Browse Rules

Search and filter across all detection sources

140 rules

wazuh informational xml

AWS VPC Flow alert.

AWS VPC Flow alert.

sekoia unknown yara

apt_ta410_flowcloud_loader [yara_rules]

Detects FlowCloud Loader

sekoia unknown yara

apt_ta410_flowcloud_rtti [yara_rules]

Detects FlowCloud via RTTI

chronicle low yara-l

AWS Delete VPC Flow Logs

Detects when AWS VPC FLow Logs are deleted.

panther medium python

GCP VPC Flow Logs Disabled

VPC flow logs were disabled for a subnet.

sentinel high kql

Flow Logs Alerts for Prancer

'High severity flow Log alerts found by Prancer.'

sentinel medium kql

Tailscale Premium: Network flow beaconing detected

Identifies when flows between a src-dst pair recur at a regular interval (80%+ of inter-flow gaps cluster on the same delta over 10+ flows). Signature of C2 beaconing or scheduled exfiltration. Requires Tailscale Premium or Enterprise.

panther medium python

VPC Flow Port Scanning

Searches for potential port scanning activity in VPC Flow logs

sagan medium other

[CISCO-MERAKI] Flow denied by Layer 3 firewall

[CISCO-MERAKI] Flow denied by Layer 3 firewall

sekoia unknown yara

ta410_control_flow_obfuscation [yara_rules]

Detects control flow obfuscation used by TA410 in XXXModule_dlcore0

panther medium python

Auth0 Post Login Action Flow Updated

An Auth0 User updated a post login action flow for your organization's tenant.

sagan medium other

[MSAPI-MICROSOFTFLOW-GEOIP] Flow action from outside HOME_COUNTRY

[MSAPI-MICROSOFTFLOW-GEOIP] Flow action from outside HOME_COUNTRY

sagan medium other

[MSAPI-SECURITYCOMPLIANCECENTER] Insight Generated - Significant mail flow without TLS

[MSAPI-SECURITYCOMPLIANCECENTER] Insight Generated - Significant mail flow without TLS

falconforce unknown kql

Hijack Execution Flow: DLL Side-Loading

sentinel high kql

GCP Audit Logs - VPC Flow Logs Disabled

'Detects when Google Cloud Platform VPC Flow Logs configurations are disabled or deleted. VPC Flow Logs capture information about IP traffic going to and from network interfaces in VPC networks, providing critical visibility for security monitoring and forensic analysis. Disabling VPC Flow Logs reduces network visibility and may indicate an attempt to evade detection before performing malicious activities. Adversaries may disable flow logs to hide lateral movement, data exfiltration, or command

sagan medium other

[MSAPI-MICROSOFTFLOW-BLUEDOT] Flow action from Bluedot listed IP address

[MSAPI-MICROSOFTFLOW-BLUEDOT] Flow action from Bluedot listed IP address

panther medium python

AWS VPC Flow Logs

This policy validates that AWS VPCs (Virtual Private Clouds) have network flow logging enabled.

wazuh informational xml

AWS VPC Flow: [$(aws.action)] - Interface: $(aws.interface_id) - Protocol: $(aws.protocol)

AWS VPC Flow: [$(aws.action)] - Interface: $(aws.interface_id) - Protocol: $(aws.protocol)

wazuh low xml

AWS VPC Flow: [$(aws.action)] - Interface: $(aws.interface_id) - Protocol: $(aws.protocol)

AWS VPC Flow: [$(aws.action)] - Interface: $(aws.interface_id) - Protocol: $(aws.protocol)

sigma medium sigma

Application Using Device Code Authentication Flow

Device code flow is an OAuth 2.0 protocol flow specifically for input constrained devices and is not used in all environments. If this type of flow is seen in the environment and not being used in an input constrained device scenario, further investigation is warranted. This can be a misconfigured application or potentially something malicious.

panther informational python

Signal - VPC Flow Logs Allowed SSH

VPC Flow Logs observed inbound traffic on SSH port. This rule is a signal to be used in correlation rules.

panther high python

VPC Flow Logs Inbound Port Allowlist

VPC Flow Logs observed inbound traffic violating the port allowlist.

panther high python

VPC Flow Logs Inbound Port Blocklist

VPC Flow Logs observed inbound traffic violating the port blocklist.

sentinel medium kql

TI Map IP entity to AzureNetworkAnalytics_CL (NSG Flow Logs)

Identifies a match in AzureNetworkAnalytics_CL (NSG Flow Logs) from any IP IOC from TI that was Allowed

sentinel medium kql

TI map IP entity to AzureNetworkAnalytics_CL (NSG Flow Logs)

Identifies a match in AzureNetworkAnalytics_CL (NSG Flow Logs) from any IP IOC from TI that was Allowed