periods and healthcare selections from external senders that contain urgent language or requests for action. Excludes legitimate HR communications, marketing mailers, and trusted sender domains with valid authentication.

splunk unknown spl

AWS Credential Access RDS Password reset

The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this could lead to data breaches,

splunk unknown spl

ASL AWS Credential Access RDS Password reset

The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this co