Browse Rules

Search and filter across all detection sources

30 rules

sagan informational other

[BOMGAR] Beyond Trust account_changed

[BOMGAR] Beyond Trust account_changed

sagan informational other

[BOMGAR] Beyond Trust accounts_changed

[BOMGAR] Beyond Trust accounts_changed

sagan informational other

[BOMGAR] Beyond Trust management_account_changed

[BOMGAR] Beyond Trust management_account_changed

sentinel medium kql

SlackAudit - User email linked to account changed.

'Detects when user email linked to account changes.'

panther high python

Snyk Service Account Change

Detects when Snyk Service Accounts are changed

panther high python

Wiz Service Account Change

This rule detects creations, updates and deletions of service accounts.

panther informational python

Signal - Notion Account Changed

A Notion User changed their account information.

wazuh medium xml

Windows: User account changed.

Windows: User account changed.

wazuh low xml

Windows: Group Account Changed

Windows: Group Account Changed

sentinel low kql

F&O - Bank account change following network alias reassignment

Identifies changes to user accounts where the network alias was modified to a new value. Shortly afterwards, the updated alias is used to update a bank account number.

sentinel medium kql

Pathlock TDnR - G/L Account Changes

Detects changes to General Ledger (G/L) accounts in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized modifications to G/L accounts may indicate financial data manipulation, accounting fraud, or attempts to conceal unauthorised transactions.

wazuh medium xml

ASA: User created or modified on the Firewall.

ASA: User created or modified on the Firewall.

sentinel low kql

User Added to Admin Role

'Detects a user being added to a new privileged role. Monitor these additions to ensure the users are made eligible for these roles are intended to have these levels of access. Ref: https://docs.microsoft.com/azure/active-directory/fundamentals/security-operations-privileged-accounts#changes-to-privileged-accounts'

sentinel medium kql

Privileged Account Permissions Changed

'Detects changes to permissions assigned to admin users. Threat actors may try and increase permission scope by adding additional roles to already privileged accounts. Review any modifications to ensure they were made legitimately. Ref: https://docs.microsoft.com/azure/active-directory/fundamentals/security-operations-privileged-accounts#changes-to-privileged-accounts'

wazuh low xml

Windows: User account unlocked.

Windows: User account unlocked.

sentinel medium kql

Service Principal Assigned Privileged Role

'Detects a privileged role being added to a Service Principal. Ensure that any assignment to a Service Principal is valid and appropriate - Service Principals should not be assigned to very highly privileged roles such as Global Admin. Ref: https://docs.microsoft.com/azure/active-directory/fundamentals/security-operations-privileged-accounts#changes-to-privileged-accounts'

splunk unknown spl

Windows Computer Account Changed to Domain Controller

Detects a modification to the User Account Control flags for a computer account where the `SERVER_TRUST_ACCOUNT` flag is set. This flag is normally associated with domain controller computer accounts. This activity may indicate a legitimate domain controller promotion or, if unexpected, an attempt to grant a computer account domain controller-like trust within Active Directory.

sentinel high kql

Changes to PIM Settings

'PIM provides a key mechanism for assigning privileges to accounts, this query detects changes to PIM role settings. Monitor these changes to ensure they are being made legitimately and don't confer more privileges than expected or reduce the security of a PIM elevation. Ref: https://docs.microsoft.com/azure/active-directory/fundamentals/security-operations-privileged-accounts#changes-to-privileged-accounts'

splunk unknown spl

Windows AD DSRM Account Changes

The following analytic identifies changes to the Directory Services Restore Mode (DSRM) account behavior via registry modifications. It detects alterations in the registry path "*\\System\\CurrentControlSet\\Control\\Lsa\\DSRMAdminLogonBehavior" with specific values indicating potential misuse. This activity is significant because the DSRM account, if misconfigured, can be exploited to persist within a domain, similar to a local administrator account. If confirmed malicious, an attacker could ga

sentinel medium kql

Account Elevated to New Role

'Detects an account that is elevated to a new role where that account has not had that role in the last 14 days. Role elevations are a key mechanism for gaining permissions, monitoring which users have which roles, and for anomalies in those roles is useful for finding suspicious activity. Ref: https://docs.microsoft.com/azure/active-directory/fundamentals/security-operations-privileged-accounts#changes-to-privileged-accounts'

wazuh medium xml

Windows: General account database changed.

Windows: General account database changed.

wazuh medium xml

Windows: Security enabled group created.

Windows: Security enabled group created.

wazuh medium xml

Windows: Security enabled group deleted.

Windows: Security enabled group deleted.

sublime high mql

Service abuse: Coursera callback scam

Detects inbound messages spoofing Coursera transactional notifications - such as email confirmation requests or account change alerts - sent from Coursera's legitimate sending infrastructure, but targeting recipients on newly registered domains or containing mailto links pointing to newly registered non-Coursera domains. The combination of authentic-looking Coursera branding with anomalous recipient or embedded contact domains suggests account takeover or credential harvesting activity targeting

wazuh low xml

Windows: Computer account added/changed/deleted.

Windows: Computer account added/changed/deleted.