Browse Rules

Search and filter across all detection sources

69 rules

panther informational python

GCP Tag Binding Creation

Detects the creation of tag bindings in GCP, which could be part of a privilege escalation attempt using tag-based access control.

panther informational python

GCP IAM and Tag Enumeration

Detects enumeration of IAM policies and tags in GCP, which could be a precursor to privilege escalation attempts via tag-based access control.

wazuh informational xml

Docker: Image $(docker.Actor.Attributes.name) tagged

Docker: Image $(docker.Actor.Attributes.name) tagged

sagan high other

[CITRIX] Netscaler - AppFw CSRF tag violation

[CITRIX] Netscaler - AppFw CSRF tag violation

sagan informational other

[AWS-COGNITO] AWS Cognito event detected (TagResource)

[AWS-COGNITO] AWS Cognito event detected (TagResource)

panther informational python

GCP Privilege Escalation via TagBinding

Detects a sequence of events that could indicate a privilege escalation attempt via GCP's tag-based access control. The sequence includes: 1. Enumeration of IAM policies and tags 2. Creation of a tag binding 3. Performance of a privileged operation

sagan medium other

[MIMECAST] Impersonation Protection Tagged Malicious By Threat Dictionary

[MIMECAST] Impersonation Protection Tagged Malicious By Threat Dictionary

sentinel high kql

Vectra Create Incident Based on Tag for Accounts

Create an incident when the account entity presents a specific tag. If the tag is present, an incident should be created and marked with highest priority.

sentinel high kql

Vectra Create Incident Based on Tag for Hosts

Create an incident when the host entity presents a specific tag. If the tag is present, an incident should be created and marked with highest priority.

sagan medium other

[MIMECAST] Impersonation Protection Tagged Malicious By Custom Name Match

[MIMECAST] Impersonation Protection Tagged Malicious By Custom Name Match

sagan medium other

[MIMECAST] Impersonation Protection Tagged Malicious By Custom Threat Dictionary

[MIMECAST] Impersonation Protection Tagged Malicious By Custom Threat Dictionary

sagan medium other

[MIMECAST] Impersonation Protection Tagged Malicious By Similar External Domain

[MIMECAST] Impersonation Protection Tagged Malicious By Similar External Domain

sagan medium other

[MIMECAST] Impersonation Protection Tagged Malicious By Similar Internal Domain

[MIMECAST] Impersonation Protection Tagged Malicious By Similar Internal Domain

yara unknown yara

HasTaggantSignature [packers]

TaggantSignature Check

panther low python

AWS Resource Minimum Tags

This policy ensures that applicable resources have a minimum number of tags set.

sagan medium other

[MIMECAST] Impersonation Protection Tagged Malicious By Similar Custom External Domain

[MIMECAST] Impersonation Protection Tagged Malicious By Similar Custom External Domain

panther low python

AWS Resource Required Tags

This policy ensures that AWS resources have specific tags, dependent on their resource type.

panther medium python

A More Friendly Name

An optional Description

panther medium python

A More Friendly Name

An optional Description

panther informational python

GCP Privileged Operation

Detects privileged operations in GCP that could be part of a privilege escalation attempt, especially when following tag binding creation.

sentinel high kql

Mimecast Targeted Threat Protection - Impersonation Protect

Detects a maliciously tagged impersonation

sentinel high kql

Mimecast Targeted Threat Protection - Impersonation Protect

'Detects a maliciously tagged impersonation.'

chronicle high yara-l

Process Launch VT Enrichment

Identify process creations that are tagged exploit in VT

panther informational python

Suspicious is_suspicious tag

GSuite reported a suspicious activity for this user.

sublime high mql

Service abuse: Google Tag Manager debug cookie clearing with open redirect potential

Detects messages containing links to Google Tag Manager's debug cookie clearing endpoint with suspicious URL parameters that may be exploited for open redirects, or links that have been rewritten through Google Tag Manager encoding methods.