Browse Rules

Search and filter across all detection sources

84 rules

sentinel high kql

GCP Audit Logs - Detect Organization Policy Deletion or Updation

'Detects when a Google Cloud Platform organization policy is deleted or updated. Organization policies provide centralized control over your organization's cloud resources and help ensure security and compliance. Deletion or modification of org policies may indicate an attempt to bypass security controls or weaken the security posture of GCP projects. Adversaries may delete or update organization policies to disable security constraints before performing malicious activities.'

chronicle high yara-l

Google Workspace MFA Disabled

Identifies when multi-factor authentication (MFA) is disabled for a Google Workspace organization. Security teams can monitor for changes to MFA configuration that may weaken the organization's security posture.

panther medium python

Zoom All Meetings Secured With One Option Disabled

A Zoom User turned off your organization's requirement that all meetings are secured with one security option.

panther medium python

AWS EC2 Manual Security Group Change

An EC2 security group was manually updated without abiding by the organization's accepted processes. This rule expects organizations to either use the Console, CloudFormation, or Terraform, configurable in the rule's ALLOWED_USER_AGENTS.

panther medium python

Tracebit Alert

Tracebit maintains security canaries across your organization to detect potential intrusions. This alert indicates that Tracebit has detected activity on security canaries.

sigma high sigma

Github High Risk Configuration Disabled

Detects when a user disables a critical security feature for an organization.

splunk unknown spl

GitHub Organizations Disable 2FA Requirement

The following analytic detects when two-factor authentication (2FA) requirements are disabled in GitHub Organizations. The detection monitors GitHub Organizations audit logs for 2FA requirement changes by tracking actor details, organization information, and associated metadata. For a SOC, identifying disabled 2FA requirements is critical as it could indicate attempts to weaken account security controls. Two-factor authentication is a fundamental security control that helps prevent unauthorized

chronicle high yara-l

GCP Cloud Audit Logging Removed From All Services

Detect when GCP Cloud Audit logs are removed from all services at project or organization level. Audit logging helps organizations maintain security and minimize risk.

chronicle high yara-l

GCP Exempt Principals From Audit Log

Detect when GCP Cloud Audit logs are exempted for principals in all services at project or organization level. Audit logging helps organizations maintain security and minimize risk.

panther critical python

GitHub Org Authentication Method Changed

Detects critical changes to GitHub organization authentication settings including SAML SSO, 2FA requirements, SAML provider configuration, and OAuth restrictions. These foundational security controls protect entire organizations, and unauthorized modifications can enable attackers to bypass identity management, maintain persistence, or prepare for data exfiltration. Legitimate changes are rare and should be well-documented with proper authorization.

panther medium python

Notion Audit Log Exported

A Notion User exported audit logs for your organization’s workspace.

chronicle low yara-l

Google Workspace Password Policy Changed

Identifies when Google Workspace password policy is changed. Security teams can monitor for changes to password policy configuration that may weaken the organization's security posture.

chronicle high yara-l

Google Workspace SAML IDP Configuration Change

Identifies SAML provider configuration changes in Google Workspace. Security teams can monitor for changes to SAML provider configuration that may weaken the organization's security posture.

elastic high kql

MFA Disabled for Google Workspace Organization

Detects when multi-factor authentication (MFA) is disabled for a Google Workspace organization. An adversary may attempt to modify a password policy in order to weaken an organization’s security controls.

panther medium python

Anthropic Organization Settings Updated

Detects when organization-wide settings are modified in Anthropic. These changes can affect security posture for all users (e.g., SSO configuration, data retention, access controls). The updates field identifies which settings were changed.

splunk unknown spl

GitHub Organizations Delete Branch Ruleset

The following analytic detects when branch rulesets are deleted in GitHub Organizations. The detection monitors GitHub Organizations audit logs for branch ruleset deletion events by tracking actor details, repository information, and associated metadata. For a SOC, identifying deleted branch rulesets is critical as it could indicate attempts to bypass code review requirements and security controls. Branch rulesets are essential security controls that enforce code review, prevent force pushes, an

splunk unknown spl

GitHub Organizations Disable Classic Branch Protection Rule

The following analytic detects when classic branch protection rules are disabled in GitHub Organizations. The detection monitors GitHub Organizations audit logs for branch protection removal events by tracking actor details, repository information, and associated metadata. For a SOC, identifying disabled branch protection is critical as it could indicate attempts to bypass code review requirements and security controls. Branch protection rules are essential security controls that enforce code re

panther high python

External GSuite File Share

An employee shared a sensitive file externally with another organization

panther high python

Notion SAML SSO Configuration Changed

A Notion User changed settings to enforce SAML SSO configurations for your organization.

sentinel high kql

Insider Risk_High User Security Incidents Correlation

'This alert joins SecurityAlerts to SecurityIncidents to associate Security Alerts and Incidents with user accounts. This aligns all Microsoft Alerting Products with Microsoft Incident Generating Products (Microsoft Sentinel, M365 Defender) for a count of user security incidents over time. The default threshold is 5 security incidents, and this is customizable per the organization's requirements. Results include UserPrincipalName (UPN), SecurityIncident, LastIncident, ProductName, LastObservedTi

sentinel medium kql

Application Redirect URL Update

'Detects the redirect URL of an app being changed. Applications associated with URLs not controlled by the organization can pose a security risk. Ref: https://docs.microsoft.com/azure/active-directory/fundamentals/security-operations-applications#application-configuration-changes'

panther informational python

AWS CloudTrail Attempt To Leave Org

Detects when an actor attempts to remove an AWS account from an Organization. Security configurations are often defined at the organizational level. Leaving the organization can disrupt or totally shut down these controls.

sigma medium sigma

Activity from Infrequent Country

Detects when a Microsoft Cloud App Security reported when an activity occurs from a location that wasn't recently or never visited by any user in the organization.

sentinel high kql

SSG_Security_Incidents

The security analytic rule is designed to scrutinize network activity involving private IP addresses within an organization's internal network. By filtering log entries to include only those where either the source or the destination IP is private, the rule focuses on internal communications that could indicate unauthorized access, internal threats, or other security anomalies.

panther high python

Microsoft Exchange External Forwarding

Detects when a user creates email forwarding rules to external organizations in Microsoft Exchange Online. This can indicate data exfiltration attempts, where an attacker sets up forwarding to collect emails outside the organization. The rule detects both mailbox forwarding (Set-Mailbox) and inbox rules (New-InboxRule). The detection includes: 1. External organization forwarding based on domain comparison 2. Suspicious forwarding patterns like: - Forwarding without keeping a copy - Deletin