Browse Rules

Search and filter across all detection sources

116 rules

panther informational python

AWS DNS Logs Deleted

Detects when logs for a DNS Resolver have been removed.

panther informational python

AWS VPC Flow Logs Removed

Detects when logs for a VPC have been removed.

panther medium python

CloudTrail Stopped

A CloudTrail Trail was modified.

panther informational python

EC2 VPC Modified

An EC2 VPC was modified.

panther medium python

Account Security Configuration Changed

An account wide security configuration was changed.

panther informational python

AWS CloudTrail Retention Lifecycle Too Short

Detects when an S3 bucket containing CloudTrail logs has been modified to delete data after a short period of time.

panther informational python

EC2 Network ACL Modified

An EC2 Network ACL was modified.

panther informational python

EC2 Network Gateway Modified

An EC2 Network Gateway was modified.

panther informational python

EC2 Security Group Modified

An EC2 Security Group was modified.

panther low python

GSuite User Advanced Protection Change

A user disabled advanced protection for themselves.

panther informational python

Detection content has been deleted from Panther

Detection content has been removed from Panther.

panther high python

Panther SAML configuration has been modified

An Admin has modified Panther's SAML configuration.

panther medium python

OSQuery Reports Application Firewall Disabled

Verifies that MacOS has automatic software updates enabled.

panther high python

Slack Legal Hold Policy Modified

Detects changes to configured legal hold policies

panther medium python

AWS CloudTrail Log Validation

This policy ensures that CloudTrail logs have file integrity validation enabled.

panther medium python

AWS Config Service Disabled

An AWS Config Recorder or Delivery Channel was disabled or deleted

panther medium python

Slack Information Barrier Modified

Detects when a Slack information barrier is deleted/updated

panther low python

AWS S3 Bucket Logging

Ensures that a logging policy is set for the S3 bucket.

panther low python

AWS EC2 Instance Detailed Monitoring

This policy ensures that the AWS Instance has Detailed Monitoring Enabled

panther medium python

AWS Redshift Cluster Logging

This policy validates that Redshift Cluster have logging enabled. This includes audit logs.

panther high python

Carbon Black Data Forwarder Stopped

Detects when a user disables or deletes a Data Forwarder.

panther medium python

AWS CloudTrail Least Privilege Access

Users with permissions to disable or reconfigure CloudTrail should be limited.

panther medium python

AWS VPC Flow Logs

This policy validates that AWS VPCs (Virtual Private Clouds) have network flow logging enabled.

panther medium python

Azure Alert Rules Deleted

Detects when Azure alert rules are deleted. Deleting alert rules disables security notifications and is a common defense evasion technique.

panther high python

AWS ACM Secure Algorithms

This policy validates that all ACM certificates are using secure key and signature algorithms.