Browse Rules

Search and filter across all detection sources

259 rules

anvilogic high spl

Multiple Host logons [splunk-unix]

Use case looks for users who have logged into multiple hosts. -- Threat Actor Association: CL-STA-0043

elastic high kql

CyberArk Privileged Access Security Error

Identifies the occurrence of a CyberArk Privileged Access Security (PAS) error level audit event. The event.code correlates to the CyberArk Vault Audit Action Code.

anvilogic medium other

GCP: API Key Created [snowflake-gcpaudit]

This use case detects when an API key has been created for a GCP project.

anvilogic medium spl

GCP: API Key Created [splunk-gcpaudit]

This use case detects when an API key has been created for a GCP project.

anvilogic high spl

O365 Login Events [splunk-apply_al(avl_r7397)]

This use case looks for O365 Login Events. - Threat Actor Association: Lapsus$

elastic low eql

Unusual Login Activity

Identifies an unusually high number of authentication attempts.

anvilogic high spl

Clear Linux System Logs [splunk-unix]

This use case would detect the alteration or removal of log files. Atomics T1070.003 Test #3 Atomics T1070.003 Test #5

anvilogic high spl

Azure Impossible Travels Sign-in [splunk-azure]

This use case looks for user signins from multiple locations by time and distance.

anvilogic medium spl

NIX Interactive Shell [splunk-unix]

This use case detects the creation of an interactive shell on a NIX host -- Software Association: Kinsing

anvilogic high spl

O365 Impossible Travels Sign-in [splunk-o365]

This use case looks for user signins from multiple locations by time and distance.

anvilogic medium spl

O365 Inbox Rules [splunk-o365]

This use case looks for potential malicious activity regard inbox rules. -- Threat Actor Association: Lapsus$, SEABORGIUM

anvilogic high spl

O365 Multiple signins from Same IP address [splunk-o365]

This use case looks for multiple signings from the same IP address.

elastic high kql

CyberArk Privileged Access Security Recommended Monitor

Identifies the occurrence of a CyberArk Privileged Access Security (PAS) non-error level audit event which is recommended for monitoring by the vendor. The event.code correlates to the CyberArk Vault Audit Action Code.

elastic medium eql

Attempt to Disable Auditd Service

Adversaries may attempt to disable the Auditd service to evade detection. Auditd is a Linux service that provides system auditing and logging. Disabling the Auditd service can prevent the system from logging important security events, which can be used to detect malicious activity.

elastic high eql

Entra ID Sign-in BloodHound Suite User-Agent Detected

Identifies potential enumeration activity using AzureHound, SharpHound, or BloodHound across Microsoft cloud services. These tools are often used by red teamers and adversaries to map users, groups, roles, applications, and access relationships within Microsoft Entra ID (Azure AD) and Microsoft 365.

anvilogic critical spl

Web: Potential file transfer using SCP [splunk-unix]

This use case is searching for specific keywords that are generated when a SCP file transfer - Threat Actor Association: Lazarus

elastic high kql

AWS CloudTrail Log Suspended

Detects Cloudtrail logging suspension via StopLogging API. Stopping CloudTrail eliminates forward audit visibility and is a classic defense evasion step before sensitive changes or data theft. Investigate immediately and determine what occurred during the logging gap.

anvilogic medium spl

Kubernetes Update Pod Configuration [splunk-unix]

This use case looks for when a pod configuration has been modified with kubectl-edit, scale, autoscale, or replace.

elastic high kql

Entra ID Conditional Access Policy (CAP) Modified

Identifies a modification to a conditional access policy (CAP) in Microsoft Entra ID. Adversaries may modify existing CAPs to loosen access controls and maintain persistence in the environment with a compromised identity or entity.

anvilogic high other

GSUITE Successful login from Suspicious Country [snowflake-gsuite]

Looks for suspicious authentication in google workspace based on Country. Note: This use case will require allow listing for specific countries per organization in order to function correctly.

anvilogic high spl

GSUITE Successful login from Suspicious Country [splunk-gsuite]

Looks for suspicious authentication in google workspace based on Country. Note: This use case will require allow listing for specific countries per organization in order to function correctly.

anvilogic low spl

Kubernetes Enumeration [splunk-unix]

This use case looks for when the Kubectl get command has been executed. -- Threat Actor Association: TeamTNT -- Atomics T1053.007 Test#1

anvilogic high spl

SSH Pivoting [splunk-unix]

This use case is searching for specific keywords that are generated when SSH pivoting is made - Threat Actor Association: Daixin Team, Lightbasin / UNC1945, TeamTNT

anvilogic high spl

O365 New Management Role Assignment [splunk-o365]

Use case looks for when a new role has been assigned to a management group in Office 365. Adversaries may use this tactic for continued persistence. - Threat Actor Association: Lapsus$

elastic medium kql

Entra ID Actor Token User Impersonation Abuse

Identifies potential abuse of actor tokens in Microsoft Entra ID audit logs. Actor tokens are undocumented backend mechanisms used by Microsoft for service-to-service (S2S) operations, allowing services to perform actions on behalf of users. These tokens appear in logs with the service's display name but the impersonated user's UPN. While some legitimate Microsoft operations use actor tokens, unexpected usage may indicate exploitation of CVE-2025-55241, which allowed unauthorized access to Azure