Browse Rules

Search and filter across all detection sources

230 rules

wazuh informational xml

Security Configuration Assessment: check event

Security Configuration Assessment: check event

wazuh informational xml

Group of Security Configuration Assessment rules

Group of Security Configuration Assessment rules

panther medium python

Account Security Configuration Changed

An account wide security configuration was changed.

sigma medium sigma

Azure Network Security Configuration Modified or Deleted

Identifies when a network security configuration is modified or deleted.

wazuh low xml

The configuration data registry key, sub key or configuration data cache folder were not secured properly

The configuration data registry key, sub key or configuration data cache folder were not secured properly

sagan informational other

[CISCO-MERAKI] Changes to Security-Related Configurations Log Detected

[CISCO-MERAKI] Changes to Security-Related Configurations Log Detected

sagan informational other

[WINDOWS-SECURITY] A configuration entry changed in OCSP Responder Service

[WINDOWS-SECURITY] A configuration entry changed in OCSP Responder Service

sagan informational other

[WINDOWS-SECURITY] A configuration entry changed in OCSP Responder Service

[WINDOWS-SECURITY] A configuration entry changed in OCSP Responder Service

sagan informational other

[WINDOWS-SECURITY] A configuration entry changed in OCSP Responder Service

[WINDOWS-SECURITY] A configuration entry changed in OCSP Responder Service

sagan informational other

[WINDOWS-SECURITY] A configuration entry changed in OCSP Responder Service

[WINDOWS-SECURITY] A configuration entry changed in OCSP Responder Service

chronicle high yara-l

Google Workspace SAML IDP Configuration Change

Identifies SAML provider configuration changes in Google Workspace. Security teams can monitor for changes to SAML provider configuration that may weaken the organization's security posture.

chronicle high yara-l

sap_security_audit_log_configuration_change

Detects changes to the SAP Security Audit Log configuration. Monitoring message codes AUE, AUF, AUI, AUJ, FU0, and E05.

panther medium python

Okta Login Without Push Marker

panther low python

AWS S3 Bucket Lifecycle Configuration

Verifies that the S3 Bucket Object Lifecycle configuration expires data within 90 and 365 days.

sentinel informational kql

VMware SD-WAN - Orchestrator Audit Event

This rule is searching for configuration changes. Configuration changes can override security measures and the overarching security design. Therefore audit events must be accurately tracked.

wazuh low xml

Monitored: A security event was monitored; however, it was not blocked, due to the current configuration.

Monitored: A security event was monitored; however, it was not blocked, due to the current configuration.

bertjanp unknown kql

Prioritize Secure Configuration

This query helps you prioritize configuration changes that affect your devices based on the Microsoft Defender TVM modules.

panther informational python

AWS Software Discovery

A user is obtaining a list of security software, configurations, defensive tools, and sensors that are in AWS.

panther high python

Notion SAML SSO Configuration Changed

A Notion User changed settings to enforce SAML SSO configurations for your organization.

panther medium python

Databricks High Priority Configuration Changes

Detects high-priority security configuration changes including audit logging modifications, IP access list changes, and security-critical workspace settings. Severity is elevated for successful changes to high-risk settings.

splunk unknown spl

Windows WinSCP Configuration Security Access

This analytic detects unauthorized access to the WinSCP security configuration folder by processes other than WinSCP itself. WinSCP stores sensitive SSH and FTP session credentials, including passwords and private key references, under the user profile path Martin Prikryl\WinSCP 2\Configuration\Security. Information-stealing malware such as Phantom Stealer targets this directory to harvest stored credentials for exfiltration. The detection uses Windows Security Event 4663 (Object Access) to iden

panther medium python

AWS EC2 Manual Security Group Change

An EC2 security group was manually updated without abiding by the organization's accepted processes. This rule expects organizations to either use the Console, CloudFormation, or Terraform, configurable in the rule's ALLOWED_USER_AGENTS.

panther informational python

Databricks Workspace-Level Configuration Changes

Detects configuration changes at the Databricks workspace level. Workspace-level changes affect a single workspace and include settings like cluster configurations, notebook settings, and workspace-specific security controls.

panther medium python

Azure Network Security Configuration Modified or Deleted

Identifies when a network security configuration is modified or deleted. This includes Network Security Group (NSG) changes, security rule modifications, NSG joins to subnets/interfaces, and diagnostic settings changes. These actions may indicate defense evasion, persistence, or preparation for data exfiltration.

panther high python

AWS ACM Secure Algorithms

This policy validates that all ACM certificates are using secure key and signature algorithms.