Search and filter across all detection sources
284 rules
[SNORT] Successful User Privilege Gain
[AWS-SIGNIN] Successful User login without MFA
[IMAPD] Successful login
[KNOCKD] Open Sesame
[PPTP] Connection established
[CONFLUENT] Kafka Successful Authentication
[CYLANCE] AuditLog - Device Edit
[HORDEIMP] IMP successful login
[WATCHGUARD] VPN - User login
[MCAS] ALERT_ANUBIS_DETECTION_VELOCITY
[NETWRIX] Active Directory User Added
[WINDOWS-AUTH] User account created
[WINDOWS-AUTH] User account deleted
[XINETD] POP3S [SSL] User login
[ZEEK] SSH Watched_Country_Login
[CISCO-BLUEDOT] VPN Login from Tor
[CONFLUENT] Authorization to create Kafka Cluster
[COURIER-BLUEDOT] Timeout from suspicious source
[COURIER-CORRELATED] Timeout after exploit attempt
[COURIER-CORRELATED] Timeout after honeypot activity
[COURIER-CORRELATED] Timeout after recon activity
[COURIER] Courierpassd|Poppassd - Changed user password
[FORTINET] L2TP/PPTP/PPPoE Authentication success