Browse Rules

Search and filter across all detection sources

9 rules

sagan unknown other

[WEBLABYRINTH] New host logged!

[WEBLABYRINTH] New host logged!

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet New-HostedContentFilterPolicy Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet New-HostedContentFilterPolicy Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet New-HostedContentFilterRule Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet New-HostedContentFilterRule Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet New-HostedOutboundSpamFilterPolicy Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet New-HostedOutboundSpamFilterPolicy Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet New-HostedOutboundSpamFilterRule Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet New-HostedOutboundSpamFilterRule Successfully Executed

wazuh low xml

Arpwatch new host detected.

Arpwatch new host detected.

anvilogic high other

AWS DisassociateAddress [snowflake-awscloudtrail]

Threat identifier for AWS API call DisassociateAddress, threat actors can initiate a Elastic IP Hijacking attack by querying for all IP addresses and disassociate an existing Elastic IP assign it to a new host

anvilogic high spl

AWS DisassociateAddress [splunk-awscloudtrail]

Threat identifier for AWS API call DisassociateAddress, threat actors can initiate a Elastic IP Hijacking attack by querying for all IP addresses and disassociate an existing Elastic IP assign it to a new host

elastic low kql

GKE Secret Access via Unusual User Agent

Detects GKE secrets get or list requests from a previously unseen combination of source IP, identity, and user agent, excluding the default Kubernetes client placeholder. Attackers who compromise a pod or steal a kubeconfig often use curl, custom scripts, or atypical clients from a new host to read service-account tokens, registry credentials, or application secrets. Anonymous identities are excluded; use dedicated anonymous-access rules for unauthenticated probing.