Search and filter across all detection sources
26 rules
[GCP] Suspicious Login
API - Suspicious Login
'42Crunch API protection against suspicious login'
[GCP] Suspicious Login Blocked
[OPENSSH] Suspicious login to a nologin account
Google Workspace Suspicious Login and Google Drive File Download
Identifies when a Google Workspace user downloads a file from Google Drive after a suspicious login event occurred.
Google Workspace Suspicious Login and Google Drive File Share
Identifies when a Google Workspace user shares a file on Google Drive after a suspicious login event occurred.
[NETSKOPE] Compromised Credential alert
Suspicious GSuite Login
GSuite reported a suspicious login for this user.
[WINDOWS-AUTH] Suspicious network login
[CROWDSTRIKE] User Login From Unusual Machine
[WINDOWS-CORRELATED] Possible remote WMIC command execution
[MSAPI-EXCHANGE-GEOIP] MailboxLogin from outside HOME_COUNTRY
[WINDOWS-AUTH] Suspicious network login from non-RFC1918
Suspicious Login Activity Classified By Google
Detects Google Workspace login activity that's classified as suspicious by Google.
[MSAPI-EXCHANGE-BLUEDOT] MailboxLogin from Bluedot listed IP address
[SNORT] An attempted login using a suspicious username was detected
Acronis - Login from Abnormal IP - Low Occurrence
Suspicious login from an IP address observed up to two times in the last two weeks.
Azure Suspicious Logins [splunk-azure]
This use case looks for logins from multiple src_ip, states, or regions. -- Threat Actor Association: LUCR-3
Azure Suspicious Login Failures [splunk-azure]
This use case looks for login failures on a user coming from multiple locations/ips. -- Threat Actor Association: LUCR-3
Auth0 Fraud Risk by Volume
Detects a surge in either failed, successful or suspicious login attempts using leaked passwords over a window of time and a threshold. Exceeding set threshold may indicate potential fraud.
Azure VM Run Command operation executed during suspicious login window
'Identifies when the Azure Run Command operation is executed by a UserPrincipalName and IP Address that has resulted in a recent user entity behaviour alert.'
Attachment: EML file contains HTML attachment with login portal indicators
Attached EML file contains an HTML attachment with suspicious login indicators. Known credential theft technique.
Suspicious Login from deleted guest account
' This query will detect logins from guest account which was recently deleted. For any successful logins from deleted identities should be investigated further if any existing user accounts have been altered or linked to such identity prior deletion'