Browse Rules

Search and filter across all detection sources

5 rules

anvilogic high other

Snowflake Create Integration [snowflake-database_query_history]

Creates a new integration in the system or replaces an existing integration. An integration is a Snowflake object that provides an interface between Snowflake and third-party services.

panther medium python

Salesforce Third-Party Integration Monitoring

Monitors third-party integrations and OAuth connected apps accessing Salesforce. Connected apps use OAuth for authorization and can access data on behalf of users, making them a potential vector for: - Unauthorized data access - Shadow IT applications - Compromised OAuth tokens - Over-privileged integrations This detection triggers on connected app usage events and adjusts severity based on: - Connection type (refresh tokens are higher risk) - App authorization events - Suspicious app naming pa

sentinel high kql

Third party integrated apps

'This query searches for your services by regulating the access of third-party integrated apps. Only allow access to necessary apps that support robust security controls. Third-party applications are not created by Microsoft, so there is a possibility they could be used for malicious purposes like exfiltrating data from your tenancy. Attackers can maintain persistent access to your services through these integrated apps, without relying on compromised accounts.'

anvilogic high spl

Auth0: Native Social Login [splunk-auth0]

Threat actors may attempt to exploit social login integrations to bypass traditional authentication mechanisms using compromised third-party accounts. This use case detects successful native social login events, which could indicate legitimate user authentication or an attacker leveraging stolen social credentials for account takeover.

panther medium python

AWS SSO Access Token Retrieved by Unauthenticated IP

When using AWS in an enterprise environment, best practices dictate to use a single sign-on service for identity and access management. AWS SSO is a popular solution, integrating with third-party providers such as Okta and allowing to centrally manage roles and permissions in multiple AWS accounts. In this post, we demonstrate that AWS SSO is vulnerable by design to device code authentication phishing – just like any identity provider implementing OpenID Connect device code authentication. This