Browse Rules

Search and filter across all detection sources

26 rules

sagan informational other

[GCP] Suspicious Login

[GCP] Suspicious Login

sentinel high kql

API - Suspicious Login

'42Crunch API protection against suspicious login'

sagan informational other

[GCP] Suspicious Login Blocked

[GCP] Suspicious Login Blocked

sagan critical other

[OPENSSH] Suspicious login to a nologin account

[OPENSSH] Suspicious login to a nologin account

chronicle high yara-l

Google Workspace Suspicious Login and Google Drive File Download

Identifies when a Google Workspace user downloads a file from Google Drive after a suspicious login event occurred.

chronicle high yara-l

Google Workspace Suspicious Login and Google Drive File Share

Identifies when a Google Workspace user shares a file on Google Drive after a suspicious login event occurred.

sagan medium other

[NETSKOPE] Compromised Credential alert

[NETSKOPE] Compromised Credential alert

panther medium python

Suspicious GSuite Login

GSuite reported a suspicious login for this user.

sagan medium other

[WINDOWS-AUTH] Suspicious network login

[WINDOWS-AUTH] Suspicious network login

sagan medium other

[WINDOWS-AUTH] Suspicious network login

[WINDOWS-AUTH] Suspicious network login

sagan medium other

[CROWDSTRIKE] User Login From Unusual Machine

[CROWDSTRIKE] User Login From Unusual Machine

sagan medium other

[WINDOWS-CORRELATED] Possible remote WMIC command execution

[WINDOWS-CORRELATED] Possible remote WMIC command execution

sagan medium other

[MSAPI-EXCHANGE-GEOIP] MailboxLogin from outside HOME_COUNTRY

[MSAPI-EXCHANGE-GEOIP] MailboxLogin from outside HOME_COUNTRY

sagan medium other

[WINDOWS-AUTH] Suspicious network login from non-RFC1918

[WINDOWS-AUTH] Suspicious network login from non-RFC1918

sagan medium other

[WINDOWS-AUTH] Suspicious network login from non-RFC1918

[WINDOWS-AUTH] Suspicious network login from non-RFC1918

sigma medium sigma

Suspicious Login Activity Classified By Google

Detects Google Workspace login activity that's classified as suspicious by Google.

sagan medium other

[MSAPI-EXCHANGE-BLUEDOT] MailboxLogin from Bluedot listed IP address

[MSAPI-EXCHANGE-BLUEDOT] MailboxLogin from Bluedot listed IP address

sagan medium other

[SNORT] An attempted login using a suspicious username was detected

[SNORT] An attempted login using a suspicious username was detected

sentinel medium kql

Acronis - Login from Abnormal IP - Low Occurrence

Suspicious login from an IP address observed up to two times in the last two weeks.

anvilogic high spl

Azure Suspicious Logins [splunk-azure]

This use case looks for logins from multiple src_ip, states, or regions. -- Threat Actor Association: LUCR-3

anvilogic high spl

Azure Suspicious Login Failures [splunk-azure]

This use case looks for login failures on a user coming from multiple locations/ips. -- Threat Actor Association: LUCR-3

panther high python

Auth0 Fraud Risk by Volume

Detects a surge in either failed, successful or suspicious login attempts using leaked passwords over a window of time and a threshold. Exceeding set threshold may indicate potential fraud.

sentinel high kql

Azure VM Run Command operation executed during suspicious login window

'Identifies when the Azure Run Command operation is executed by a UserPrincipalName and IP Address that has resulted in a recent user entity behaviour alert.'

sublime high mql

Attachment: EML file contains HTML attachment with login portal indicators

Attached EML file contains an HTML attachment with suspicious login indicators. Known credential theft technique.

sentinel medium kql

Suspicious Login from deleted guest account

' This query will detect logins from guest account which was recently deleted. For any successful logins from deleted identities should be investigated further if any existing user accounts have been altered or linked to such identity prior deletion'