Search and filter across all detection sources
97 rules
Docker: Group of network events
[HORDEIMP] Emergency message
[HORDEIMP] Error message
[OPENSSH] Corrupted traffic
[CISCO-IOS] Invalid ARP
[JUNIPER] ARP address change
[JUNIPER] AS group missing
[JUNIPER] Duplicate IP address
[JUNIPER] Login authentication error
[ARP] arpwatch - Broadcast address detected
[FORTINET] Corrupted MAC packet detected
[GCP-SCC] Allow Open Firewall
[GCP-SCC] Allow RDP Port
[JUNIPER] BGP missing MD5 digest
[JUNIPER] Possible authentication dictionary attack
[OKTA] REQUEST FROM SUSPICIOUS ACTOR
[OPENVPN] Unencrypted VPN connection initiated
[PALO-ALTO] Suspicious DNS Request
[PPTP] Failed message [communications error]
[SAGAN] System stop sending logs
IOC IP Target
Detect network events that indicate communication to a watchlisted IP address
[ARP] arpwatch - Bogus IP address detected
[ARP] arpwatch - Ethernet mismatch [MAC != ARP]