Browse Rules

Search and filter across all detection sources

140 rules

sagan medium other

[NETSKOPE] Account activation link validation failed Event Detected

[NETSKOPE] Account activation link validation failed Event Detected

panther medium python

Snowflake Grant to Public Role

Detect additional grants to the public role.

wazuh low xml

ms-exchange: E-mail rcpt is not valid (invalid account).

ms-exchange: E-mail rcpt is not valid (invalid account).

panther medium python

Snowflake Account Admin Granted

Detect when account admin is granted.

panther high python

AWS Root Account Hardware MFA

This policy validates that a hardware MFA device is in use for access to the root account.

panther medium python

Snowflake Account Admin Granted

Detect when account admin is granted.

panther medium python

CloudTrail Password Spraying

Detect password spraying account using a scheduled query

sentinel low kql

Failed logon attempts by valid accounts within 10 mins

'Identifies when failed logon attempts are 20 or higher during a 10 minute period (2 failed logons per minute minimum) from valid account.'

panther high python

Root Console Login

The root account has been logged into.

panther high python

Zendesk Account Owner Changed

Only one admin user can be the account owner. Ensure the change in ownership is expected.

sagan medium other

[CROWDSTRIKE] Possible Privilege Escalation Detected - User Executed Valid Accounts DCE/RPC Command Targeting DC For First Time

[CROWDSTRIKE] Possible Privilege Escalation Detected - User Executed Valid Accounts DCE/RPC Command Targeting DC For First Time

panther medium python

Zendesk Mobile App Access Modified

A user updated account setting that enabled or disabled mobile app access.

panther critical python

AWS Root Account MFA

Validates that Multi-Factor Authentication (MFA) is enabled for the AWS root account. The root account has complete unrestricted access to all AWS resources and is the highest-value target for attackers. Without MFA, accounts are vulnerable to phishing, credential stuffing, and password compromise attacks.

sigma high sigma

Azure AD Account Credential Leaked

Indicates that the user's valid credentials have been leaked.

panther informational python

Box New Login

A user logged in from a new device.

panther low python

Suspicious Snowflake Sessions - Unusual Application

Detects unusual (non-common) applications and client characteristics that have been used to connect to a Snowflake account

panther medium python

AWS IAM Policy Does Not Grant Network Admin Access

This policy validates that no IAM policies grant admin privileges on network resources. This should be used in conjunction with suppressions for the legitimate network admin policies in your account.

panther medium python

AWS IAM Role Restricts Usage

This policy validates that IAM roles in the account are restrictive in what entities may assume them. This can help prevent malicious actors from assuming roles they should not be assuming.

panther informational python

Box Untrusted Device Login

A user attempted to login from an untrusted device.

panther informational python

GitHub User Access Key Created

Detects when a GitHub user access key is created.

panther high python

AWS IAM Policy Administrative Privileges

This policy validates that there are no IAM policies that grant full administrative privileges to IAM users or groups.

panther medium python

Admin Role Assigned

Assigning an admin role manually could be a sign of privilege escalation

panther high python

AWS Compromised IAM Key Quarantine

Detects when an IAM user has the AWSCompromisedKeyQuarantineV2 policy attached to their account.

panther high python

Logins Without MFA

A console login was made without multi-factor authentication.

panther informational python

Okta Admin Role Assigned

A user has been granted administrative privileges in Okta