Search and filter across all detection sources
539 rules
[CARBONBLACK-APP-CONTROL] Security Alert (Warning)
[WINDOWS-SECURITY] Suspicious Service Control Command
[WINDOWS-SECURITY] Comsrvc MiniDump Command via Service Control
[WINDOWS-SECURITY] net group domain controllers command executed
[CISCO-UMBRELLA] Command Control Callbacks Security Category Detected and Allowed
[WINDOWS-SECURITY] Kerberos - RC4 Encryption Still Supported by Domain Controller
[WINDOWS-SECURITY] SyncroSetup RMM Installed
EC2 Security Group Modified
An EC2 Security Group was modified.
[WINDOWS-SECURITY] CRITICAL - Microsoft Quick Assist Executed
AWS S3 Bucket Secure Access
Ensures access to S3 buckets is forced to use a secure (HTTPS) connection.
Potential Defense Evasion via Filter Manager Control Program
Identifies attempt to unload a security driver via the Filter Manager Control Program.
CloudTrail Stopped
A CloudTrail Trail was modified.
EC2 VPC Modified
An EC2 VPC was modified.
AWS CloudTrail Management Events Enabled
This policy ensures that at least one CloudTrail has management (control plane) operations logged.
AWS Security Group Tightly Restricts Outbound Traffic
This policy validates that Security Groups have restrictive controls on outbound traffic.
AWS VPC Default Security Group Restrictions
This policy validates that the default Security Group for a given AWS VPC is restricting all inbound and outbound traffic.
VPC Flow Logs Inbound Port Allowlist
VPC Flow Logs observed inbound traffic violating the port allowlist.
VPC Flow Logs Inbound Port Blocklist
VPC Flow Logs observed inbound traffic violating the port blocklist.
EC2 Network ACL Modified
An EC2 Network ACL was modified.
EC2 Network Gateway Modified
An EC2 Network Gateway was modified.
ECR CRUD Actions
Unauthorized ECR Create, Read, Update, or Delete event occurred.
Lambda CRUD Actions
Unauthorized lambda Create, Read, Update, or Delete event occurred.
AWS Security Group Created [snowflake-awscloudtrail]
Detects when an AWS Security Group has been created. AWS security groups act as a virtual firewall for an instance to control inbound and outbound traffic.
AWS Security Group Created [splunk-awscloudtrail]