Browse Rules

Search and filter across all detection sources

260 rules

sagan medium other

[CISCO-SECUREENDPOINT] iOS Network Detection

[CISCO-SECUREENDPOINT] iOS Network Detection

sagan critical other

[CISCO-SCA] Azure Network Security Group

[CISCO-SCA] Azure Network Security Group

sigma medium sigma

Azure Network Security Configuration Modified or Deleted

Identifies when a network security configuration is modified or deleted.

sagan informational other

[WINDOWS-SECURITY] Network Policy Server quarantined a user

[WINDOWS-SECURITY] Network Policy Server quarantined a user

sagan informational other

[WINDOWS-SECURITY] Network Policy Server quarantined a user

[WINDOWS-SECURITY] Network Policy Server quarantined a user

sagan informational other

[WINDOWS-SECURITY] Network Policy Server unlocked the user account

[WINDOWS-SECURITY] Network Policy Server unlocked the user account

sagan informational other

[WINDOWS-SECURITY] Network Policy Server unlocked the user account

[WINDOWS-SECURITY] Network Policy Server unlocked the user account

sagan informational other

[WINDOWS-SECURITY] Network Policy Server denied access to a user

[WINDOWS-SECURITY] Network Policy Server denied access to a user

sagan informational other

[WINDOWS-SECURITY] Network Policy Server denied access to a user

[WINDOWS-SECURITY] Network Policy Server denied access to a user

sagan informational other

[WINDOWS-SECURITY] Network Policy Server discarded the request for a user

[WINDOWS-SECURITY] Network Policy Server discarded the request for a user

sagan informational other

[WINDOWS-SECURITY] Network Policy Server discarded the accounting request for a user

[WINDOWS-SECURITY] Network Policy Server discarded the accounting request for a user

panther medium python

Azure Excessive Network Security Group Read

Detects excessive read operations on Azure Network Security Groups. Adversaries may repeatedly read Network Security Group configurations to map network ports and firewall rules as part of reconnaissance activities. This pattern can indicate an attacker attempting to understand network security controls before launching lateral movement or exfiltration attacks. The threshold-based detection triggers when the same resource is read excessively within a time window.

panther informational python

EC2 Network ACL Modified

An EC2 Network ACL was modified.

panther informational python

EC2 Network Gateway Modified

An EC2 Network Gateway was modified.

panther medium python

Upwind Network Detection Passthrough

Re-raises Upwind network security detections in Panther. Covers port scans, DoS activity, DNS anomalies, DNS-over-HTTPS abuse, and other anomalous network behaviors.

panther medium python

Azure Network Security Configuration Modified or Deleted

Identifies when a network security configuration is modified or deleted. This includes Network Security Group (NSG) changes, security rule modifications, NSG joins to subnets/interfaces, and diagnostic settings changes. These actions may indicate defense evasion, persistence, or preparation for data exfiltration.

splunk unknown spl

Detect Port Security Violation

The following analytic detects port security violations on Cisco switches. It leverages logs from Cisco network devices, specifically looking for events with mnemonics indicating port security violations. This activity is significant because it indicates an unauthorized device attempting to connect to a secured port, potentially bypassing network access controls. If confirmed malicious, this could allow an attacker to gain unauthorized access to the network, leading to data exfiltration, network

sagan informational other

[WINDOWS-SECURITY] Network Policy Server locked the user account due to repeated failed authentication attempts

[WINDOWS-SECURITY] Network Policy Server locked the user account due to repeated failed authentication attempts

sagan informational other

[WINDOWS-SECURITY] Network Policy Server locked the user account due to repeated failed authentication attempts

[WINDOWS-SECURITY] Network Policy Server locked the user account due to repeated failed authentication attempts

sagan informational other

[WINDOWS-SECURITY] IPsec Services failed to get the complete list of network interfaces on the computer

[WINDOWS-SECURITY] IPsec Services failed to get the complete list of network interfaces on the computer

sentinel high kql

NetworkSecurityGroups Alert From Prancer

'High severity network security groups alerts found by Prancer.'

sublime medium mql

Brand impersonation: Barracuda Networks

Impersonation of Barracuda Networks, an IT security company.

sagan informational other

[WINDOWS-SECURITY] IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces

[WINDOWS-SECURITY] IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces

sagan informational other

[WINDOWS-SECURITY] IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces

[WINDOWS-SECURITY] IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces

elastic medium kql

Attempt to Deactivate an Okta Network Zone

Detects attempts to deactivate an Okta network zone. Okta network zones can be configured to limit or restrict access to a network based on IP addresses or geolocations. An adversary may attempt to modify, delete, or deactivate an Okta network zone in order to remove or weaken an organization's security controls.