Browse Rules

Search and filter across all detection sources

539 rules

sagan informational other

[CARBONBLACK-APP-CONTROL] Security Alert (Warning)

[CARBONBLACK-APP-CONTROL] Security Alert (Warning)

sagan critical other

[WINDOWS-SECURITY] Suspicious Service Control Command

[WINDOWS-SECURITY] Suspicious Service Control Command

sagan high other

[WINDOWS-SECURITY] Comsrvc MiniDump Command via Service Control

[WINDOWS-SECURITY] Comsrvc MiniDump Command via Service Control

sagan high other

[WINDOWS-SECURITY] Comsrvc MiniDump Command via Service Control

[WINDOWS-SECURITY] Comsrvc MiniDump Command via Service Control

sagan critical other

[WINDOWS-SECURITY] net group domain controllers command executed

[WINDOWS-SECURITY] net group domain controllers command executed

sagan informational other

[CISCO-UMBRELLA] Command Control Callbacks Security Category Detected and Allowed

[CISCO-UMBRELLA] Command Control Callbacks Security Category Detected and Allowed

sagan medium other

[WINDOWS-SECURITY] Kerberos - RC4 Encryption Still Supported by Domain Controller

[WINDOWS-SECURITY] Kerberos - RC4 Encryption Still Supported by Domain Controller

sagan unknown other

[WINDOWS-SECURITY] SyncroSetup RMM Installed

[WINDOWS-SECURITY] SyncroSetup RMM Installed

panther informational python

EC2 Security Group Modified

An EC2 Security Group was modified.

sagan unknown other

[WINDOWS-SECURITY] CRITICAL - Microsoft Quick Assist Executed

[WINDOWS-SECURITY] CRITICAL - Microsoft Quick Assist Executed

panther low python

AWS S3 Bucket Secure Access

Ensures access to S3 buckets is forced to use a secure (HTTPS) connection.

elastic-protections high eql

Potential Defense Evasion via Filter Manager Control Program

Identifies attempt to unload a security driver via the Filter Manager Control Program.

panther medium python

CloudTrail Stopped

A CloudTrail Trail was modified.

panther informational python

EC2 VPC Modified

An EC2 VPC was modified.

panther high python

AWS CloudTrail Management Events Enabled

This policy ensures that at least one CloudTrail has management (control plane) operations logged.

panther low python

AWS Security Group Tightly Restricts Outbound Traffic

This policy validates that Security Groups have restrictive controls on outbound traffic.

panther low python

AWS VPC Default Security Group Restrictions

This policy validates that the default Security Group for a given AWS VPC is restricting all inbound and outbound traffic.

panther high python

VPC Flow Logs Inbound Port Allowlist

VPC Flow Logs observed inbound traffic violating the port allowlist.

panther high python

VPC Flow Logs Inbound Port Blocklist

VPC Flow Logs observed inbound traffic violating the port blocklist.

panther informational python

EC2 Network ACL Modified

An EC2 Network ACL was modified.

panther informational python

EC2 Network Gateway Modified

An EC2 Network Gateway was modified.

panther informational python

ECR CRUD Actions

Unauthorized ECR Create, Read, Update, or Delete event occurred.

panther high python

Lambda CRUD Actions

Unauthorized lambda Create, Read, Update, or Delete event occurred.

anvilogic high other

AWS Security Group Created [snowflake-awscloudtrail]

Detects when an AWS Security Group has been created. AWS security groups act as a virtual firewall for an instance to control inbound and outbound traffic.

anvilogic high spl

AWS Security Group Created [splunk-awscloudtrail]

Detects when an AWS Security Group has been created. AWS security groups act as a virtual firewall for an instance to control inbound and outbound traffic.