Browse Rules

Search and filter across all detection sources

23 rules

panther medium python

CloudTrail Password Spraying

Detect password spraying account using a scheduled query

panther informational python

Box New Login

A user logged in from a new device.

panther high python

Logins Without MFA

A console login was made without multi-factor authentication.

panther informational python

Box Untrusted Device Login

A user attempted to login from an untrusted device.

panther high python

AWS Compromised IAM Key Quarantine

Detects when an IAM user has the AWSCompromisedKeyQuarantineV2 policy attached to their account.

panther high python

Logins Without SAML

An AWS console login was made without SAML/SSO.

panther high python

Impossible Travel for Login Action

A user has subsequent logins from two geographic locations that are very far apart

panther medium python

GSuite Login Type

A login of a non-approved type was detected for this user.

panther low python

Suspicious Snowflake Sessions - Unusual Application

Detects unusual (non-common) applications and client characteristics that have been used to connect to a Snowflake account

panther high python

A Login from Outside the Corporate Office

A system has been logged into from a non approved IP space.

panther high python

Box Shield Suspicious Alert Triggered

A user login event or session event was tagged as medium to high severity by Box Shield.

panther medium python

AWS CloudTrail Password Spraying

Detects password spraying attacks by alerting when more than 9 distinct usernames fail to authenticate to the AWS console from the same account and region within 60 minutes.

elastic high kql

Google Workspace Suspended User Account Renewed

Detects when a previously suspended user's account is renewed in Google Workspace. An adversary may renew a suspended user account to maintain access to the Google Workspace organization with a valid account.

panther medium python

Azure Microsoft Graph Single Session from Multiple IP Addresses

Detects when a user signs in to Microsoft Entra ID and subsequently accesses Microsoft Graph from a different IP address using the same session ID. This behavior may indicate OAuth application abuse, session hijacking, token replay attacks, or adversary-in-the-middle attacks where an attacker has obtained a valid session token and is using it from their own infrastructure.

panther high python

Okta SWA Off-Hours Credential Access - Behavioral

Detects Okta SWA credential access occurring outside normal business hours using behavioral z-score analysis on temporal patterns. Compromised admin accounts often access SWA credentials at unusual times - late at night, during weekends, or from a different geographic location than normal. This detection builds a 90-day baseline for each admin's temporal credential access patterns, then identifies anomalous shifts toward off-hours, late-night, and weekend activity in the last 7 days. **Detecti

panther medium python

Google Workspace OAuth Token Requests from New IP

Alerts when users request OAuth tokens from IP addresses they haven't used in the past 30 days, with 3+ requests indicating active usage. This may indicate GAIA credential theft where attackers use stolen refresh tokens to request access tokens from their infrastructure.

panther high python

Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral

Detects Okta SWA (Secure Web Authentication) bulk credential extraction, abuse, and access from previously unseen IP addresses or user agents using behavioral z-score and source novelty analysis. SWA apps store credentials in Okta's encrypted vault. Admin accounts with SWA access can view or rotate credentials for users across many apps. This detection builds a 90-day behavioral baseline for each admin's SWA access, credential change patterns, and known source IPs/user agents, then identifies a

elastic low kql

Successful SSH Authentication from Unusual User

This rule leverages the new_terms rule type to detect successful SSH authentications by a user who has not been authenticated in the last 5 days. This behavior may indicate an attacker attempting to gain access to the system using a valid account.

elastic low kql

Successful SSH Authentication from Unusual IP Address

This rule leverages the new_terms rule type to detect successful SSH authentications by an IP- address that has not been authenticated in the last 5 days. This behavior may indicate an attacker attempting to gain access to the system using a valid account.

elastic high kql

First-Time FortiGate Administrator Login

This rule detects the first observed successful login of a user with the Administrator role to the FortiGate management interface within the last 5 days. First-time administrator logins can indicate newly provisioned accounts, misconfigurations, or unauthorized access using valid credentials and should be reviewed promptly.

panther medium python

Azure Device Code Authentication with Broker Client

Detects device code authentication using the Microsoft Broker Client application, which may indicate Primary Refresh Token (PRT) abuse. Device code flow allows adversaries to trick users into entering codes on attacker-controlled applications. When combined with Microsoft Broker Client (app ID 29d9ed98-a469-4536-ade2-f981bc1d605e), this may indicate PRT theft or replay attacks that bypass MFA and Conditional Access policies.

panther medium python

Okta AD Agent Authentication Anomaly - Z-Score Detection

Detects potential Okta AD Agent token theft and credential abuse using statistical z-score analysis. This detection uses a lookup table containing 90-day behavioral baselines for each user's AD Agent authentication patterns, then calculates z-scores to identify suspicious activity in the last 7 days. **PREREQUISITES:** 1. Baseline builder query must run first: `Query.Okta.ADAgentBaselineBuilder` 2. Lookup table must be configured: `okta_ad_pantherflow_baseline_90d` 3. Allow 24 hours for initia

splunk unknown spl

Azure AD Multiple Users Failing To Authenticate From Ip

The following analytic detects a single source IP failing to authenticate with 30 unique valid users within 5 minutes in Azure Active Directory. It leverages Azure AD SignInLogs with error code 50126, indicating invalid passwords. This behavior is significant as it may indicate a Password Spraying attack, where an adversary attempts to gain initial access or elevate privileges by trying common passwords across many accounts. If confirmed malicious, this activity could lead to unauthorized access