Browse Rules

Search and filter across all detection sources

21 rules

wazuh high xml

Auditd: replay attack detected

Auditd: replay attack detected

wazuh low xml

Auditd: group ID changed

Auditd: group ID changed

wazuh low xml

Auditd: user ID changed

Auditd: user ID changed

sentinel medium kql

Pathlock TDnR - SAP HANA Database Audit Trail

Detects security events from the SAP HANA tenant database audit trail, forwarded by Pathlock Threat Detection and Response. HANA audit anomalies may indicate unauthorized database access, privilege abuse, or attempts to read sensitive data directly from the HANA database.

wazuh medium xml

Auditd: user becomes root

Auditd: user becomes root

wazuh medium xml

Auditd: process ended abnormally

Auditd: process ended abnormally

wazuh medium xml

Auditd: device enables promiscuous mode

Auditd: device enables promiscuous mode

wazuh low xml

Auditd: file is made executable

Auditd: file is made executable

wazuh medium xml

Auditd: file or a directory access ended abnormally

Auditd: file or a directory access ended abnormally

wazuh medium xml

Auditd: Role-Based Access Control (RBAC) failure detected.

Auditd: Role-Based Access Control (RBAC) failure detected.

wazuh medium xml

Auditd: execution of a file ended abnormally

Auditd: execution of a file ended abnormally

wazuh informational xml

Auditd: user-space account addition ended abnormally.

Auditd: user-space account addition ended abnormally.

wazuh informational xml

Auditd: user-space account deletion ended abnormally.

Auditd: user-space account deletion ended abnormally.

wazuh informational xml

Auditd: user-space account modification ended abnormally.

Auditd: user-space account modification ended abnormally.

wazuh medium xml

Auditd: failure of the Abstract Machine Test Utility (AMTU) detected

Auditd: failure of the Abstract Machine Test Utility (AMTU) detected

wazuh low xml

Auditd: limit of failed login attempts reached.

Auditd: limit of failed login attempts reached.

wazuh medium xml

Auditd: maximum amount of Discretionary Access Control (DAC) or Mandatory Access Control (MAC) failures reached

Auditd: maximum amount of Discretionary Access Control (DAC) or Mandatory Access Control (MAC) failures reached

wazuh low xml

Auditd: login attempt from a forbidden location.

Auditd: login attempt from a forbidden location.

wazuh low xml

Auditd: login attempt reached the maximum amount of concurrent sessions.

Auditd: login attempt reached the maximum amount of concurrent sessions.

wazuh low xml

Auditd: account login attempt ended abnormally.

Auditd: account login attempt ended abnormally.

wazuh low xml

Auditd: login attempt is made at a time when it is prevented by.

Auditd: login attempt is made at a time when it is prevented by.