Browse Rules

Search and filter across all detection sources

21 rules

sentinel high kql

Guardian- Privacy Protection PII Policy Violation Detection

'This alert creates an incident when Privacy Protection PII Policy Violation detected from the Guardian'

sentinel high kql

Guardian- Special PII Detection Policy Violation Detection

'This alert creates an incident when Special PII Detection Policy Violation detected from the Guardian.'

sublime high mql

beta.DLP: US Passport Number

Detects messages containing US passport numbers.

sublime high mql

beta.DLP: UK Passport

Detects messages containing UK passport numbers.

sublime high mql

beta.DLP: Canadian Social Insurance Number (SIN)

Detects messages containing Canadian Social Insurance Numbers.

sublime high mql

beta.DLP: NHS Number

Detects messages containing UK NHS numbers.

sublime high mql

beta.DLP: US Driver's License

Detects messages containing US driver's license numbers.

sublime high mql

beta.DLP: UK National Insurance Number

Detects messages containing UK National Insurance numbers.

sublime high mql

beta.DLP: UK Driver's License

Detects messages containing UK driver's license numbers.

sublime high mql

beta.DLP: US Individual Taxpayer Identification Number (ITIN)

Detects messages containing US Individual Taxpayer Identification Numbers.

sublime high mql

beta.DLP: US Social Security Number (SSN)

Detects messages containing US Social Security Numbers.

sublime high mql

beta.DLP: UK UTR (Tax)

Detects messages containing UK Unique Taxpayer Reference numbers.

sentinel high kql

Unauthenticated API Endpoint with Sensitive Data

Detects internet-facing API endpoints with no authentication that handle sensitive data classifications (PII, Financial, PHI, Confidential). Uses StratoSecure_ApiInventory_CL from Phase 6 API inventory discovery.

sentinel medium kql

CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule

"This analytics rule detects high severity alerts from CYFIRMA indicating exposure of Personally Identifiable Information (PII) or Confidential Information (CII) in public or unsecured sources. Such leaks may include email addresses, credentials, phone numbers, or other sensitive personal or organizational data. These exposures can lead to identity theft, phishing, credential compromise, or regulatory non-compliance. Investigate promptly and initiate remediation steps including user notificat

sentinel high kql

CYFIRMA - Social and Public Exposure - Exposure of PII/CII in Public Domain Rule

"This analytics rule detects high severity alerts from CYFIRMA indicating exposure of Personally Identifiable Information (PII) or Confidential Information (CII) in public or unsecured sources. Such leaks may include email addresses, credentials, phone numbers, or other sensitive personal or organizational data. These exposures can lead to identity theft, phishing, credential compromise, or regulatory non-compliance. Investigate promptly and initiate remediation steps including user notificat

sublime medium mql

Attachment: Credit card application with WhatsApp contact

Detects messages containing promotional credit card offers with attached forms requesting extensive personal information (PII) and directing victims to contact via WhatsApp, indicating potential fraud.

sentinel high kql

GTI - Data Leak Alert Detected

Triggers an incident when a GTI Relevance System Alert of type data_leak is ingested. Data Leak alerts indicate that sensitive organisational data (credentials, PII, intellectual property, source code, databases, etc.) has been found exposed on the dark web, paste sites, or underground forums and matches your organisation profile. Each unique Alert ID is grouped into a single incident.

panther medium python

Kubernetes Ingress Created Without TLS

This detection monitors for Ingress objects being created without TLS certificates configured. Ingresses without TLS expose services over unencrypted HTTP, allowing sensitive data like passwords, tokens, and PII to be transmitted in cleartext. This violates security best practices and compliance requirements like PCI-DSS and HIPAA, and enables man-in-the-middle attacks.

splunk unknown spl

AWS Credential Access RDS Password reset

The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this could lead to data breaches,

splunk unknown spl

ASL AWS Credential Access RDS Password reset

The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this co

elastic low eql

M365 SharePoint Search for Sensitive Content

Identifies search queries in SharePoint containing sensitive terms related to credentials, financial data, PII, legal matters, or infrastructure information. Adversaries who compromise user accounts often search for high-value files before exfiltration. This rule detects searches containing terms across multiple sensitivity categories, regardless of the access method (browser, PowerShell, or API). The actual search query text is analyzed against a curated list of sensitive terms to identify pote