Browse Rules

Search and filter across all detection sources

19 rules

sagan unknown other

[RSA-DPM] Swap-Memory Memory status Yellow

[RSA-DPM] Swap-Memory Memory status Yellow

sagan medium other

[CLOUDTRAIL] Elastic Beanstalk cloudtrail event detected - (SwapEnvironmentCNAMEs)

[CLOUDTRAIL] Elastic Beanstalk cloudtrail event detected - (SwapEnvironmentCNAMEs)

sagan unknown other

[RSA-DPM] Swap-Memory Memory status Red [Critical]

[RSA-DPM] Swap-Memory Memory status Red [Critical]

yara unknown yara

SWAG_Archive [packers]

sagan high other

[CITRIX] Netscaler - NS-XML APPFW supports SwA and MTOM SOAP attachments

[CITRIX] Netscaler - NS-XML APPFW supports SwA and MTOM SOAP attachments

yara unknown yara

SWAG_Archive_Hint_FILE_START [packers]

panther high python

Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral

Detects Okta SWA (Secure Web Authentication) bulk credential extraction, abuse, and access from previously unseen IP addresses or user agents using behavioral z-score and source novelty analysis. SWA apps store credentials in Okta's encrypted vault. Admin accounts with SWA access can view or rotate credentials for users across many apps. This detection builds a 90-day behavioral baseline for each admin's SWA access, credential change patterns, and known source IPs/user agents, then identifies a

splunk unknown spl

Linux Hardware Addition SwapOff

The following analytic detects the execution of the "swapoff" command, which disables the swapping of paging devices on a Linux system. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs. This activity is significant because disabling swap can be a tactic used by malware, such as Awfulshred, to evade detection and hinder forensic analysis. If confirmed malicious, this action could allow an attacker to manipulate system memory management, poten

splunk unknown spl

Linux Auditd Hardware Addition Swapoff

The following analytic detects the execution of the "swapoff" command, which disables the swapping of paging devices on a Linux system. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs. This activity is significant because disabling swap can be a tactic used by malware, such as Awfulshred, to evade detection and hinder forensic analysis. If confirmed malicious, this action could allow an attacker to manipulate system memory management, poten

panther high python

Okta SWA Off-Hours Credential Access - Behavioral

Detects Okta SWA credential access occurring outside normal business hours using behavioral z-score analysis on temporal patterns. Compromised admin accounts often access SWA credentials at unusual times - late at night, during weekends, or from a different geographic location than normal. This detection builds a 90-day baseline for each admin's temporal credential access patterns, then identifies anomalous shifts toward off-hours, late-night, and weekend activity in the last 7 days. **Detecti

elastic medium eql

Memory Swap Modification

This rule detects memory swap modification events on Linux systems. Memory swap modification can be used to manipulate the system's memory and potentially impact the system's performance. This behavior is commonly observed in malware that deploys miner software such as XMRig.

sigma medium sigma

Multi Factor Authentication Disabled For User Account

Detects changes to the "StrongAuthenticationRequirement" value, where the state is set to "0" or "Disabled". Threat actors were seen disabling multi factor authentication for users in order to maintain or achieve access to the account. Also see in SIM Swap attacks.

anvilogic high spl

Known Credential Dumping Tool Execution [splunk-edr]

This Use Case would detect if one of the following tools Mimipenguin, Lazagne or swap_digger is downloaded or executed on a Unix host. -- Threat Actor Association: Alloy Taurus/Gallium, APT15, MuddyWater, TeamTNT - Software Association: ALPHV/BlackCat, AvosLocker, LockBit, Ransom Cartel

anvilogic high other

Known Credential Dumping Tool Execution [snowflake-crowdstrikefdr_process]

This Use Case would detect if one of the following tools Mimipenguin, Lazagne or swap_digger is downloaded or executed on a Unix host. -- Threat Actor Association: Alloy Taurus/Gallium, APT15, MuddyWater, TeamTNT - Software Association: ALPHV/BlackCat, AvosLocker, LockBit, Ransom Cartel

anvilogic high spl

Known Credential Dumping Tool Execution [splunk-unix]

This Use Case would detect if one of the following tools Mimipenguin, Lazagne or swap_digger is downloaded or executed on a Unix host. -- Threat Actor Association: Alloy Taurus/Gallium, APT15, MuddyWater, TeamTNT - Software Association: ALPHV/BlackCat, AvosLocker, LockBit, Ransom Cartel

elastic-protections high eql

Potential Privilege Escalation via LocalPotato Exploit

Identifies a privilege escalation attempt via local NTLM relay attack targeting the local SMB server via exploiting a context swapping vulnerability during the authentication process. The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.

splunk unknown spl

Windows Alternate Data Stream Created Over Local Share

The following analytic detects the creation of an NTFS alternate data stream (ADS) accessed over a local administrative share targeting the loopback address (127.0.0.1). It leverages Windows Security Event Logs with EventCode 5145 to identify this activity. Legitimate local processes access files directly rather than through a local SMB share. This behavior is a hallmark of the ShieldBreak exploit, which abuses a symbolic link swap through a loopback share to redirect a privileged, Defender-driv

elastic medium kql

AWS Bedrock Third-Party or External Knowledge Base Associated to Agent

Detects when an Amazon Bedrock agent is associated with, or updated to use, a knowledge base via the AssociateAgentKnowledgeBase, or UpdateAgentKnowledgeBase API actions. Bedrock agents consume knowledge base (RAG) content as trusted context for the model. By wiring an agent to an externally controlled or third-party knowledge base, or by swapping in an attacker-controlled knowledge base, an adversary can redraw the agent's trust boundary toward an untrusted source. This is a software-supply-

elastic medium kql

Azure AD Graph Access with Unusual Client and User

Identifies Azure AD Graph (graph.windows.net) requests where the combination of calling OAuth client ("azure.aadgraphactivitylogs.properties.app_id") and signed-in user ("user.id") has not been observed in the tenant in a historical window. A user appearing against AAD Graph under an OAuth client that has not previously authenticated that user is a sign of a FOCI swap, a phished refresh token being redeemed for a new client, or an adversary running tooling under a client identity the user does n