Browse Rules

Search and filter across all detection sources

525 rules

sagan critical other

[CROWDSTRIKE] Initial Access Tactic Catchall

[CROWDSTRIKE] Initial Access Tactic Catchall

sagan medium other

[CROWDSTRIKE] Possible Initial Access - A User Accessed An Unusual Location

[CROWDSTRIKE] Possible Initial Access - A User Accessed An Unusual Location

sagan medium other

[CROWDSTRIKE] Possible Initial Access - User accessed IP associated with malicious activity

[CROWDSTRIKE] Possible Initial Access - User accessed IP associated with malicious activity

panther informational python

GitHub User Initial Access to Private Repo

Detects when a user initially accesses a private organization repository.

sagan medium other

[CROWDSTRIKE] Initial Access Tactic - A user accessed distant locations in a short timeframe

[CROWDSTRIKE] Initial Access Tactic - A user accessed distant locations in a short timeframe

sagan informational other

[CROWDSTRIKE] Initial Access Tactic - A stale endpoint became active

[CROWDSTRIKE] Initial Access Tactic - A stale endpoint became active

sagan informational other

[CROWDSTRIKE] Initial Access Tactic - A stale user became active

[CROWDSTRIKE] Initial Access Tactic - A stale user became active

sagan informational other

[CROWDSTRIKE] Initial Access Tactic - A user performed a service access to an endpoint for the first time

[CROWDSTRIKE] Initial Access Tactic - A user performed a service access to an endpoint for the first time

sagan medium other

[CROWDSTRIKE] Possible Initial Access - First-time login to a machine by user

[CROWDSTRIKE] Possible Initial Access - First-time login to a machine by user

sagan medium other

[CROWDSTRIKE] Possible Initial Access - Web-based activity detected as anomalous by ML model

[CROWDSTRIKE] Possible Initial Access - Web-based activity detected as anomalous by ML model

sagan informational other

[CROWDSTRIKE] Initial Access Tactic - A user performed a network login from an unusual machine

[CROWDSTRIKE] Initial Access Tactic - A user performed a network login from an unusual machine

panther medium python

Okta Support Access Granted

An admin user has granted access to Okta Support to your account

sagan medium other

[CROWDSTRIKE] Initial Access Tactic - A user performed a network login from an unusual number of endpoints

[CROWDSTRIKE] Initial Access Tactic - A user performed a network login from an unusual number of endpoints

sagan medium other

[CROWDSTRIKE] Initial Access Tactic - A user performed a network login to an unusual number of endpoints

[CROWDSTRIKE] Initial Access Tactic - A user performed a network login to an unusual number of endpoints

elastic low kql

Unauthorized Access to an Okta Application

Identifies unauthorized access attempts to Okta applications.

panther medium python

Databricks Delta Sharing IP Access Failures

Detects blocked Delta Sharing access attempts due to IP access list restrictions, which may indicate unauthorized access attempts from unexpected locations.

panther high python

Logins Without MFA

A console login was made without multi-factor authentication.

panther medium python

CloudTrail Password Spraying

Detect password spraying account using a scheduled query

panther high python

Logins Without SAML

An AWS console login was made without SAML/SSO.

panther high python

Okta Support Reset Credential

A Password or MFA factor was reset by Okta Support

sentinel high kql

GTI - Initial Access Broker Alert Detected

Triggers an incident when a GTI Relevance System Alert of type initial_access_broker is ingested. Initial Access Broker alerts indicate that a threat actor is advertising or has sold access (credentials, VPN, RDP, admin panels, etc.) to an organisation that matches your profile. These are high-urgency signals that may indicate imminent compromise or an ongoing breach. Each unique Alert ID is grouped into a single incident.

panther informational python

Box New Login

A user logged in from a new device.

elastic-protections high eql

Potential Initial Access via Rogue RDP Server

Identifies attempts to drop an executable file via a malicious RDP connection file. This may indicate an attempt to get initial access by connecting to an adversary controlled malicious RDP server.

panther medium python

S3 Public Access Block Deleted

Detects when S3 bucket public access block configuration is deleted, which could allow unauthorized public access to sensitive data or indicate preparation for data exfiltration.

panther high python

AWS Compromised IAM Key Quarantine

Detects when an IAM user has the AWSCompromisedKeyQuarantineV2 policy attached to their account.