Browse Rules

Search and filter across all detection sources

2,250 rules

elastic low eql

GitHub Repo Created

A new GitHub repository was created.

elastic low eql

GitHub PAT Access Revoked

Access to private GitHub organization resources was revoked for a PAT.

elastic low eql

GitHub User Blocked From Organization

A GitHub user was blocked from access to an organization.

elastic low eql

New User Added To GitHub Organization

A new user was added to a GitHub organization.

elastic low kql

First Occurrence of IP Address For GitHub User

Detects a new IP address used for a GitHub user not previously seen in the last 14 days.

elastic low kql

First Occurrence of User-Agent For a GitHub User

Detects a new user agent used for a GitHub user not previously seen in the last 14 days.

elastic low eql

Member Removed From GitHub Organization

A member was removed or their invitation to join was removed from a GitHub Organization.

elastic low kql

First Occurrence of IP Address For GitHub Personal Access Token (PAT)

Detects a new IP address used for a GitHub PAT not previously seen in the last 14 days.

elastic low kql

First Occurrence of GitHub User Interaction with Private Repo

Detects a new private repo interaction for a GitHub user not seen in the last 14 days.

sigma high sigma

Lazarus APT DLL Sideloading Activity

Detects sideloading of trojanized DLLs used in Lazarus APT campaign in the case of a Spanish aerospace company

elastic low kql

First Occurrence of User Agent For a GitHub Personal Access Token (PAT)

Detects a new user agent used for a GitHub PAT not previously seen in the last 14 days.

elastic high kql

Entra ID Protection - Risk Detection - User Risk

Identifies user risk detection events via Microsofts Entra ID Protection service. Entra ID Protection detects user risk activity such as anonymized IP addresses, unlikely travel, password spray, and more.

elastic low kql

First Occurrence of Personal Access Token (PAT) Use For a GitHub User

A new PAT was used for a GitHub user not previously seen in the last 14 days.

hayabusa high sigma

Lazarus APT DLL Sideloading Activity

Detects sideloading of trojanized DLLs used in Lazarus APT campaign in the case of a Spanish aerospace company

elastic high kql

Entra ID Protection - Risk Detection - Sign-in Risk

Identifies sign-in risk detection events via Microsofts Entra ID Protection service. Entra ID Protection detects sign-in activity such as anonymized IP addresses, unlikely travel, password spray, and more.

elastic medium kql

SentinelOne Threat External Alerts

Generates a detection alert for each SentinelOne threat written to the configured indices. Enabling this rule allows you to immediately begin investigating SentinelOne threat alerts in the app.

elastic low kql

First Occurrence GitHub Event for a Personal Access Token (PAT)

Detects a first occurrence event for a personal access token (PAT) not seen in the last 14 days.

anvilogic high other

Snowflake Alter Stage [snowflake-database_query_history]

This use case detects the ALTER STAGE query. - Threat Actor Association: UNC5537 - Software Association: rapeflake

anvilogic medium other

Snowflake Create Share [snowflake-database_query_history]

This use case detects the CREATE SHARE query. - Threat Actor Association: UNC5537 - Software Association: rapeflake

anvilogic medium other

Snowflake Create Stage [snowflake-database_query_history]

This use case detects the CREATE STAGE query. - Threat Actor Association: UNC5537 - Software Association: rapeflake

anvilogic critical other

Snowflake Drop Database [snowflake-database_query_history]

This use case detects the DROP DATABASE query. - Threat Actor Association: UNC5537 - Software Association: rapeflake

anvilogic critical other

Snowflake Drop Stage [snowflake-database_query_history]

This use case detects the DROP STAGE query. - Threat Actor Association: UNC5537 - Software Association: rapeflake

anvilogic critical other

Snowflake Drop Table [snowflake-database_query_history]

This use case detects the DROP TABLE query. - Threat Actor Association: UNC5537 - Software Association: rapeflake

anvilogic high other

Snowflake Monitor Usage [snowflake-database_query_history]

This use case detects the MONITOR USAGE query. - Threat Actor Association: UNC5537 - Software Association: rapeflake

elastic low kql

First Occurrence of GitHub Repo Interaction From a New IP

Detects an interaction with a private GitHub repository from a new IP address not seen in the last 14 days.