Browse Rules

Search and filter across all detection sources

1,077 rules

panther medium python

1Password Login From CrowdStrike Unmanaged Device

Detects 1Password Logins from IP addresses not found in CrowdStrike''s AIP list. May indicate unmanaged device being used, or faulty CrowdStrike Sensor.

panther high python

A backdoored version of XZ or liblzma is vulnerable to CVE-2024-3094

Detects vulnerable versions of XZ and liblzma on Linux and MacOS using Osquery logs. Versions 5.6.0 and 5.6.1 of xz and liblzma are most likely vulnerable to backdoor exploit. Vuln management pack must be enabled: https://github.com/osquery/osquery/blob/master/packs/vuln-management.conf

panther informational python

A CloudTrail Was Created or Updated

A CloudTrail Trail was created, updated, or enabled.

panther high python

A Login from Outside the Corporate Office

A system has been logged into from a non approved IP space.

panther medium python

A long-lived cert was created

An unusually long-lived Teleport certificate was created

panther medium python

A More Friendly Name

An optional Description

panther medium python

A More Friendly Name

An optional Description

panther high python

A SAML Connector was created or modified

A SAML connector was created or modified

panther informational python

A Teleport Lock was created

A Teleport Lock was created

panther medium python

A Teleport Role was modified or created

A Teleport Role was modified or created

panther medium python

A user authenticated with SAML, but from an unknown company domain

A user authenticated with SAML, but from an unknown company domain

panther medium python

A User from the company domain(s) Logged in without SAML

A User from the company domain(s) Logged in without SAML

panther high python

A User Role with Sensitive Permissions has been Created

A Panther user role has been created that contains admin level permissions.

panther high python

A User's Panther Account was Modified

A Panther user's role has been modified. This could mean password, email, or role has changed for the user.

panther medium python

Account Security Configuration Changed

An account wide security configuration was changed.

panther medium python

Action Performed by Netskope Personnel

An action was performed by Netskope personnel.

panther medium python

Admin logged out because of successive login failures

An admin was logged out because of successive login failures.

panther medium python

Admin Role Assigned

Assigning an admin role manually could be a sign of privilege escalation

panther medium python

Amazon Machine Image (AMI) Modified to Allow Public Access

An Amazon Machine Image (AMI) was modified to allow it to be launched by anyone. Any sensitive configuration or application data stored in the AMI's block devices is at risk.

panther high python

An administrator account was created, deleted, or modified.

An administrator account was created, deleted, or modified.

panther medium python

Anthropic Admin API Key Created

Detects when a new admin API key is created. Admin API keys have elevated privileges and their creation should be verified as authorized. The admin_api_key_id and scopes fields identify the key and its permissions.

panther medium python

Anthropic Admin API Key Deleted

Detects when an admin API key is deleted. Unauthorized deletion could indicate an attacker revoking legitimate credentials to disrupt operations or covering tracks after using a compromised key.

panther medium python

Anthropic Artifact Shared Publicly

Detects when an artifact's sharing audience is changed to public. Public artifacts are accessible to anyone with the link, which could expose sensitive content outside the organization.

panther medium python

Anthropic Excessive Chat Access Failures

Detects when a single actor generates more than 50 chat access failures within a 10-minute window. Could indicate automated chat enumeration or unauthorized bulk access attempts. The claude_chat_id field identifies which chats were targeted — sequential or patterned IDs suggest scripted enumeration, while scattered IDs suggest shared-link browsing.

panther informational python

Anthropic Integration Connected

Tracks when a user connects an external integration (e.g., GitHub, Google Drive) to their Anthropic account. Logged for compliance visibility into external data pathways. The integration_type field identifies which service was connected.