Browse Rules

Search and filter across all detection sources

13 rules

panther low python

GCP SQL Config Changes

Monitoring changes to Sql Instance configuration may reduce time to detect and correct misconfigurations done on sql server.

panther high python

Slack EKM Config Changed

Detects when the logging settings for a workspace's EKM configuration has changed

splunk unknown spl

ESXi Syslog Config Change

This detection identifies changes to the syslog configuration on an ESXi host using esxcli, which may indicate an attempt to disrupt log collection and evade detection.

wazuh low xml

Virtual machine being reconfigured.

Virtual machine being reconfigured.

wazuh medium xml

Netscreen firewall: policy changed.

Netscreen firewall: policy changed.

wazuh medium xml

Netscreen firewall: configuration changed.

Netscreen firewall: configuration changed.

wazuh medium xml

ASA: Firewall configuration deleted.

ASA: Firewall configuration deleted.

wazuh medium xml

ASA: Firewall configuration changed.

ASA: Firewall configuration changed.

wazuh informational xml

Cisco IOS router configuration changed.

Cisco IOS router configuration changed.

splunk unknown spl

Windows SQL Server xp_cmdshell Config Change

This detection identifies when the xp_cmdshell configuration is modified in SQL Server. The xp_cmdshell extended stored procedure allows execution of operating system commands and programs from SQL Server, making it a high-risk feature commonly abused by attackers for privilege escalation and lateral movement.

wazuh medium xml

PIX: Firewall configuration deleted.

PIX: Firewall configuration deleted.

wazuh medium xml

PIX: Firewall configuration changed.

PIX: Firewall configuration changed.

panther high python

Okta AD Agent Token Abuse - Behavioral

Detects potential Okta AD Agent token theft and abuse using behavioral analysis. Instead of relying on hardcoded service account patterns, this detection identifies when AD agent-related activities (API token creation, agent registration, config changes) occur from previously unseen IP addresses or user agents. This behavioral approach adapts to your environment and catches anomalous access patterns that may indicate compromised credentials or unauthorized token generation. **What This Detectio