Browse Rules

Search and filter across all detection sources

74 rules

panther high python

Atlassian admin impersonated another user

Reports when an Atlassian user logs in (impersonates) another user.

sagan informational other

[TENABLE] An administrator started impersonating another user

[TENABLE] An administrator started impersonating another user

sagan medium other

[MIMECAST] An internal user name has been impersonated

[MIMECAST] An internal user name has been impersonated

sentinel medium kql

User Session Impersonation(Okta)

This query detects instances of user session impersonation, where an attacker successfully initiates a session impersonation event. The query extracts detailed information about the target user and the actor involved in the impersonation, providing insights into potential privilege escalation activities.

anvilogic high other

Okta: User impersonation [snowflake-okta]

User.session.impersonation events are normally triggered when an Okta Support person requests admin access.

anvilogic high spl

Okta: User impersonation [splunk-okta]

User.session.impersonation events are normally triggered when an Okta Support person requests admin access.

sagan informational other

[TENABLE] An administrator started a session where they impersonated another user

[TENABLE] An administrator started a session where they impersonated another user

sentinel medium kql

GitLab - User Impersonation

'This queries GitLab Audit Logs for user impersonation. A malicious operator or a compromised admin account could leverage the impersonation feature of GitLab to change code or repository settings bypassing usual processes. This hunting queries allows you to track the audit actions done under impersonation.'

elastic high kql

Okta User Session Impersonation

A user has initiated a session impersonation granting them access to the environment with the permissions of the user they are impersonating. This would likely indicate Okta administrative access and should only ever occur if requested and expected.

bertjanp unknown kql

List the top 10 accounts that have the most impersonators

This query lists the top 10 accounts that have performed the most imporsonated users. The definiation for this field is: Indicates whether the activity was performed by one user for another (impersonated) user.

sentinel medium kql

User impersonation by Identity Protection alerts

'This detection focuses on identifying user-related events involving IAM roles, groups, user access, and password changes. It examines instances where the user's IP address matches and alerts generated by Identity Protection share the same IP address. The analysis occurs within a time window of 1 hour, helping to flag potential cases of user impersonation.'

bertjanp unknown kql

List the top 100 accounts that have performed the most impersonated actions

This query lists the top 100 accounts that have performed the most imporsonated actions. The definiation for this field is: Indicates whether the activity was performed by one user for another (impersonated) user.

sublime medium mql

Brand impersonation: ukr[.]net

Impersonation of ukr[.]net. Originally reported by CERT-UA on 07 March, 2022, phishing emails impersonate ukr[.]net to steal user credentials. "Compromised mailboxes are used by the Russian Federation's special services to conduct cyber attacks on citizens of Ukraine."

sublime high mql

Credential phishing: Email delivery failure impersonation

Detects phishing emails impersonating email system notifications claiming delivery failures, rejected messages, or email system issues requiring user action to 'fix' or 'recover' email functionality. These attacks typically claim incoming emails couldn't be delivered and direct users to malicious portals to harvest credentials.

sublime medium mql

Attachment: PDF with Microsoft Purview message impersonation

Detects PDF attachments containing text that impersonates Microsoft Purview secure message notifications, potentially used to trick users into believing they have received legitimate secure communications from Microsoft services.

splunk unknown spl

M365 Copilot Impersonation Jailbreak Attack

Detects M365 Copilot impersonation and roleplay jailbreak attempts where users try to manipulate the AI into adopting alternate personas, behaving as unrestricted entities, or impersonating malicious AI systems to bypass safety controls. The detection searches exported eDiscovery prompt logs for roleplay keywords like "pretend you are," "act as," "you are now," "amoral," and "roleplay as" in the Subject_Title field. Prompts are categorized into specific impersonation types (AI_Impersonation, Mal

sublime high mql

Brand Impersonation: Google (QR Code)

Detects messages using Google based lures, referencing or including a QR code from an Unsolicited sender. These messages often lead users to phishing sites or initiate unwanted downloads.

sublime high mql

Brand impersonation: Adobe (QR code)

Detects messages using Adobe image based lures, referencing or including a QR code from an Unsolicited sender. These messages often lead users to phishing sites or initiate unwanted downloads.

sublime high mql

Brand impersonation: DocuSign (QR code)

Detects messages using DocuSign image based lures, referencing or including a QR code from an Unsolicited sender. These messages often lead users to phishing sites or initiate unwanted downloads.

sublime high mql

Brand impersonation: Microsoft (QR code)

Detects messages using Microsoft image based lures, referencing or including a QR code from an Unsolicited sender. These messages often lead users to phishing sites or initiate unwanted downloads.

mdecrevoisier high sigma

Computer account manipulation for delegation (RBCD)

Detects scenarios where an attacker manipulate a computer object and updates its attribute 'msDS-AllowedToActOnBehalfOfOtherIdentity' to enable a resource to impersonate and authenticate any domain user.

sentinel high kql

CYFIRMA - Brand Intelligence - Domain Impersonation High Rule

"This analytics rule detects high-risk domain impersonation activity, where newly registered or existing domains closely resemble the legitimate brand name or organizational assets. These suspicious domains may use typosquatting, homoglyphs, or brand keywords to mislead users, steal credentials, or host phishing/malicious content. The domains are identified through CYFIRMA's external threat intelligence feeds and flagged due to potential misuse in impersonation, fraud, or social engineering at

sentinel medium kql

CYFIRMA - Brand Intelligence - Domain Impersonation Medium Rule

"This analytics rule detects high-risk domain impersonation activity, where newly registered or existing domains closely resemble the legitimate brand name or organizational assets. These suspicious domains may use typosquatting, homoglyphs, or brand keywords to mislead users, steal credentials, or host phishing/malicious content. The domains are identified through CYFIRMA's external threat intelligence feeds and flagged due to potential misuse in impersonation, fraud, or social engineering at

sigma high sigma

AWS Identity Center Identity Provider Change

Detects a change in the AWS Identity Center (FKA AWS SSO) identity provider. A change in identity provider allows an attacker to establish persistent access or escalate privileges via user impersonation.

sublime high mql

Impersonation: Fake Gmail attachment

Message detects fake Gmail attachments by inspecting the body of a message for elements found within Gmail's user interface for attachment. In expected use, these elements only appears within the gmail WebUI and not within the body of message. The presence of this within message indicates a fake attachment.