Rule ID: 6fa564ac-dfb7-4753-a49b-5fc919866c28
Browse
Analytic Rules
Rule ID: d992b87b-eb49-4a9d-aa96-baacf9d26247
[Deprecated] - Alert for IOCs related to WindowsELF malware - IP Hash IOCs - September 2021
Rule ID: 825991eb-ea39-4590-9de2-ee97ef42eb93
[Deprecated] - Aqua Blizzard Actor IOCs - Feb 2022
Rule ID: 961b6a81-5c53-40b6-9800-4f661a8faea7
[Deprecated] - Cadet Blizzard Actor IOC - January 2022
Rule ID: 94749332-1ad9-49dd-a5ab-5ff2170788fc
[Deprecated] - Caramel Tsunami Actor IOC - July 2021
Rule ID: 595a10c9-91be-4abb-bbc7-ae9c57848bef
[Deprecated] - Chia_Crypto_Mining - Domain Process Hash and IP IOCs - June 2021
Rule ID: 9f9c1e51-4fb1-4510-a675-c7c2fb32f47e
[Deprecated] - Denim Tsunami AV Detection
Rule ID: ce02935c-cc67-4b77-9b96-93d9947e119a
[Deprecated] - Denim Tsunami C2 Domains July 2022
Rule ID: a779e2d5-9109-4f0a-a75e-f3d4f3c58560
[Deprecated] - Denim Tsunami File Hashes July 2022
Rule ID: 4759ddb4-2daf-43cb-b34e-d85b85b4e4a5
[Deprecated] - DEV-0322 Serv-U related IOCs - July 2021
Rule ID: a172107d-794c-48c0-bc26-d3349fe10b4d
[Deprecated] - Dev-0530 IOC - July 2022
Rule ID: 70b12a3b-4896-42cb-910c-5ffaf8d7987d
[Deprecated] - Emerald Sleet domains included in DCU takedown
Rule ID: d804b39c-03a4-417c-a949-bdbf21fa3305
[Deprecated] - Exchange Server Vulnerabilities Disclosed March 2021 IoC Match
Rule ID: b2199398-8942-4b8c-91a9-b0a707c5d147
[Deprecated] - Hive Ransomware IOC - July 2022
Rule ID: 70b12a3b-4899-42cb-910c-5ffaf9d7997d
[Deprecated] - Known Barium domains
Rule ID: 09551db0-e147-4a0c-9e7b-918f88847605
[Deprecated] - Known Diamond Sleet Comebacker and Klackring malware hashes
Rule ID: 3174a9ec-d0ad-4152-8307-94ed04fa450a
[Deprecated] - Known Diamond Sleet related maldoc hash
Rule ID: 26a3b261-b997-4374-94ea-6c37f67f4f39
[Deprecated] - Known Granite Typhoon domains and hashes
Rule ID: a04cf847-a832-4c60-b687-b0b6147da219
[Deprecated] - Known Manganese IP and UserAgent activity
Rule ID: 7249500f-3038-4b83-8549-9cd8dfa2d498
[Deprecated] - Known Mint Sandstorm group domainsIP - October 2020
Rule ID: 9122a9cb-916b-4d98-a199-1b7b0af8d598
[Deprecated] - Known Nylon Typhoon domains and hashes
Rule ID: 155f40c6-610d-497d-85fc-3cf06ec13256
[Deprecated] - Known Phosphorus group domainsIP
Rule ID: 95407904-0131-4918-bc49-ebf282ce149a
[Deprecated] - Known Plaid Rain IP
Rule ID: c87fb346-ea3a-4c64-ba92-3dd383e0f0b5
[Deprecated] - Known Ruby Sleet domains and hashes
Rule ID: 7ee72a9e-2e54-459c-bc8a-8c08a6532a63
[Deprecated] - Known Seashell Blizzard IP
Rule ID: bb8a3481-dd14-4e76-8dcc-bbec8776d695
[Deprecated] - Midnight Blizzard - Domain and IP IOCs - March 2021
Rule ID: 677da133-e487-4108-a150-5b926591a92b
[Deprecated] - Midnight Blizzard - Domain Hash and IP IOCs - May 2021
Rule ID: c37711a4-5f44-4472-8afc-0679bc0ef966
[Deprecated] - Midnight Blizzard IOCs related to FoggyWeb backdoor
Rule ID: 972c89fa-c969-4d12-932f-04d55d145299
[Deprecated] - MSHTML vulnerability CVE-2021-40444 attack
Rule ID: 68271db2-cbe9-4009-b1d3-bb3b5fe5713c
[Deprecated] - Possible Forest Blizzard attempted credential harvesting - Oct 2020
Rule ID: 7d6d8a8e-b08a-4082-8dbb-d7fd2cbbc35e
[Deprecated] - Silk Typhoon UM Service writing suspicious file
Rule ID: ab4b6944-a20d-42ab-8b63-238426525801
[Deprecated] - Solorigate Domains Found in VM Insights
Rule ID: cecdbd4c-4902-403c-8d4b-32eb1efe460b
[Deprecated] - Solorigate Network Beacon
Rule ID: c0e84221-f240-4dd7-ab1e-37e034ea2a4e
[Deprecated] - SUNSPOT log file creation
Rule ID: caf78b95-d886-4ac3-957a-a7a3691ff4ed
[Deprecated] - Tarrask malware IOC - April 2022
Rule ID: 95543d6d-f00d-4193-a63f-4edeefb7ec36
[Deprecated] - Zinc Actor IOCs domains hashes IPs and useragent - October 2022
Rule ID: 6ee72a9e-2e54-459c-bc9a-9c09a6502a63
[Deprecated] -Known Barium IP
Rule ID: a22740ec-fc1e-4c91-8de6-c29c6450ad00
[Deprecated] Explicit MFA Deny
Rule ID: 90bacdf4-e35b-47cb-92d1-29d8397eb4a0
[Entra ID] Application Assigned Administrator Permissions Immediately After Obtaining Role Management Permissions
Rule ID: ef34b272-930c-41c8-a682-8c2093cd2024
[Entra ID] Application Granted Administrative Permission to Assign Microsoft Entra ID Roles
Rule ID: 9f7197b6-eeb2-46f3-83b1-a2c4dfca46a0
[Entra ID] Authentication Method Changed for Privileged Account
Rule ID: 944d0ab5-b654-47f9-a398-2e77a0b7906e
[Entra ID] Domain Federation Trust Settings Modified
Rule ID: d6cd3c6f-1d2a-4c42-a048-dbe91cf35b18
[Entra ID] Mass Privileged Role Change Activity Detected
Rule ID: aceee46e-8fb3-42d9-967a-aac637bcefd4
[Entra ID] Privilege Elevation Request Denied
Rule ID: b64ac0e2-a241-4b9a-ad3e-ae572630b295
[Entra ID] Privileged Role Assigned to a New User
Rule ID: fad0f8b9-a0a5-430a-9a94-049a1144bf54
[Entra ID] Privileged Role Assigned to User
Rule ID: 67802748-435b-4f80-9f61-b9a9ac6ea15c
[Entra ID] Suspicious Continuous OAuth Token Usage
Rule ID: 54e6bb8e-2935-422f-9387-dba1961abfd7
1Password - Changes to firewall rules
Rule ID: 9406f5ab-1197-4db9-8042-9f3345be061c
1Password - Changes to SSO configuration
Rule ID: 92ab0938-1e7c-4671-9810-392e8b9714da
1Password - Disable MFA factor or type for all user accounts
Rule ID: bf9132c7-9d4d-4244-98c7-7d994703c208
1Password - Log Ingestion Failure
Rule ID: 9a264487-bcb8-4c7f-a461-b289a46377b8
1Password - Manual account creation
Rule ID: 26daed54-cea5-469c-9b6e-0d85a40dc463
1Password - New service account integration created
Rule ID: 327e0579-7c03-4ec7-acf5-a29dcc4a12b6
1Password - Non-privileged vault user permission change
Rule ID: 398a1cf1-f56f-4700-912c-9bf4c8409ebc
1Password - Potential insider privilege escalation via group
Rule ID: a00ffbd8-1d1c-47a3-b0a6-7d70bd8017ed
1Password - Potential insider privilege escalation via vault
Rule ID: 76e386eb-f51a-4600-97d1-f0db3b7e41f1
1Password - Privileged vault permission change
Rule ID: 6711b747-16d7-4df4-9f61-8633617f45d7
1Password - Secret extraction post vault access change by administrator
Rule ID: d54a3cf9-6169-449c-83f1-e7def3359702
1Password - Service account integration token adjustment
Rule ID: ceb20a5c-adce-4eba-9728-541361d47d87
1Password - Successful anomalous sign-in
Rule ID: 3c8140eb-e946-4bf2-8c61-03e4df56d400
1Password - User account MFA settings changed
Rule ID: 849ea271-cd9c-4afe-a13b-ddbbac5fc6d3
1Password - User added to privileged group
Rule ID: dae4c601-51c9-47f5-83d3-e6eaef929cf6
1Password - Vault export
Rule ID: 969e2e5c-9cc6-423c-a3de-514f7ad75fe7
1Password - Vault export post account creation
Rule ID: 51617533-cf51-4415-9020-b15bd47d69d2
1Password - Vault export prior to account suspension or deletion
Rule ID: 09c49590-4e9d-4da9-a34d-17222d0c9e7e
A client made a web request to a potentially harmful file ASIM Web Session schema
Rule ID: 8cbc3215-fa58-4bd6-aaaa-f0029c351730
A host is potentially running a crypto miner ASIM Web Session schema
Rule ID: 3f0c20d5-6228-48ef-92f3-9ff7822c1954
A host is potentially running a hacking tool ASIM Web Session schema
Rule ID: 42436753-9944-4d70-801c-daaa4d19ddd2
A host is potentially running PowerShell to send HTTPS requests ASIM Web Session schema
Rule ID: 46ac55ae-47b8-414a-8f94-89ccd1962178
A potentially malicious web request was executed against a web server
Rule ID: d36bb1e3-5abc-4037-ad9a-24ba3469819e
Abnormal Deny Rate for Source IP
Rule ID: 826f930c-2f25-4508-8e75-a95b809a4e15
Abnormal Port to Protocol
Rule ID: da243bf4-382b-46b9-9b4d-ce6ffe9e7beb
Abnormal Security - Account Takeover case opened
Rule ID: 8effd19a-abab-433a-9184-ae67ac51e6d0
Abnormal Security - High-risk email attack detected
Rule ID: 51c6ba55-fecd-4be0-9064-1aafc4d3e8d6
Abnormal Security - User-reported email judged malicious
Rule ID: b15ea4c9-58da-44d8-90e4-6591d947e7e3
Abnormal Security - Vendor compromise case detected
Rule ID: 48a9478b-440a-4330-b42c-94bd84dc904c
Access to AWS without MFA
Rule ID: 8df80270-b4fa-4a7a-931e-8d17c0b321ae
Access Token Manipulation - Create Process with Token
Rule ID: bff058b2-500e-4ae5-bb49-a5b1423cbd5b
Accessed files shared by temporary external user
Rule ID: 7efc75ce-e2a4-400f-a8b1-283d3b0f2c60
Account added and removed from privileged groups
Rule ID: bb616d82-108f-47d3-9dec-9652ea0d3bf6
Account Created and Deleted in Short Timeframe
Rule ID: 99d589fa-7337-40d7-91a0-c96d0c4fa437
Account created from non-approved sources
Rule ID: 6d63efa6-7c25-4bd4-a486-aa6bf50fde8a
Account created or deleted by non-approved user
Rule ID: 450f4e56-5bba-4070-b9d9-9204ba9d777d
Account Creation
Rule ID: c1c66f0b-5531-4a3e-a619-9d2f770ef730
Account Elevated to New Role
Rule ID: 84037130-a623-46c2-9144-0c0955ac4112
Acronis - Login from Abnormal IP - Low Occurrence
Rule ID: 1385f0ce-69d9-4abf-8039-52080c8c7017
Acronis - Multiple Endpoints Accessing Malicious URLs
Rule ID: a783ade7-bf43-416d-b809-8f5b06d87790
Acronis - Multiple Endpoints Infected by Ransomware
Rule ID: 5090ad7b-4b47-4cab-9015-bffb43aecde8
Acronis - Multiple Inboxes with Malicious Content Detected
Rule ID: 6c360107-f3ee-4b91-9f43-f4cfd90441cf
AD account with Dont Expire Password
Rule ID: cfc1ae62-db63-4a3e-b88b-dc04030c2257
AD FS Abnormal EKU object identifier attribute
Rule ID: 2f4165a6-c4fb-4e94-861e-37f1b4d6c0e6
AD FS Remote Auth Sync Connection
Rule ID: d57c33a9-76b9-40e0-9dfa-ff0404546410
AD FS Remote HTTP Network Connection
Rule ID: 62085097-d113-459f-9ea7-30216f2ee6af
AD user enabled and password not set within 48 hours
Rule ID: 6d1a5478-e613-44f4-a48f-12cc18568522
Adding User or Group Failed
Rule ID: d7feb859-f03e-4e8d-8b21-617be0213b13
Addition of a Temporary Access Pass to a Privileged Account
Rule ID: dcdf9bfc-c239-4764-a9f9-3612e6dff49c
ADFS Database Named Pipe Connection
Rule ID: 18e6a87e-9d06-4a4e-8b59-3469cd49552d
ADFS DKM Master Key Export
Rule ID: 63d87fcb-d197-48d2-a642-de4813f0219a
Admin password not updated in 30 days
Rule ID: f80d951a-eddc-4171-b9d0-d616bb83efdc
Admin promotion after Role Management Application Permission Grant
Rule ID: 87419138-d75f-450d-aca4-1dc802e32540
Admin SaaS account detected
Rule ID: 52aec824-96c1-4a03-8e44-bb70532e6cea
AdminSDHolder Modifications
Rule ID: ded8168e-c806-4772-af30-10576e0a7529
AFD WAF - Code Injection
Rule ID: a4d99328-e4e6-493d-b0d5-57e6f9ddae77
AFD WAF - Path Traversal Attack
Rule ID: 2a632013-379d-4993-956f-615063d31e10
Affected rows stateful anomaly on database
Rule ID: 76c9e83d-c6f9-4270-ad21-761410f9cc6c
AIShield - Image classification AI Model Evasion high suspicious vulnerability detection
Rule ID: c4bedb3c-4fb8-4b1c-af5b-8229bd25f521
AIShield - Image classification AI Model Evasion low suspicious vulnerability detection
Rule ID: b4cc5396-2a34-45f5-a726-860e476edf15
AIShield - Image classification AI Model extraction high suspicious vulnerability detection
Rule ID: 1ed02dcc-0bc9-465e-94b4-bd8969221602
AIShield - Image Segmentation AI Model extraction high suspicious vulnerability detection
Rule ID: 4ec55816-e07b-45fc-b89e-917c93906540
AIShield - Natural language processing AI model extraction high suspicious vulnerability detection
Rule ID: 669680fb-91e5-4cbd-9eb6-e5352e0f8af0
AIShield - Tabular classification AI Model Evasion high suspicious vulnerability detection
Rule ID: af245eff-0db9-4df8-82e6-998185cac332
AIShield - Tabular classification AI Model Evasion low suspicious vulnerability detection
Rule ID: 8d03e3ff-18eb-497c-a6cb-1c35ccdb0ed3
AIShield - Tabular classification AI Model extraction high suspicious vulnerability detection
Rule ID: 37118ef6-73b4-49aa-b13b-cdeeeea580df
AIShield - Timeseries Forecasting AI Model extraction high suspicious vulnerability detection
Rule ID: 2e0efcd4-56d2-41df-9098-d6898a58c62b
Alarming number of anomalies generated in NetBackup
Rule ID: 9649e203-3cb7-47ff-89a9-42f2a5eefe31
Alsid Active Directory attacks pathways
Rule ID: 25e0b2dd-3ad3-4d5b-80dd-720f4ef0f12c
Alsid DCShadow
Rule ID: d3c658bd-8da9-4372-82e4-aaffa922f428
Alsid DCSync
Rule ID: 21ab3f52-6d79-47e3-97f8-ad65f2cb29fb
Alsid Golden Ticket
Rule ID: 3caa67ef-8ed3-4ab5-baf2-3850d3667f3d
Alsid Indicators of Attack
Rule ID: 154fde9f-ae00-4422-a8da-ef00b11da3fc
Alsid Indicators of Exposures
Rule ID: 3acf5617-7c41-4085-9a79-cc3a425ba83a
Alsid LSASS Memory
Rule ID: ba239935-42c2-472d-80ba-689186099ea1
Alsid Password Guessing
Rule ID: 472b7cf4-bf1a-4061-b9ab-9fe4894e3c17
Alsid Password issues
Rule ID: 9e20eb4e-cc0d-4349-a99d-cad756859dfb
Alsid Password Spraying
Rule ID: a5fe9489-cf8b-47ae-a87e-8f3a13e4203e
Alsid privileged accounts issues
Rule ID: fb9e0b51-8867-48d7-86f4-6e76f2176bf8
Alsid user accounts issues
Rule ID: 2b701288-b428-4fb8-805e-e4372c574786
Anomalous login followed by Teams action
Rule ID: 7cb8f77d-c52f-4e46-b82f-3cf2e106224a
Anomalous sign-in location by user account and authenticating application
Rule ID: f7c3f5c8-71ea-49ff-b8b3-148f0e346291
Anomalous Single Factor Signin
Rule ID: f845881e-2500-44dc-8ed7-b372af3e1e25
Anomalous User Agent connection attempt
Rule ID: cd6def0d-3ef0-4d55-a7e3-faa96c46ba12
Anomaly found in Network Session Traffic ASIM Network Session schema
Rule ID: 8717e498-7b5d-4e23-9e7c-fa4913dbfd79
Anomaly in SMB TrafficASIM Network Session schema
Rule ID: 9c1e9381-79dd-4ddf-9570-b73a1dc59fe0
Anomaly Sign In Event from an IP
Rule ID: 4f767afa-d666-4ed4-b453-a4f5ad35181b
Antivirus Detected an Infected File
Rule ID: 6ccc187a-42ee-4635-8bcc-3b299f8570df
Anvilogic Alert
Rule ID: 767f9dc4-3b01-11ec-8d3d-0242ac130003
Apache - Apache 2449 flaw CVE-2021-41773
Rule ID: 54da6a42-3b00-11ec-8d3d-0242ac130003
Apache - Command in URI
Rule ID: e9edfe1c-3afd-11ec-8d3d-0242ac130003
Apache - Known malicious user agent
Rule ID: 15f5a956-3af9-11ec-8d3d-0242ac130003
Apache - Multiple client errors from single IP
Rule ID: 1bf246a2-3af9-11ec-8d3d-0242ac130003
Apache - Multiple server errors from single IP
Rule ID: db5f16f0-3afe-11ec-8d3d-0242ac130003
Apache - Private IP in URL
Rule ID: c5d69e46-3b00-11ec-8d3d-0242ac130003
Apache - Put suspicious file
Rule ID: a0077556-3aff-11ec-8d3d-0242ac130003
Apache - Request from private IP
Rule ID: d1c52578-3afc-11ec-8d3d-0242ac130003
Apache - Request to sensitive files
Rule ID: 14d7e15e-3afb-11ec-8d3d-0242ac130003
Apache - Requests to rare files
Rule ID: 7a3193b8-67b7-11ec-90d6-0242ac120003
ApexOne - Attack Discovery Detection
Rule ID: 1a87cd10-67b7-11ec-90d6-0242ac120003
ApexOne - CC callback events
Rule ID: 4a9a5900-67b7-11ec-90d6-0242ac120003
ApexOne - Commands in Url
Rule ID: b463b952-67b8-11ec-90d6-0242ac120003
ApexOne - Device access permissions was changed
Rule ID: 6303235a-ee70-42a4-b969-43e7b969b916
ApexOne - Inbound remote access connection
Rule ID: cd94e078-67b7-11ec-90d6-0242ac120003
ApexOne - Multiple deny or terminate actions on single IP
Rule ID: e289d762-6cc2-11ec-90d6-0242ac120003
ApexOne - Possible exploit or execute operation
Rule ID: c92d9fe4-67b6-11ec-90d6-0242ac120003
ApexOne - Spyware with failed response
Rule ID: 4d7199b2-67b8-11ec-90d6-0242ac120003
ApexOne - Suspicious commandline arguments
Rule ID: 9e3dc038-67b7-11ec-90d6-0242ac120003
ApexOne - Suspicious connections
Rule ID: 25c86f99-0a91-4b7f-88f3-599a008e5ab8
API - Account Takeover
Rule ID: 2c59e609-e0a0-4e8e-adc5-ab4224be8a36
API - Anomaly Detection
Rule ID: d944d564-b6fa-470d-b5ab-41b341878c5e
API - API Scraping
Rule ID: 1b047dc3-a879-4f99-949b-d1dc867efc83
API - BOLA
Rule ID: 28500be7-cfcf-40e1-bad4-bc524e9283e2
API - Invalid host access
Rule ID: bbd163f4-1f56-434f-9c23-b06713c119c2
API - JWT validation
Rule ID: 421b38ec-4295-4aed-8299-c92e268ad663
API - Kiterunner detection
Rule ID: d951d64d-0ecd-4675-8c79-6c870d5f72ac
API - Password Cracking
Rule ID: b808063b-07d5-432c-95d0-8900da61cce9
API - Rate limiting
Rule ID: c6258d51-7b82-4942-8293-94c1dcf91595
API - Rate limiting
Rule ID: 7bdc10d6-aa24-4ca9-9a93-802cd8761354
API - Suspicious Login
Rule ID: 9b8dd8fd-f192-42eb-84f6-541920400a7a
App Gateway WAF - Scanner Detection
Rule ID: bdb2cd63-99f2-472e-b1b9-acba473b6744
App Gateway WAF - SQLi Detection
Rule ID: 1c7ff502-2ad4-4970-9d29-9210c6753138
App Gateway WAF - XSS Detection
Rule ID: 912a18fc-6165-446b-8740-81ae6c3f75ee
App GW WAF - Code Injection
Rule ID: b6c3a8a6-d22c-4882-9c57-abc01690938b
App GW WAF - Path Traversal Attack
Rule ID: 68c0b6bb-6bd9-4ef4-9011-08998c8ef90f
Application Gateway WAF - SQLi Detection
Rule ID: d2bc08fa-030a-4eea-931a-762d27c6a042
Application Gateway WAF - XSS Detection
Rule ID: fa8d692d-5b00-4a6c-99b3-30b4710efa59
Application Group Deleted
Rule ID: ff3ceb7d-bed0-4ed2-8dbf-1feb9047810f
Application Group Settings Updated
Rule ID: 9fb2ee72-959f-4c2b-bc38-483affc539e4
Application ID URI Changed
Rule ID: a1080fc1-13d1-479b-8340-255f0290d96c
Application Redirect URL Update
Rule ID: c2da1106-bfe4-4a63-bf14-5ab73130ccd5
AppServices AV Scan Failure
Rule ID: 9d0295ee-cb75-4f2c-9952-e5acfbb67036
AppServices AV Scan with Infected Files
Rule ID: 18dbdc22-b69f-4109-9e39-723d9465f45f
Aqua Blizzard AV hits - Feb 2022
Rule ID: 6a90f177-dcaa-44ec-b6e6-723ee8408cb2
Archive Repository Deleted
Rule ID: 74c3bda5-cdae-4af3-ab54-daddfbe8bc70
Archive Repository Settings Updated
Rule ID: a9bf1b8c-c761-4840-b9a8-7535ca68ca28
ARGOS Cloud Security - Exploitable Cloud Resources
Rule ID: 322d4765-be6b-4868-9e3f-138a4f339dd6
Armorblox Needs Review Alert
Rule ID: efe4efef-5ca7-4b51-a53e-0e96492ce97a
ASR Bypassing Writing Executable Content
Rule ID: 83fbf6a2-f227-48f4-8e7b-0b0ecac2381b
Atlassian Beacon Alert
Rule ID: 3af9285d-bb98-4a35-ad29-5ea39ba0c628
Attempt to bypass conditional access rule in Microsoft Entra ID
Rule ID: 4595192f-671b-4724-aa62-093a9724c2f3
Attempt to Delete Backup Failed
Rule ID: 54c9a609-60db-47b0-82ee-86895c89bd89
Attempt to Update Security Object Failed
Rule ID: 75ea5c39-93e5-489b-b1e1-68fa6c9d2d04
Attempts to sign in to disabled accounts
Rule ID: 66276b14-32c5-4226-88e3-080dacc31ce1
Audit policy manipulation using auditpol utility
Rule ID: ef895ada-e8e8-4cf0-9313-b1ab67fab69f
Authentication Attempt from New Country
Rule ID: feb0a2fb-ae75-4343-8cbc-ed545f1da289
Authentication Method Changed for Privileged Account
Rule ID: 694c91ee-d606-4ba9-928e-405a2dd0ff0f
Authentication Methods Changed for Privileged Account
Rule ID: af435ca1-fb70-4de1-92c1-7435c48482a9
Authentications of Privileged Accounts Outside of Expected Controls
Rule ID: 5f171045-88ab-4634-baae-a7b6509f483b
AV detections related to Dev-0530 actors
Rule ID: 186970ee-5001-41c1-8c73-3178f75ce96a
AV detections related to Europium actors
Rule ID: 4e5914a4-2ccd-429d-a845-fa597f0bd8c5
AV detections related to Hive Ransomware
Rule ID: 3bd33158-3f0b-47e3-a50f-7c20a1b88038
AV detections related to SpringShell Vulnerability
Rule ID: 1785d372-b9fe-4283-96a6-3a1d83cabfd1
AV detections related to Tarrask malware
Rule ID: b6685757-3ed1-4b05-a5bd-2cacadc86c2a
AV detections related to Ukraine threats
Rule ID: 3705158d-e008-49c9-92dd-e538e1549090
AV detections related to Zinc actors
Rule ID: 90b7ac11-dd6c-4ba1-a99b-737061873859
Awake Security - High Match Counts By Device
Rule ID: d5e012c2-29ba-4a02-a813-37b928aafe2d
Awake Security - High Severity Matches By Device
Rule ID: dfa3ec92-bdae-410f-b675-fe1814e4d43e
Awake Security - Model With Multiple Destinations
Rule ID: 734c00a0-a95b-44dd-9b69-d926ed44256d
AWS role with admin privileges
Rule ID: 2526079b-3355-4756-a2d1-21e9cd957261
AWS role with shadow admin privileges
Rule ID: 9c2f6c3b-7fd8-4c5a-9d9d-3c4f9e6a7b21
AWS Security Hub - Detect CloudTrail trails lacking KMS encryption
Rule ID: d2b6fa0f-6a4c-4c48-8c64-5e2e1ac4e7b9
AWS Security Hub - Detect EC2 Security groups allowing unrestricted high-risk ports
Rule ID: de1f71d2-d127-439d-a8a2-e64d3187298a
AWS Security Hub - Detect IAM Policies allowing full administrative privileges
Rule ID: 171cbece-be87-4467-8754-63d82b3d3dfb
AWS Security Hub - Detect IAM root user Access Key existence
Rule ID: 6b3b9b1d-0d5d-4d4a-9f0f-8d1e2c7a5f44
AWS Security Hub - Detect root user lacking MFA
Rule ID: 7b8c5e2d-6f1c-4a1f-9e2a-3c5f7a8b9c10
AWS Security Hub - Detect SQS Queue lacking encryption at rest
Rule ID: 4f0f3c2a-8d44-43f8-9d9a-5b1e0d5f2c11
AWS Security Hub - Detect SQS Queue policy allowing public access
Rule ID: 0aa20f8c-b8e4-4a34-a5b8-8b2d9dd7d1c2
AWS Security Hub - Detect SSM documents public sharing enabled
Rule ID: 19602494-94af-43c8-90ba-eb0e14999612
AWSCloudTrail - Amazon ECR image scanning disabled
Rule ID: 9da99021-d318-4711-a78a-6dea76129b3a
AWSCloudTrail - AWS GuardDuty detector disabled or suspended
Rule ID: 65360bb0-8986-4ade-a89d-af3cf44d28aa
AWSCloudTrail - Changes to Amazon VPC settings
Rule ID: c7bfadd4-34a6-4fa5-82f8-3691a32261e8
AWSCloudTrail - Changes to AWS Elastic Load Balancer security groups
Rule ID: 4f19d4e3-ec5f-4abc-9e61-819eb131758c
AWSCloudTrail - Changes to AWS Security Group ingress and egress settings
Rule ID: 8c2ef238-67a0-497d-b1dd-5c8a0f533e25
AWSCloudTrail - Changes to internet facing AWS RDS Database instances
Rule ID: efdc3cff-f006-426f-97fd-4657862f7b9a
AWSCloudTrail - CloudFormation policy created then used for privilege escalation
Rule ID: 467cbe7e-e6d4-4f4e-8e44-84dd01932c32
AWSCloudTrail - Created CRUD S3 policy and then privilege escalation
Rule ID: 454133a7-5427-4a7c-bdc4-0adfa84dda16
AWSCloudTrail - Creating keys with encrypt policy without MFA
Rule ID: 9a6554e6-63d9-4f94-9b32-64d1d40628f2
AWSCloudTrail - Creation of Access Key for IAM User
Rule ID: 6f675c17-7a61-440c-abd1-c73ef4d748ec
AWSCloudTrail - Creation of CRUD DynamoDB policy and then privilege escalation
Rule ID: 8e15998e-1e32-4b6d-abd1-e8482e8f3def
AWSCloudTrail - Creation of CRUD KMS policy and then privilege escalation
Rule ID: 22115d3c-e87c-485a-9130-33797d619124
AWSCloudTrail - Creation of CRUD Lambda policy and then privilege escalation
Rule ID: 6009c632-94e9-4ffb-a11a-b4b99f457f88
AWSCloudTrail - Creation of DataPipeline policy and then privilege escalation
Rule ID: a694e977-740c-4578-9f8f-5e39029f1d23
AWSCloudTrail - Creation of EC2 policy and then privilege escalation
Rule ID: 56626956-304f-4408-8ea6-7ba5746ce09e
AWSCloudTrail - Creation of Glue policy and then privilege escalation
Rule ID: 796a45ee-220b-42be-8415-c8c933cf3b6d
AWSCloudTrail - Creation of Lambda policy and then privilege escalation
Rule ID: 8a607285-d95c-473d-8aab-59920de63af6
AWSCloudTrail - Creation of new CRUD IAM policy and then privilege escalation
Rule ID: aaa2c05e-fdd4-4fa0-9072-6cffe3641b34
AWSCloudTrail - Creation of SSM policy and then privilege escalation
Rule ID: f8577e4d-8481-437b-a94e-06f615985668
AWSCloudTrail - EC2 Startup Shell Script Changed
Rule ID: f6928301-56da-4d2c-aabe-e1a552bc8892
AWSCloudTrail - ECR image scan findings high or critical
Rule ID: 610d3850-c26f-4f20-8d86-f10fdf2425f5
AWSCloudTrail - Failed Attempts to Change AWS CloudTrail Logs
Rule ID: 826bb2f8-7894-4785-9a6b-a8a855d8366f
AWSCloudTrail - Full Admin policy created and then attached to Roles Users or Groups
Rule ID: d25b1998-a592-4bc5-8a3a-92b39eedb1bc
AWSCloudTrail - Login to AWS Management Console without MFA
Rule ID: 32555639-b639-4c2b-afda-c0ae0abefa55
AWSCloudTrail - Monitor AWS Credential abuse or hijacking
Rule ID: f8ea7d50-e33b-4b9d-9c3e-a59fcbcee281
AWSCloudTrail - Network ACL with all the open ports to a specified CIDR
Rule ID: 0ee2aafb-4500-4e36-bcb1-e90eec2f0b9b
AWSCloudTrail - NRT Login to AWS Management Console without MFA
Rule ID: 874a1762-3fd7-4489-b411-6d4a9e9e8a59
AWSCloudTrail - Policy version set to default
Rule ID: 719d5204-10ab-4b1f-aee1-da7326750260
AWSCloudTrail - Privilege escalation via CloudFormation policy
Rule ID: b9be2aa6-911d-4131-8658-d2a537ed49f4
AWSCloudTrail - Privilege escalation via CRUD DynamoDB policy
Rule ID: e20d35a3-4fec-4c8b-81b1-fc33b41990b0
AWSCloudTrail - Privilege escalation via CRUD IAM policy
Rule ID: d7c39e15-997f-49e5-a782-73bf07db8aa5
AWSCloudTrail - Privilege escalation via CRUD KMS policy
Rule ID: d0953d50-3dc1-4fa3-80fa-4d3e973a0959
AWSCloudTrail - Privilege escalation via CRUD Lambda policy
Rule ID: fc3061bb-319c-4fe9-abe2-f59899a6d907
AWSCloudTrail - Privilege escalation via CRUD S3 policy
Rule ID: 48896551-1c28-4a09-8388-e51e5a927d23
AWSCloudTrail - Privilege escalation via DataPipeline policy
Rule ID: a2b2a984-c820-4d93-830e-139bffd81fa3
AWSCloudTrail - Privilege escalation via EC2 policy
Rule ID: 370f0e5e-da1d-4a14-8ced-d1d7ab66a8d7
AWSCloudTrail - Privilege escalation via Glue policy
Rule ID: 8e01c41d-bd4c-4bbe-aed5-18592735052d
AWSCloudTrail - Privilege escalation via Lambda policy
Rule ID: c668c09f-5a49-43f9-b249-6b89a31ec8fb
AWSCloudTrail - Privilege escalation via SSM policy
Rule ID: 49ce5322-60d7-4b02-ad79-99f650aa5790
AWSCloudTrail - Privilege escalation with admin managed policy
Rule ID: 139e7116-3884-4246-9978-c8f740770bdf
AWSCloudTrail - Privilege escalation with AdministratorAccess managed policy
Rule ID: afb4191b-a142-4065-a0da-f721ee3d006c
AWSCloudTrail - Privilege escalation with FullAccess managed policy
Rule ID: 8f1630c2-2e45-4df2-be43-50fba90f601d
AWSCloudTrail - RDS instance publicly exposed
Rule ID: b7a44e0d-ae4c-4fb2-be1b-aa0e45f2327b
AWSCloudTrail - S3 bucket access point publicly exposed
Rule ID: 6b9b4ee6-f4c1-4b86-8c8c-beb0bb59ae44
AWSCloudTrail - S3 bucket exposed via ACL
Rule ID: 44a5b65e-b0a9-4591-aabc-388fd92a28c4
AWSCloudTrail - S3 bucket exposed via policy
Rule ID: b442b9e2-5cc4-4129-a85b-a5ef38a9e5f0
AWSCloudTrail - S3 bucket suspicious ransomware activity
Rule ID: 15d3bf4e-8708-41c8-a836-8b0aa5be730e
AWSCloudTrail - S3 Object Exfiltration from Anonymous User
Rule ID: 09f2a28b-3286-4268-9e2f-33805f104e5d
AWSCloudTrail - S3 object publicly exposed
Rule ID: bce1dcba-4948-414d-8838-6385afb9d496
AWSCloudTrail - SAML update identity provider
Rule ID: 75647b58-bcc8-4eb5-9658-46698d3fa153
AWSCloudTrail - SSM document is publicly exposed
Rule ID: 0adab960-5565-4978-ba6d-044553e4acc4
AWSCloudTrail - Successful API executed from a Tor exit node
Rule ID: 31b9e94b-0df6-4a3d-a297-3457b53c5d86
AWSCloudTrail - Successful brute force attack on S3 Bucket
Rule ID: 633a91df-d031-4b6e-a413-607a61540559
AWSCloudTrail - Successful Tampering with AWS CloudTrail Logs
Rule ID: 8c2dc344-9352-4ca1-8863-b1b7a5e09e59
AWSCloudTrail - Suspicious AWS CLI Command Execution
Rule ID: 9e457dc4-81f0-4d25-bc37-a5fa4a17946a
AWSCloudTrail - Suspicious AWS EC2 Compute Resource Deployments
Rule ID: 21702832-aff3-4bd6-a8e1-663b6818503d
AWSCloudTrail - Suspicious command sent to EC2
Rule ID: 60dfc193-0f73-4279-b43c-110ade02b201
AWSCloudTrail - Suspicious overly permissive KMS key policy created
Rule ID: f7210a45-12a4-4d02-b59e-f23476827a4b
AWSCloudTrail - Unauthorized EC2 Instance Setup Attempt
Rule ID: cfaaf0bc-16d1-48df-ac8b-9d901bbd516a
AWSCloudTrail - User IAM Enumeration
Rule ID: bf0cde21-0c41-48f6-a40c-6b5bd71fa106
AWSGuardDuty - GuardDuty Alert
Rule ID: 89e6adbd-612c-4fbe-bc3d-32f81baf3b6c
Azure DevOps Administrator Group Monitoring
Rule ID: acfdee3f-b794-404a-aeba-ef6a1fa08ad1
Azure DevOps Agent Pool Created Then Deleted
Rule ID: bc71cf84-c02c-4c0a-a64c-306d84f9ff89
Azure DevOps Audit Detection for known malicious tooling
Rule ID: 4e8238bd-ff4f-4126-a9f6-09b3b6801b3d
Azure DevOps Audit Stream Disabled
Rule ID: 3b9a44d7-c651-45ed-816c-eae583a6f2f1
Azure DevOps Build Variable Modified by New User
Rule ID: bf07ca9c-e408-443a-8939-6860a45a929e
Azure DevOps New Extension Added
Rule ID: 5f0d80db-3415-4265-9d52-8466b7372e3a
Azure DevOps PAT used with Browser
Rule ID: ac891683-53c3-4f86-86b4-c361708e2b2b
Azure DevOps Personal Access Token PAT misuse
Rule ID: 17f23fbe-bb73-4324-8ecf-a18545a5dc26
Azure DevOps Pipeline Created and Deleted on the Same Day
Rule ID: 155e9134-d5ad-4a6f-88f3-99c220040b66
Azure DevOps Pipeline modified by a new user
Rule ID: 4d8de9e6-263e-4845-8618-cd23a4f58b70
Azure DevOps Pull Request Policy Bypassing - Historic allow list
Rule ID: 71d374e0-1cf8-4e50-aecd-ab6c519795c2
Azure DevOps Retention Reduced
Rule ID: d564ff12-8f53-41b8-8649-44f76b37b99f
Azure DevOps Service Connection Abuse
Rule ID: 5efb0cfd-063d-417a-803b-562eae5b0301
Azure DevOps Service Connection AdditionAbuse - Historic allow list
Rule ID: 4ca74dc0-8352-4ac5-893c-73571cc78331
Azure DevOps Variable Secret Not Secured
Rule ID: 6e95aef3-a1e0-4063-8e74-cd59aa59f245
Azure Diagnostic settings removed from a resource
Rule ID: 0914adab-90b5-47a3-a79f-7cdcac843aa7
Azure Key Vault access TimeSeries anomaly
Rule ID: 68c89998-8052-4c80-a1f6-9d81060b6d57
Azure Machine Learning Write Operations
Rule ID: 87210ca1-49a4-4a7d-bb4a-4988752f978c
Azure Portal sign in from another Azure Tenant
Rule ID: 132fdff4-c044-4855-a390-c1b71e0f833b
Azure RBAC Elevate Access
Rule ID: 9a15c3dd-f72b-49a4-bcb7-94406395661e
Azure secure score admin MFA
Rule ID: C27BB559-28C5-4924-A7DA-3BF04CD02C8F
Azure secure score block legacy authentication
Rule ID: 8EB2B20A-BF64-4DCC-9D98-1AD559502C00
Azure secure score MFA registration V2
Rule ID: F539B2A7-D9E7-4438-AA20-893BC61DF130
Azure secure score one admin
Rule ID: 88C9A5E0-31EC-490B-82E5-A286D9B99A67
Azure secure score PW age policy new
Rule ID: 8E6D9A66-F1B0-463D-BA90-11A5AEC0E15A
Azure secure score role overlap
Rule ID: 114120B2-AAA0-4C4E-BDF1-2EE178465047
Azure Secure Score Self Service Password Reset
Rule ID: 5231D757-A5B5-4CA7-A91B-AA3702970E02
Azure secure score sign in risk policy
Rule ID: 1C07A4CB-E31B-4917-BD2A-3572E42F602C
Azure secure score user risk policy
Rule ID: 0610e72f-ceaf-42d1-879e-952a1bd8d07a
Azure Security Benchmark Posture Changed
Rule ID: 11bda520-a965-4654-9a45-d09f372f71aa
Azure VM Run Command operation executed during suspicious login window
Rule ID: 5239248b-abfb-4c6a-8177-b104ade5db56
Azure VM Run Command operations executing a unique PowerShell script
Rule ID: 2de8abd6-a613-450e-95ed-08e503369fb3
Azure WAF matching for Log4j vulnCVE-2021-44228
Rule ID: b8527d36-4cba-49c1-9cab-de9cdc3de879
Backup Proxy Deleted
Rule ID: 73b4d1d5-c357-4350-bb58-924684a4792a
Backup Repository Deleted
Rule ID: f78e0bb9-2878-4e36-b9c9-6141bff8d3dd
Backup Repository Settings Updated
Rule ID: ca67c83e-7fff-4127-a3e3-1af66d6d4cad
Base64 encoded Windows process command-lines
Rule ID: f8b3c49c-4087-499b-920f-0dcfaff0cbca
Base64 encoded Windows process command-lines Normalized Process Events
Rule ID: 6345c923-99eb-4a83-b11d-7af0ffa75577
Beacon Traffic Based on Common User Agents Visiting Limited Number of Domains
Rule ID: f920ac64-dfd0-4dea-9b7c-acecf1ea2b28
Best Practice Compliance Check Not Passed
Rule ID: cdb6e4a4-b9bd-4c30-94b9-ecce5a72d528
Bitglass - Impossible travel distance
Rule ID: bfca0251-1581-4185-906b-4805099e3216
Bitglass - Login from new device
Rule ID: 7c570bfc-9f20-490e-80e8-b898c7ce4bda
Bitglass - Multiple failed logins
Rule ID: 09690f9b-33d1-4372-a6aa-eb7d3b3cdebc
Bitglass - Multiple files shared with external entity
Rule ID: 8c8602e6-315d-400f-9d1e-23bbdee1dbfe
Bitglass - New admin user
Rule ID: a123668c-d907-41b9-bf3f-8cb4cd7b163a
Bitglass - New risky user
Rule ID: 4b272e82-19f1-40d1-bfdf-74fbb6353e8b
Bitglass - Suspicious file uploads
Rule ID: 40f69a27-8c68-4c8c-bb7c-7eb0f0a8a1fa
Bitglass - The SmartEdge endpoint agent was uninstalled
Rule ID: 4dd61530-859f-49e7-bd27-a173cb1a4589
Bitglass - User Agent string has changed for user
Rule ID: 34401e66-9fe9-476b-a443-3a3f89e4f3b0
Bitglass - User login from new geo location
Rule ID: 2a1dc4c2-a8d6-4a0e-8539-9b971c851195
Bitsadmin Activity
Rule ID: d68b758a-b117-4cb8-8e1d-dcab5a4a2f21
BitSight - compromised systems detected
Rule ID: 161ed3ac-b242-4b13-8c6b-58716e5e9972
BitSight - diligence risk category detected
Rule ID: d8844f11-3a36-4b97-9062-1e6d57c00e37
BitSight - drop in company ratings
Rule ID: b11fdc35-6368-4cc0-8128-52cd2e2cdda0
BitSight - drop in the headline rating
Rule ID: a1275c5e-0ff4-4d15-a7b7-96018cd979f5
BitSight - new alert found
Rule ID: a5526ba9-5997-47c6-bf2e-60a08b681e9b
BitSight - new breach found
Rule ID: e261b70a-3005-4a1b-a7a2-2c8147fafed7
blacklens Insights
Rule ID: 34099af9-e79a-4d5a-a50c-c5e51f5bb965
BloodHound Attack Path Finding - Add Key Credential Link Privileges on Tier Zero Objects
Rule ID: 17c3d3b1-42f1-4bbd-bcbd-6ab7621448c9
BloodHound Attack Path Finding - Add Member Privileges on Tier Zero Security Groups
Rule ID: 357d3dee-3b61-4de9-9084-fb245ba23d81
BloodHound Attack Path Finding - Add Members to Tier Zero Group
Rule ID: 58c70f97-543b-4116-8624-12ee7ad8a13d
BloodHound Attack Path Finding - Add Owner to Tier Zero Object via MS Graph App Role
Rule ID: ca509c4b-d30f-4bad-b59c-4d0ddd0fc822
BloodHound Attack Path Finding - Add Resource-Based Constrained Delegation Privileges on Tier Zero Computers
Rule ID: 01ee9ec6-ca69-478d-8830-8fa598ae73d9
BloodHound Attack Path Finding - Add Secret to Tier Zero Principal
Rule ID: 3d6fa984-a989-4742-bcc2-099d2a995ef7
BloodHound Attack Path Finding - AddOwner Role on Tier Zero Resource
Rule ID: f2e24dac-37a2-493d-a8d7-5b7f6bea438c
BloodHound Attack Path Finding - AddSelf Privilege on Tier Zero Security Groups
Rule ID: b0b747f2-938a-4f13-b7d1-9def60a719bd
BloodHound Attack Path Finding - Admins on Tier Zero Computers
Rule ID: 77d9d959-e899-4a43-a376-d2e4059ca8f4
BloodHound Attack Path Finding - AKS Contributor Role on Tier Zero Managed Cluster
Rule ID: 234ba956-2361-4db2-a9d4-c4c89fb2ed55
BloodHound Attack Path Finding - AllExtended Privileges on Tier Zero Objects
Rule ID: ba785c29-37f7-469b-b437-495bfdf136eb
BloodHound Attack Path Finding - App Admin Control of Tier Zero Principal
Rule ID: 1f9610b1-f9e0-4da2-9600-12f07ba6f437
BloodHound Attack Path Finding - AS-REP Roastable User Accounts
Rule ID: 9bd607bf-a64c-4917-913e-e9a33f4ea28e
BloodHound Attack Path Finding - Avere Contributor Role on Tier Zero Virtual Machine
Rule ID: 39984923-f74a-45ea-b321-b1dd45ba04e2
BloodHound Attack Path Finding - Cloud App Admin Over Tier Zero Principal
Rule ID: bdfa4b55-e385-4035-8af8-ea77df4a81c3
BloodHound Attack Path Finding - Command Execution on Tier Zero Virtual Machine
Rule ID: e9ef6adb-6fa3-49ff-b105-c4cbd4f37808
BloodHound Attack Path Finding - Computers Vulnerable to Coercion-Based NTLM Relay to SMB Attack
Rule ID: 7b2cc2d2-052f-4ac9-9be0-fb6f22cbca33
BloodHound Attack Path Finding - Constrained Delegation on Tier Zero Computers
Rule ID: 04a117f0-ff6e-464b-984d-119e33fb0dd5
BloodHound Attack Path Finding - Contributor Role on Tier Zero Automation Account
Rule ID: 36191460-f26a-4c4e-8492-71e6049e6bbb
BloodHound Attack Path Finding - Contributor Role on Tier Zero Resource
Rule ID: c322a41b-c759-4aca-ac9a-25b00791c397
BloodHound Attack Path Finding - DCOM Users on Tier Zero Computers
Rule ID: e426256f-eb14-4b05-9aad-f630944e7012
BloodHound Attack Path Finding - ForceChangePassword Privileges on Tier Zero Objects
Rule ID: 5ae4f7e1-b14c-45fe-8d38-f409e148c1da
BloodHound Attack Path Finding - GenericAll Privileges on Tier Zero Objects
Rule ID: 20d7a85c-6af9-4471-a403-961445c0e49e
BloodHound Attack Path Finding - GenericWrite Privileges on Tier Zero Objects
Rule ID: 21d458a0-b0d5-47bb-9fd1-fdda31f3b7f1
BloodHound Attack Path Finding - Get Certifcates on Tier Zero Key Vault
Rule ID: fbeabff4-fad7-4458-8098-c6426388cf3d
BloodHound Attack Path Finding - Get Keys on Tier Zero Key Vault
Rule ID: cd3e607c-8ab4-4799-a27e-7ff63ae401af
BloodHound Attack Path Finding - Get Secrets on Tier Zero Key Vault
Rule ID: 008a74e7-ad90-4855-87e6-6bdb86eed127
BloodHound Attack Path Finding - Kerberoastable User Accounts
Rule ID: 2f770ce2-97cb-4afc-8dce-28114c3ad66e
BloodHound Attack Path Finding - Kerberos Delegation on Tier Zero Objects
Rule ID: 7b7347d2-3efb-47d9-a329-5b7ae4357d70
BloodHound Attack Path Finding - Key Vault Contributor Role on Tier Zero Resource
Rule ID: af134cb3-a3e7-421c-bcef-0c6c6432a273
BloodHound Attack Path Finding - Large Default Group With SyncLapsPassword Privileges
Rule ID: e3c95148-04b6-4165-b9a6-a107f8a119d9
BloodHound Attack Path Finding - Large Default Groups in DCOM Users Groups
Rule ID: 141b9381-50fe-4beb-a91a-799da4f466fc
BloodHound Attack Path Finding - Large Default Groups in Local Administrator Groups
Rule ID: ac15bea7-c2c2-4f0f-b13c-2099f4d86f77
BloodHound Attack Path Finding - Large Default Groups in PS Remote Users Groups
Rule ID: 000d4f86-fc35-4451-9b2b-2a660a95f715
BloodHound Attack Path Finding - Large Default Groups in SQL Admins Groups
Rule ID: 2f65df97-23a1-403b-93ea-6e478ee75c5a
BloodHound Attack Path Finding - Large Default Groups With Add Key Credential Link Privileges
Rule ID: 36262b9d-fc92-47fb-8ec1-bda6e74e3d4e
BloodHound Attack Path Finding - Large Default Groups With Add Member Privileges
Rule ID: 6a9a4ef0-e08b-40ad-ad40-c88b6ab915ae
BloodHound Attack Path Finding - Large Default Groups With Add Self Privileges
Rule ID: ab49f284-0b2a-42c9-b5e3-2c0fbf941d8e
BloodHound Attack Path Finding - Large Default Groups With All Extended Privileges
Rule ID: b4f835f1-3ce1-4009-9dcd-816ba4107e9b
BloodHound Attack Path Finding - Large Default Groups With ForceChangePassword Privileges
Rule ID: 54a6167c-f1a3-45a1-8fd0-6023dbda9446
BloodHound Attack Path Finding - Large Default Groups With GenericAll Privileges
Rule ID: 8193f4fc-383e-45b0-8ef5-15ef1eeae7e3
BloodHound Attack Path Finding - Large Default Groups With GenericWrite Privileges
Rule ID: 12ecc3cf-a1db-4fa4-bcb2-605dd3a274e0
BloodHound Attack Path Finding - Large Default Groups With Limited Ownership Privileges
Rule ID: 222e7627-fc25-4ffd-a312-5a27513800ea
BloodHound Attack Path Finding - Large Default Groups With Ownership Privileges
Rule ID: f4776f0d-86b7-470a-993a-f3152bbb8917
BloodHound Attack Path Finding - Large Default Groups With RDP Access
Rule ID: 86eda318-a551-438c-b72a-3db0ba6bc27e
BloodHound Attack Path Finding - Large Default Groups With Read GMSA Password Privileges
Rule ID: d6450ee2-2161-4d3c-96c9-674c3c44a791
BloodHound Attack Path Finding - Large Default Groups With Read LAPS Password Privileges
Rule ID: a50a328d-a14d-4599-a4e4-32de5b7fe0c7
BloodHound Attack Path Finding - Large Default Groups With Resource-Based Constrained Delegation Privileges
Rule ID: 506957d5-23e2-4d38-b047-2273c121831c
BloodHound Attack Path Finding - Large Default Groups With WriteAccountRestrictions Privileges
Rule ID: cfa3b93b-0203-4dd1-b784-c148af74e389
BloodHound Attack Path Finding - Large Default Groups With WriteDacl Privilege
Rule ID: 660af442-45ec-4321-b6ce-ee39677f0472
BloodHound Attack Path Finding - Large Default Groups With WriteGpLink Privilege
Rule ID: f2f15e17-c056-487b-ad96-13128c8a6024
BloodHound Attack Path Finding - Large Default Groups With WriteOwner Privileges
Rule ID: b26a44aa-aec3-4cfe-aa75-e41104f97a9a
BloodHound Attack Path Finding - Large Default Groups With WriteOwnerLimitedRights Privileges
Rule ID: 8bbc3980-8b18-40c5-829e-d282afa52284
BloodHound Attack Path Finding - Large Default Groups With WriteServicePrincipalName Privileges
Rule ID: 92914273-eb38-4a54-9c5d-03db8d24fba7
BloodHound Attack Path Finding - Legacy SID History on Tier Zero Objects
Rule ID: a2150e6d-b75b-4440-9c7e-18e901fb0b13
BloodHound Attack Path Finding - Limited Ownership Privileges on Tier Zero Objects
Rule ID: 25ffa891-4832-485d-9461-f8c90df1d3ff
BloodHound Attack Path Finding - Logic App Contributor Role on Tier Zero Logic App
Rule ID: cf22c2f4-fdc6-465f-8d71-561af44bd475
BloodHound Attack Path Finding - Logons From Tier Zero Users
Rule ID: 1eb72567-2785-44d0-81dd-6a2b08803cdf
BloodHound Attack Path Finding - Non Tier Zero Principals With ADCS ESC1 Privileges
Rule ID: 14adaa12-cad0-41ca-b848-f536723e4117
BloodHound Attack Path Finding - Non Tier Zero Principals With ADCS ESC10 Scenario A Privileges
Rule ID: 82c9f9b1-2990-4d5c-a5f4-26e4e54c904c
BloodHound Attack Path Finding - Non Tier Zero Principals With ADCS ESC13 Privileges Against Tier Zero Group
Rule ID: 9fe3e89b-fd57-4df1-a6e7-8a875966dada
BloodHound Attack Path Finding - Non Tier Zero Resource Assigned to Tier Zero Service Principal
Rule ID: 8844495b-1d05-4080-9fc2-28621f744a4b
BloodHound Attack Path Finding - Non-Tier Zero AD User Synced to Tier Zero Entra User
Rule ID: 64ba60b8-67d4-4356-8b88-0dfbf98e454a
BloodHound Attack Path Finding - Non-Tier Zero Computer Hosting EnterpriseCA Trusted for NT Authentication
Rule ID: 94e4114f-acd5-48d9-8b5e-07d08b809541
BloodHound Attack Path Finding - Non-Tier Zero Entra User Synced to Tier Zero AD User
Rule ID: 8e1df707-a242-42ba-a0aa-68b61f1e620d
BloodHound Attack Path Finding - Non-Tier Zero Principal Can Grant Tier Zero App Roles
Rule ID: 146f6a92-d11a-4728-b66d-6d4dc359ff59
BloodHound Attack Path Finding - Non-Tier Zero Principal Can Grant Tier Zero Entra ID Role
Rule ID: bc26d218-89a4-40ba-88b6-76e5141b5731
BloodHound Attack Path Finding - Non-Tier Zero Principal Trusted for Unconstrained Delegation
Rule ID: d9fb446e-58a9-4788-afee-66a2b5391347
BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC10 Scenario B Privileges
Rule ID: e6c6fb5d-c2a4-4ff4-8c75-a66f37e1ecc0
BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC3 Privileges
Rule ID: dcd1c727-2084-44d8-871c-a74ac0d8f091
BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC4 Privileges
Rule ID: ca313efd-032c-4825-b687-86c50e92200f
BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC6 Scenario A Privileges
Rule ID: 3050426c-56c0-4a20-9bb2-9d63d3c59484
BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC6 Scenario B Privileges
Rule ID: 4f431f88-ada9-4a20-bbe5-fddc7add942e
BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC9 Scenario A Privileges
Rule ID: 93a17e41-1504-4ef3-8a1e-7ad15a32ce98
BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC9 Scenario B Privileges
Rule ID: d6bf4db8-f2f3-4738-9051-bb892b268da3
BloodHound Attack Path Finding - Non-Tier Zero Principals With DCSync Privileges
Rule ID: cc168d7f-59d1-4472-be98-854869e62907
BloodHound Attack Path Finding - Owner Role on Tier Zero Resource
Rule ID: d902d7c1-8a9c-469a-9899-7222214a0663
BloodHound Attack Path Finding - Ownership of Tier Zero Principal
Rule ID: 4dcc4d52-947b-4680-89be-b08a71def3d4
BloodHound Attack Path Finding - Ownership Privileges on Tier Zero Objects
Rule ID: 25ea90f3-89d6-417f-8e16-2e7fee38ccf6
BloodHound Attack Path Finding - PS Remote Users on Tier Zero Computers
Rule ID: 0eefbca4-0dde-4e72-afaa-dbacc131d07a
BloodHound Attack Path Finding - RDP Users on Tier Zero Computers
Rule ID: d738e45b-472b-4d6b-a1a0-258c4fe9eb26
BloodHound Attack Path Finding - Read GMSA Password Privileges on Tier Zero Objects
Rule ID: 1a7721b8-028f-47d2-a1aa-dbb307aefb27
BloodHound Attack Path Finding - ReadLapsPassword Privileges on Tier Zero Objects
Rule ID: 7874ea85-ec86-4519-9aa6-7b7d8c8c4a21
BloodHound Attack Path Finding - Reset a Tier Zero Users Password
Rule ID: b3c6f684-5fb3-451d-b1d9-fec8089c2503
BloodHound Attack Path Finding - SQL Admin Users on Tier Zero Computers
Rule ID: 31d40f68-8bc5-44f0-bf8c-c9c17d9ef1c8
BloodHound Attack Path Finding - SyncLapsPassword Privileges on Tier Zero Objects
Rule ID: 28b86df8-daa1-4b94-939b-903c24d8196d
BloodHound Attack Path Finding - Tier Zero Computer Vulnerable to Coercion-Based NTLM Relay to ADCS ESC8 Attack
Rule ID: 1bc4eeaa-08d8-47b6-85ab-bbea5a062282
BloodHound Attack Path Finding - Tier Zero Computer Vulnerable to Coercion-Based NTLM Relay to LDAP Attack
Rule ID: 37a04fa0-b13c-43d9-a6a0-f34229ebf8f4
BloodHound Attack Path Finding - Tier Zero Computer Vulnerable to Coercion-Based NTLM Relay to LDAPS Attack
Rule ID: 70e09635-9787-41af-9973-87d22ca15292
BloodHound Attack Path Finding - Tier Zero Group Control via MS Graph App Role
Rule ID: d817dc53-1787-4b02-b8cf-d6254eec5ddb
BloodHound Attack Path Finding - Tier Zero Service Principal Control via MS Graph App Role
Rule ID: 221a122d-8e68-42c9-beaf-010fe184a88f
BloodHound Attack Path Finding - Tier Zero SMSA Installed on Non-Tier Zero Computer
Rule ID: ccd94d43-3d74-4928-93bf-eb9bfe7924ca
BloodHound Attack Path Finding - User Access Admin Role on Tier Zero Resource
Rule ID: f1334bfc-7cdd-4655-b8de-e1398158f4b5
BloodHound Attack Path Finding - VM Admin Login Role on Tier Zero System
Rule ID: 6356d718-5a61-4f74-b8a4-f93b0b721e9a
BloodHound Attack Path Finding - VM Contributor Role on Tier Zero System
Rule ID: a1052a3e-d955-4a0b-9f96-179393e7741a
BloodHound Attack Path Finding - Website Contributor Role on Tier Zero Resource
Rule ID: f1a667b2-91a8-4a9b-8d31-9a54bb5f0cd5
BloodHound Attack Path Finding - Write Account Restrictions Privileges on Tier Zero Objects
Rule ID: c09d3a9d-47da-4bd8-a14d-ea51b447d75d
BloodHound Attack Path Finding - WriteDacl Privileges on Tier Zero Objects
Rule ID: b64ee057-94a4-42a5-a769-430a2943f764
BloodHound Attack Path Finding - WriteGpLink Privileges on Tier Zero Objects
Rule ID: 924e60be-38af-4a33-98d4-45f2b1643094
BloodHound Attack Path Finding - WriteOwner Privileges on Tier Zero Objects
Rule ID: 645b0f09-f318-41c3-860d-6c0fb595af2b
BloodHound Attack Path Finding - WriteOwnerLimitedRights Privileges on Tier Zero Objects
Rule ID: b58af025-1b74-436a-8517-b230864cbbb6
BloodHound Attack Path Finding - WriteServicePrincipalName Privileges on Tier Zero Objects
Rule ID: 3c5be96e-2eeb-439a-9856-1c23aa72cfdd
BOLA Finding with API Traffic Anomaly
Rule ID: 1139230c-cf10-45db-b616-fed0d1415c05
Box - Abmormal user activity
Rule ID: b91ec98d-5747-45c8-b2f6-a07bf47068f0
Box - Executable file in folder
Rule ID: 266746ae-5eaf-4068-a980-5d630f435c46
Box - File containing sensitive data
Rule ID: 8889e69c-2161-412a-94a6-76c1b2d9daa7
Box - Forbidden file type downloaded
Rule ID: edbf38d7-e170-4af2-ad50-1a05b374611b
Box - Inactive user login
Rule ID: 3b803560-f8a6-4db4-89cb-617d89724ba1
Box - Item shared to external entity
Rule ID: 1b212329-6f2c-46ca-9071-de3464f3d88d
Box - Many items deleted by user
Rule ID: fd36ac88-cd92-4137-aa23-37a3648621fa
Box - New external user
Rule ID: b2197d7f-4731-483c-89de-d48606b872da
Box - User logged in as admin
Rule ID: 174c31c9-22ec-42e5-8226-814391c08200
Box - User role changed to owner
Rule ID: 3fbc20a4-04c4-464e-8fcb-6667f53e4987
Brute force attack against an Entra-authenticated Windows device
Rule ID: 28b42356-45af-40a6-a0b4-a554cdfd5d8a
Brute force attack against Azure Portal
Rule ID: 97ad74c4-fdd9-4a3f-b6bf-5e28f4f71e06
Brute Force Attack against GitHub Account
Rule ID: 5a6ce089-e756-40fb-b022-c8e8864a973a
Brute force attack against user credentials
Rule ID: a6c435a2-b1a0-466d-b730-9f8af69262e8
Brute force attack against user credentials Uses Authentication Normalization
Rule ID: 218f60de-c269-457a-b882-9966632b9dc6
Bulk Changes to Privileged Account Permissions
Rule ID: 7ce00cba-f76f-4026-ab7f-7e4f1b67bd18
C2-NamedPipe
Rule ID: 06360572-94a7-42a4-add7-58fb933b2353
Canary alerts to incidents
Rule ID: 066395ac-ef91-4993-8bf6-25c61ab0ca5a
Caramel Tsunami Actor IOC - July 2021
Rule ID: e6f6c71c-f1fd-473b-9129-249db5d7462c
Cayosoft Guardian - Cloud Application Security Threats
Rule ID: 4720d7a5-6845-4ce4-aa45-79334e1a1176
Cayosoft Guardian - Core Identity and Infrastructure Threats
Rule ID: e15944a8-4172-4208-a928-631e01920d9c
CDM_ContinuousDiagnosticsMitigation_Posture
Rule ID: fd950af9-d9db-4879-a60a-7267cc041beb
CDM_ContinuousDiagnosticsMitigation_PostureChanged
Rule ID: aa5eaac7-1264-4833-b620-8f062be75541
Certified Pre-Owned - backup of CA private key - rule 1
Rule ID: 88f8fbc0-345d-458e-85f6-f73921d5ef50
Certified Pre-Owned - backup of CA private key - rule 2
Rule ID: b838a13c-052e-45b8-a5ac-7d3eb62efa11
Certified Pre-Owned - TGTs requested with certificate authentication
Rule ID: 4a9d3c2e-7f1b-4e58-9a0c-2d5b8e3f1a7c
CertUtil Used for File Download Living off the Land
Rule ID: 492fbe35-cbac-4a8c-9059-826782e6915a
Changes to Application Logout URL
Rule ID: cc5780ce-3245-4bba-8bc1-e9048c2257ce
Changes to Application Ownership
Rule ID: 0ed0fe7c-af29-4990-af7f-bb5ccb231198
Changes to PIM Settings
Rule ID: 8d3b9c7e-5a2f-4e1d-b6c8-3f9a7e2d1b4c
Check Point Exposure Management - Alert Ingestion Anomaly
Rule ID: 2f7c4e91-6b8d-4a3f-9e15-c0d84b7a2f36
Check Point Exposure Management - Argos alerts to incidents
Rule ID: a97e2333-b7de-4c14-9700-e652a1dbef26
Checkpoint - Pending Phishing emails
Rule ID: 4d173248-439b-4741-8b37-f63ad0c896ae
Chia_Crypto_Mining IOC - June 2021
Rule ID: 157c0cfc-d76d-463b-8755-c781608cdc1a
Cisco - firewall block but success logon to Microsoft Entra ID
Rule ID: 79f29feb-6a9d-4cdf-baaa-2daf480a5da1
Cisco ASA - average attack detection rate increase
Rule ID: f3a8c2d0-7b41-4e9a-9f6a-2d8a1c4e5b72
Cisco ASA - Possible Data Exfiltration Detection
Rule ID: 795edf2d-cf3e-45b5-8452-fe6c9e6a582e
Cisco ASA - threat detection message fired
Rule ID: 398dd1cd-3251-49d8-b927-5b93bae4a094
Cisco Duo - AD sync failed
Rule ID: 413e49a5-b107-4698-8428-46b89308bd22
Cisco Duo - Admin password reset
Rule ID: 0724cb01-4866-483d-a149-eb400fe1daa8
Cisco Duo - Admin user created
Rule ID: 6424c623-31a5-4892-be33-452586fd4075
Cisco Duo - Admin user deleted
Rule ID: 01df3abe-3dc7-40e2-8aa7-f00b402df6f0
Cisco Duo - Authentication device new location
Rule ID: e46c5588-e643-4a60-a008-5ba9a4c84328
Cisco Duo - Multiple admin 2FA failures
Rule ID: 034f62b6-df51-49f3-831f-1e4cfd3c40d2
Cisco Duo - Multiple user login failures
Rule ID: 6e4f9031-91d3-4fa1-8baf-624935f04ad8
Cisco Duo - Multiple users deleted
Rule ID: f05271b6-26a5-49cf-ad73-4a202fba6eb6
Cisco Duo - New access device
Rule ID: 16c91a2c-17ad-4985-a9ad-4a4f1cb11830
Cisco Duo - Unexpected authentication factor
Rule ID: 232a1c75-63fc-4c81-8b18-b4a739fccba8
Cisco SDWAN - Intrusion Events
Rule ID: dc3627c3-f9de-4f17-bfd3-ba99b64a0a67
Cisco SDWAN - IPS Event Threshold
Rule ID: cb14defd-3415-4420-a2e4-2dd0f3e07a86
Cisco SDWAN - Maleware Events
Rule ID: a62a207e-62be-4a74-acab-4466d5b3854f
Cisco SDWAN - Monitor Critical IPs
Rule ID: 0f788a93-dc88-4f80-89ef-bef7cd0fef05
Cisco SE - Connection to known C2 server
Rule ID: b6df3e11-de70-4779-ac9a-276c454a9025
Cisco SE - Dropper activity on host
Rule ID: bccdbc39-31d3-4e2b-9df2-e4c9eecba825
Cisco SE - Generic IOC
Rule ID: aea4468e-6322-48b6-bd83-f9d300cce855
Cisco SE - Malware execusion on host
Rule ID: 225053c7-085b-4fca-a18f-c367f9228bf3
Cisco SE - Malware outbreak
Rule ID: b13489d7-feb1-4ad3-9a4c-09f6d64448fd
Cisco SE - Multiple malware on host
Rule ID: 64fece0a-44db-4bab-844d-fd503dc0aaba
Cisco SE - Policy update failure
Rule ID: d2c97cc9-1ccc-494d-bad4-564700451a2b
Cisco SE - Possible webshell
Rule ID: c9629114-0f49-4b50-9f1b-345287b2eebf
Cisco SE - Ransomware Activity
Rule ID: eabb9c20-7b0b-4a77-81e8-b06944f351c6
Cisco SE - Unexpected binary file
Rule ID: 4683ebce-07ad-4089-89e3-39d8fe83c011
Cisco SE High Events Last Hour
Rule ID: df5c34dd-e1e6-4e07-90b1-4309ebfe754c
Cisco SEG - DLP policy violation
Rule ID: 236e872c-31d1-4b45-ac2a-fda3af465c97
Cisco SEG - Malicious attachment not blocked
Rule ID: 1399a9a5-6200-411e-8c34-ca5658754cf7
Cisco SEG - Multiple large emails sent to external recipient
Rule ID: dfdb9a73-4335-4bb4-b29b-eb713bce61a6
Cisco SEG - Multiple suspiciuos attachments received
Rule ID: 53242559-95ea-4d4c-b003-107e8f06304b
Cisco SEG - Possible outbreak
Rule ID: 2e5158e1-9fc2-40ff-a909-c701a13a0405
Cisco SEG - Potential phishing link
Rule ID: 506291dd-8050-4c98-a92f-58e376080a0a
Cisco SEG - Suspicious link
Rule ID: ef0a253c-95b5-48e1-8ebc-dbeb073b9338
Cisco SEG - Suspicious sender domain
Rule ID: f8ba18c4-81e3-4db0-8f85-4989f2ed2ade
Cisco SEG - Unexpected attachment
Rule ID: 9cb4a02d-3708-42ba-b33b-0fdd360ce4b6
Cisco SEG - Unexpected link
Rule ID: c66b8ced-8c76-415b-a0f3-08c7030a857d
Cisco SEG - Unscannable attacment
Rule ID: c9b6d281-b96b-4763-b728-9a04b9fe1246
Cisco Umbrella - Connection to non-corporate private network
Rule ID: 75297f62-10a8-4fc1-9b2a-12f25c6f05a7
Cisco Umbrella - Connection to Unpopular Website Detected
Rule ID: b619d1f1-7f39-4c7e-bf9e-afbb46457997
Cisco Umbrella - Crypto Miner User-Agent Detected
Rule ID: 2b328487-162d-4034-b472-59f1d53684a1
Cisco Umbrella - Empty User Agent Detected
Rule ID: 8d537f3c-094f-430c-a588-8a87da36ee3a
Cisco Umbrella - Hack Tool User-Agent Detected
Rule ID: 8c8de3fa-6425-4623-9cd9-45de1dd0569a
Cisco Umbrella - Rare User Agent Detected
Rule ID: d6bf1931-b1eb-448d-90b2-de118559c7ce
Cisco Umbrella - Request Allowed to harmfulmalicious URI category
Rule ID: de58ee9e-b229-4252-8537-41a4c2f4045e
Cisco Umbrella - Request to blocklisted file type
Rule ID: ee1818ec-5f65-4991-b711-bcf2ab7e36c3
Cisco Umbrella - URI contains IP address
Rule ID: b12b3dab-d973-45af-b07e-e29bb34d8db9
Cisco Umbrella - Windows PowerShell User-Agent Detected
Rule ID: 38029e86-030c-46c4-8a91-a2be7c74d74c
Cisco WSA - Access to unwanted site
Rule ID: 4250b050-e1c6-4926-af04-9484bbd7e94f
Cisco WSA - Internet access from public IP
Rule ID: 46b6c6fc-2c1a-4270-be10-9d444d83f027
Cisco WSA - Multiple attempts to download unwanted file
Rule ID: ebf9db0c-ba7b-4249-b9ec-50a05fa7c7c9
Cisco WSA - Multiple errors to resource from risky category
Rule ID: 1db49647-435c-41ad-bf8c-7130ba75429d
Cisco WSA - Multiple errors to URL
Rule ID: 93186e3d-5dc2-4a00-a993-fa1448db8734
Cisco WSA - Multiple infected files
Rule ID: 6f756792-4888-48a5-97cf-40d9430dc932
Cisco WSA - Suspected protocol abuse
Rule ID: 8e9d1f70-d529-4598-9d3e-5dd5164d1d02
Cisco WSA - Unexpected file type
Rule ID: 32c460ad-2d40-43e9-8ead-5cdd1d7a3163
Cisco WSA - Unexpected uploads
Rule ID: 010644fd-2830-4451-9e0e-606cc192f2e7
Cisco WSA - Unexpected URL
Rule ID: 9b61a945-ebcb-4245-b6e4-51f3addb5248
Cisco WSA - Unscannable file or scan error
Rule ID: 1fa0da3e-ec99-484f-aadb-93f59764e158
CiscoISE - Command executed with the highest privileges from new IP
Rule ID: b6549a28-d61c-476e-b350-4404352ee427
CiscoISE - Attempt to delete local store logs
Rule ID: 4eddd44a-25e4-41af-930d-0c17218bec74
CiscoISE - Backup failed
Rule ID: 6107cba5-2974-4c22-8222-2a6f7bbea664
CiscoISE - Certificate has expired
Rule ID: e71890a2-5f61-4790-b1ed-cf1d92d3e398
CiscoISE - Command executed with the highest privileges by new user
Rule ID: 0c509e9b-121e-4951-9f9b-43722e052b4f
CiscoISE - Device changed IP in last 24 hours
Rule ID: 548a2eda-d3eb-46cc-8d4b-1601551629e4
CiscoISE - Device PostureStatus changed to non-compliant
Rule ID: e63b4d90-d0a8-4609-b187-babfcc7f86d7
CiscoISE - ISE administrator password has been reset
Rule ID: ce171782-1643-4f21-bbb7-fa954b1e6897
CiscoISE - Log collector was suspended
Rule ID: 21d3be4c-6088-4e76-b6eb-d25479019cb9
CiscoISE - Log files deleted
Rule ID: fd6e3416-0421-4166-adb9-186e555a7008
Claroty - Asset Down
Rule ID: 9a8b4321-e2be-449b-8227-a78227441b2a
Claroty - Critical baseline deviation
Rule ID: e7dbcbc3-b18f-4635-b27c-718195c369f1
Claroty - Login to uncommon location
Rule ID: 4b5bb3fc-c690-4f54-9a74-016213d699b4
Claroty - Multiple failed logins by user
Rule ID: 1c2310ef-19bf-4caf-b2b0-a4c983932fa5
Claroty - Multiple failed logins to same destinations
Rule ID: 6c29b611-ce69-4016-bf99-eca639fee1f5
Claroty - New Asset
Rule ID: 3b22ac47-e02c-4599-a37a-57f965de17be
Claroty - Policy violation
Rule ID: 99ad9f3c-304c-44c5-a61f-3a17f8b58218
Claroty - Suspicious activity
Rule ID: 5cf35bad-677f-4c23-8927-1611e7ff6f28
Claroty - Suspicious file transfer
Rule ID: 731e5ac4-7fe1-4b06-9941-532f2e008bb3
Claroty - Threat detected
Rule ID: 515d0bba-b297-4f83-8280-20ff7f27ecb1
Clearing of forensic evidence from event logs using wevtutil
Rule ID: a9956d3a-07a9-44a6-a279-081a85020cae
ClientDeniedAccess
Rule ID: 72239d5b-ef96-4f15-896f-6cdcd9c53ca7
Cloud Gateway Deleted
Rule ID: 73e1d89b-79a6-4ab0-b3bb-5e564fcf10f1
Cloud Gateway Pool Deleted
Rule ID: 2b3b59eb-ea7c-45f6-9df8-8dbaed632317
Cloud Gateway Pool Settings Updated
Rule ID: 9f0d4171-9a9f-42e4-acbf-9093dd4203de
Cloud Gateway Settings Updated
Rule ID: 1f1634e5-585e-4187-ac5b-6d0e157bd2ea
Cloud Replica Permanent Failover Performed by Tenant
Rule ID: a7ce6135-9d55-4f14-b058-adc2e920a4fa
Cloudflare - Bad client IP
Rule ID: a7ce6135-9d55-4f14-b058-adc2e920a4fb
Cloudflare - Bad client IP
Rule ID: 40554544-6e4a-4413-8d14-bf2de939c5d0
Cloudflare - Client request from country in blocklist
Rule ID: 40554544-6e4a-4413-8d14-bf2de939c5d9
Cloudflare - Client request from country in blocklist
Rule ID: 729c6d21-fad9-4a6a-9c7f-482393c95957
Cloudflare - Empty user agent
Rule ID: 729c6d21-fad9-4a6a-9c7f-482393c95958
Cloudflare - Empty user agent
Rule ID: ef877d68-755f-4cf1-ac1d-f336e395667c
Cloudflare - Multiple error requests from single source
Rule ID: ef877d68-755f-4cf1-ac1d-f336e395667d
Cloudflare - Multiple error requests from single source
Rule ID: fc50076a-0275-43d5-b9dd-38346c061f67
Cloudflare - Multiple user agents for single source
Rule ID: fc50076a-0275-43d5-b9dd-38346c061f68
Cloudflare - Multiple user agents for single source
Rule ID: f32142b1-4bcb-45c0-92e4-2ddc18768522
Cloudflare - Unexpected client request
Rule ID: f32142b1-4bcb-45c0-92e4-2ddc18768523
Cloudflare - Unexpected client request
Rule ID: 7313352a-09f6-4a84-88bd-6f17f1cbeb88
Cloudflare - Unexpected POST requests
Rule ID: 7313352a-09f6-4a84-88bd-6f17f1cbeb8f
Cloudflare - Unexpected POST requests
Rule ID: dcb797cd-a4cd-4306-897b-7991f71d7e27
Cloudflare - Unexpected URI
Rule ID: dcb797cd-a4cd-4306-897b-7991f71d7e28
Cloudflare - Unexpected URI
Rule ID: f53fe2a9-96b5-454c-827e-cf1764a67fb0
Cloudflare - WAF Allowed threat
Rule ID: f53fe2a9-96b5-454c-827e-cf1764a67fb1
Cloudflare - WAF Allowed threat
Rule ID: 4d9d00b9-31a6-49e4-88c1-9e68277053ac
Cloudflare - XSS probing pattern in request
Rule ID: 4d9d00b9-31a6-49e4-88c1-9e68277053ad
Cloudflare - XSS probing pattern in request
Rule ID: fb127436-e5c4-4e31-85a8-d3507128dd09
CMMC 20 Level 1 Foundational Readiness Posture
Rule ID: 7bfe573b-3069-4e81-98fe-9a4cffbcbc24
CMMC 20 Level 2 Advanced Readiness Posture
Rule ID: 44e80f00-b4f5-486b-a57d-4073746276df
Cognni Incidents for Highly Sensitive Business Information
Rule ID: 7ebb7386-6c99-4331-aab1-a185a603eb47
Cognni Incidents for Highly Sensitive Financial Information
Rule ID: 2926ce29-08d2-4654-b2e8-7d8df70095d9
Cognni Incidents for Highly Sensitive Governance Information
Rule ID: f68846cf-ec99-497d-9ce1-80a9441564fb
Cognni Incidents for Highly Sensitive HR Information
Rule ID: 4f45f43b-3a4b-491b-9cbe-d649603384aa
Cognni Incidents for Highly Sensitive Legal Information
Rule ID: a0647a60-16f9-4175-b344-5cdd2934413f
Cognni Incidents for Low Sensitivity Business Information
Rule ID: 77171efa-4502-4ab7-9d23-d12305ff5a5e
Cognni Incidents for Low Sensitivity Financial Information
Rule ID: d2e40c79-fe8c-428e-8cb9-0e2282d4558c
Cognni Incidents for Low Sensitivity Governance Information
Rule ID: ef8654b1-b2cf-4f6c-ae5c-eca635a764e8
Cognni Incidents for Low Sensitivity HR Information
Rule ID: 8374ec0f-d857-4c17-b1e7-93d11800f8fb
Cognni Incidents for Low Sensitivity Legal Information
Rule ID: 2c286288-3756-4824-b599-d3c499836c11
Cognni Incidents for Medium Sensitivity Business Information
Rule ID: d29b1d66-d4d9-4be2-b607-63278fc4fe6b
Cognni Incidents for Medium Sensitivity Financial Information
Rule ID: c1d4a005-e220-4d06-9e53-7326a22b8fe4
Cognni Incidents for Medium Sensitivity Governance Information
Rule ID: 75ff4f7d-0564-4a55-8b25-a75be951cde3
Cognni Incidents for Medium Sensitivity HR Information
Rule ID: db750607-d48f-4aef-b238-085f4a9882f1
Cognni Incidents for Medium Sensitivity Legal Information
Rule ID: 02f6c2e5-219d-4426-a0bf-ad67abc63d53
COM Event System Loading New DLL
Rule ID: ed8c9153-6f7a-4602-97b4-48c336b299e1
COM Registry Key Modified to Point to File in Color Profile Folder
Rule ID: 4465ebde-b381-45f7-ad08-7d818070a11c
Common Event Format CEF via AMA - Critical or High Severity Detections by User
Rule ID: f7d298b2-726c-42a5-bbac-0d7f9950f527
Common Event Format CEF via AMA - Critical Severity Detection
Rule ID: 317e757e-c320-448e-8837-fc61a70fe609
Commvault Cloud Alert
Rule ID: 1aaff41f-4e18-45b1-bb34-de6eb4943cf2
Component Object Model Hijacking - Vault7 trick
Rule ID: 0990a481-3bc8-4682-838c-313918dd858c
Conditional Access - A Conditional Access app exclusion has changed
Rule ID: e3368079-a2c0-4f1c-9fb7-287e907393ef
Conditional Access - A Conditional Access Device platforms condition has changed the Device platforms condition can be spoofed
Rule ID: 2e96fa64-ac4d-4c92-b79e-e9c54b5d8230
Conditional Access - A Conditional Access policy was deleted
Rule ID: 40702da1-ae8a-4e46-ac1f-9327ca6ef588
Conditional Access - A Conditional Access policy was disabled
Rule ID: 5588de32-73b1-40b9-bddc-4d9e74051859
Conditional Access - A Conditional Access policy was put into report-only mode
Rule ID: ccca6b88-a7b6-41c9-9be2-fc3daeb65b26
Conditional Access - A Conditional Access policy was updated
Rule ID: 2ce7f00d-3b3c-41b9-ae9a-b79c19d2394e
Conditional Access - A Conditional Access usergrouprole exclusion has changed
Rule ID: 0459a1b5-909d-4783-9e27-24536b05a47f
Conditional Access - A new Conditional Access policy was created
Rule ID: c385944b-17b9-4b2b-921e-0e8d0341a675
Conditional Access - Dynamic Group Exclusion Changes
Rule ID: 25a7f951-54b7-4cf5-9862-ebc04306c590
Conditional Access Policy Modified by New User
Rule ID: 259ef474-836d-4662-86ef-70cb7a38e765
Configuration Backup Failed
Rule ID: 18833d01-703a-438d-8ac6-84faa82e9b52
Configuration Backup Job Failed
Rule ID: 90039769-0c32-442b-bb12-5b61224a77a0
Configuration Backup Job Settings Updated
Rule ID: 8777f9e1-db58-4078-a381-4e47a3a2ee01
Connection to Backup Repository Lost
Rule ID: c5e9a1d7-4b2f-4e6c-8a9d-7f3b1c5e2a84
ContraForce - Destructive workspace action
Rule ID: 8a2c6e94-1b5d-4f7a-b3e8-2c9d4f6a1e52
ContraForce - Machine credential activity
Rule ID: 3f4bd2a1-7c58-4a83-9c2e-6d1f0a8b5c31
ContraForce - Privileged access change
Rule ID: 1aac7737-d52f-483d-b225-6a27c1b29a9e
Contrast ADR - DLP SQL Injection Correlation
Rule ID: c1c6ba64-134e-403b-b9a6-1bebc90809a4
Contrast ADR - EDR Alert Correlation
Rule ID: ae4f67a6-0713-4a26-ae61-284e67b408c1
Contrast ADR - Exploited Attack Event
Rule ID: 31417149-f3a2-4db4-9e5f-85e0a464f6a1
Contrast ADR - Exploited Attack in Production
Rule ID: 7ce5956f-48f2-42f5-8e2e-c254e7643c11
Contrast ADR - Security Incident Alert
Rule ID: 93641436-afb3-4921-8828-ceab0d15aaab
Contrast ADR - WAF Alert Correlation
Rule ID: 4396f8c3-d114-4154-9f4c-048ba522ed04
Contrast Blocks
Rule ID: e1abb6ed-be18-40fd-be58-3d3d84041daf
Contrast Exploits
Rule ID: 297596de-d9ae-4fb8-b6ff-00fc01c9462d
Contrast Probes
Rule ID: f713404e-805c-4e0c-91fa-2c149f76a07d
Contrast Suspicious
Rule ID: c3d4e5f6-a7b8-49c0-d1e2-f3a4b5c6d7e8
Copilot - File Uploads Disabled
Rule ID: e5f6a7b8-c9d0-41e2-f3a4-b5c6d7e8f9a0
Copilot - Jailbreak Attempt Detected
Rule ID: a1b2c3d4-e5f6-47a8-b9c0-d1e2f3a4b5c6
Copilot - Plugin Created by Non-Admin User
Rule ID: d4e5f6a7-b8c9-40d1-e2f3-a4b5c6d7e8f9
Copilot - Plugin Tampering Enable and Disable Within 5 Minutes
Rule ID: 8eaa2268-74ee-492c-b869-450eff707fef
Corelight - C2 DGA Detected Via Repetitive Failures
Rule ID: 05850746-9ae4-412f-838b-844f0903f4a9
Corelight - External Proxy Detected
Rule ID: 73f23aa2-5cc4-4507-940b-75c9092e9e01
Corelight - Forced External Outbound SMB
Rule ID: 4e55e306-3022-43a1-870a-41c4d5116079
Corelight - Multiple Compressed Files Transferred over HTTP
Rule ID: 7226d37b-50ee-4e3b-9f80-5b74080d8f2c
Corelight - Multiple files sent over HTTP with abnormal requests
Rule ID: 599570d4-06f8-4939-8e29-95cd003f1abd
Corelight - Network Service Scanning Multiple IP Addresses
Rule ID: 6b579e98-abc9-4e7a-9efc-2f3408ba16c9
Corelight - Possible Typo Squatting or Punycode Phishing HTTP Request
Rule ID: f3245aa1-1ca1-471c-a0b7-97ea6b791d5d
Corelight - Possible Webshell
Rule ID: db662e49-6e34-4d10-9d3c-5d04b5479658
Corelight - Possible Webshell Rare PUT or POST
Rule ID: 50c61708-9824-46f3-87cf-22490796fae2
Corelight - SMTP Email containing NON Ascii Characters within the Subject
Rule ID: a3df4a32-4805-4c6d-8699-f3c888af2f67
Correlate Unfamiliar sign-in properties atypical travel alerts
Rule ID: 06263265-ff65-43ff-8b15-6ac82325a672
Cortex XDR Incident - High
Rule ID: f96728eb-9802-4522-b715-47fb66c2ecf5
Cortex XDR Incident - High
Rule ID: 0d3fbeba-f9c9-40c7-9b71-8afb1816d7b2
Cortex XDR Incident - Low
Rule ID: 1426bbcf-a9ae-4aa5-9da6-abbf48f04115
Cortex XDR Incident - Low
Rule ID: 2b05823b-ee15-4b92-a642-b13170e37c35
Cortex XDR Incident - Medium
Rule ID: 2e638f3d-611f-4281-81b1-1fd4aa240ffb
Cortex XDR Incident - Medium
Rule ID: 0febd8cc-1b8d-45ed-87b3-e1e8a57d14cd
Create Incident for XDR Alerts
Rule ID: 3cf46cb9-99d5-42ee-a43c-7bd88ea394a1
Create Incidents from IronDefense
Rule ID: 9736e5f1-7b6e-4bfb-a708-e53ff1d182c3
Creation of expensive computes in Azure
Rule ID: 707494a5-8e44-486b-90f8-155d1797a8eb
Credential added after admin consented to Application
Rule ID: 32ffb19e-8ed8-40ed-87a0-1adb4746b7c4
Credential Dumping Tools - File Artifacts
Rule ID: 4ebbb5c2-8802-11ec-a8a3-0242ac120002
Credential Dumping Tools - Service Installation
Rule ID: daa32afa-b5b6-427d-93e9-e32f3f359dd7
Credential errors stateful anomaly on database
Rule ID: 1edb50b5-fee1-4826-86f9-abaf0e4ce5a5
Credential Record Deleted
Rule ID: 860e201a-deea-4129-8646-fcf8bdd976b0
Credential Record Updated
Rule ID: eda260eb-f4a1-4379-ad98-452604da9b3e
CreepyDrive request URL sequence
Rule ID: b6d03b88-4d27-49a2-9c1c-29f1ad2842dc
CreepyDrive URLs
Rule ID: 88c4b680-db1c-46b9-8ca4-4165c3abf63f
Critical Finding Overdue on Internet-Facing App
Rule ID: 1eebfaf3-40e1-4bc2-9f42-049b7b8ceb60
Critical Risks
Rule ID: 4f1c9e6e-8b6b-4d2a-9f3e-123456789abc
Critical Severity Incident
Rule ID: 2ca4e7fc-c61a-49e5-9736-5da8035c47e0
Critical Threat Detected
Rule ID: 1f40ed57-f54b-462f-906a-ac3a89cc90d4
Cross-Cloud Password Spray detection
Rule ID: 5c847e47-0a07-4c01-ab99-5817ad6cb11e
Cross-Cloud Suspicious Compute resource creation in GCP
Rule ID: 58e306fe-1c49-4b8f-9b0e-15f25e8f0cd7
Cross-Cloud Suspicious user activity observed in GCP Envourment
Rule ID: 122fbc6a-57ab-4aa7-b9a9-51ac4970cac1
Cross-Cloud Unauthorized Credential Access Detection From AWS RDS Login
Rule ID: 4555b590-1983-4b09-8aca-ecbf5d885019
Cross-tenant Access Settings Organization Added
Rule ID: 757e6a79-6d23-4ae6-9845-4dac170656b5
Cross-tenant Access Settings Organization Added
Rule ID: c2da132e-6c27-4f50-9e40-f684ca94e5b2
Cross-tenant Access Settings Organization Deleted
Rule ID: eb8a9c1c-f532-4630-817c-1ecd8a60ed80
Cross-tenant Access Settings Organization Deleted
Rule ID: c895c5b9-0fc6-40ce-9830-e8818862f2d5
Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed
Rule ID: d1b60e24-4f06-4bed-af66-275e13fe7182
Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed
Rule ID: 276d5190-38de-4eb2-9933-b3b72f4a5737
Cross-tenant Access Settings Organization Inbound Direct Settings Changed
Rule ID: 637697be-2fc5-4c57-a7b0-ac79d181a7ab
Cross-tenant Access Settings Organization Inbound Direct Settings Changed
Rule ID: 229f71ba-d83b-42a5-b83b-11a641049ed1
Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed
Rule ID: 7d44c4a7-f4a4-4f48-bd37-be333951a131
Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed
Rule ID: 0101e08d-99cd-4a97-a9e0-27649c4369ad
Cross-tenant Access Settings Organization Outbound Direct Settings Changed
Rule ID: d6de1625-8d18-44da-9991-fbdc607b7643
Cross-tenant Access Settings Organization Outbound Direct Settings Changed
Rule ID: 65bc5f1d-d29d-4729-a5a6-d9614b0900e0
CTE - Admin Login Detected
Rule ID: 1747715b-1a94-411a-a2b5-d8c40422767c
CTE - Blocked URL Attempted
Rule ID: 59246163-4cc0-4e96-a0f0-f098a83cf425
CTE - Compromised Device Suspected High-Volume IOC Blocks
Rule ID: 49da5494-b6b9-42c0-9b9b-b7b219dc8173
CTE - CTI Blocked URL Attempted
Rule ID: 21818920-85eb-4955-a7cc-f62c731f32ac
CTE - Device Enrolled but On Hold
Rule ID: 7f4af730-5c89-4f7a-aa7a-933b6e9309b5
CTE - Device License Capacity Critical 99
Rule ID: 5e644219-6067-4849-85df-7458aa575aea
CTE - Device License Capacity High 95
Rule ID: 8fbb095d-3a35-483b-b264-25b858a52f4d
CTE - Device Repeatedly Blocked Across Multiple Days
Rule ID: 0be1ebaf-36f8-49a6-a3b6-56491ccfda7f
CTE - Enrollment Token Generated
Rule ID: c32e5873-00b7-45fc-9a7e-43e9d0018978
CTE - License Expiring Critically 7 Days
Rule ID: ec305a18-2520-443d-9f54-18dea3637a15
CTE - License Expiring Soon 30 Days
Rule ID: ec08477d-87a1-498d-8f34-72b8ec8f3758
CTE - Possible Company-Wide C2 Campaign Multiple Devices Same Destination
Rule ID: e1c0f32d-a57b-42ae-8038-b869bca54fef
CTE - Risky Device Multiple IOC URL Hits
Rule ID: bd06aa7c-8aef-40f3-bf32-a70b5d48f79e
CTE - Rule Capacity Critical 95
Rule ID: b3eb26f4-affb-4a61-8b54-8780d234008e
CTE - Rule Capacity High 90
Rule ID: cf7ad1f5-7325-4bda-83d4-957ec943c457
CTE - Security Rule Changed CreatedUpdatedDeleted
Rule ID: a6d51bc1-bf51-47d1-9885-b81762cd6306
CTE - Stale Device No Heartbeat in 30 Days
Rule ID: fbbf3418-f1d8-4bd5-b7da-137a70af6bce
CTE - Sudden Block Spike Detected
Rule ID: 88341fc3-38e1-46db-8bb1-6c052e749991
CTERA Mass Access Denied Detection Analytic
Rule ID: 5365f294-0c67-432a-bacf-b1282a3b6c46
CTERA Mass Deletions Detection Analytic
Rule ID: 90502ac9-19a2-41f0-ba81-e352de90b61b
CTERA Mass Permissions Changes Detection Analytic
Rule ID: 8e8978a2-9188-4187-8909-5ea00507bf16
CyberArkEPM - Attack attempt not blocked
Rule ID: a11bf869-458e-49fd-be03-58021b14be15
CyberArkEPM - MSBuild usage as LOLBin
Rule ID: c02f96b4-057b-4e63-87af-6376ef7a081b
CyberArkEPM - Multiple attack types
Rule ID: eddfd1fd-71df-4cc3-b050-287643bee398
CyberArkEPM - Possible execution of Powershell Empire
Rule ID: 0d4e62da-0a64-4532-b93e-28cd2940c300
CyberArkEPM - Process started from different locations
Rule ID: 9281b7cc-8f05-45a9-bf10-17fb29492a84
CyberArkEPM - Renamed Windows binary
Rule ID: 9d0d44ab-54dc-472a-9931-53521e888932
CyberArkEPM - Uncommon process Internet access
Rule ID: 16b940d2-aaf8-4eaa-a5e1-05df5f5c3d43
CyberArkEPM - Uncommon Windows process started from System folder
Rule ID: 911d5b75-a1ce-4f13-a839-9c2474768696
CyberArkEPM - Unexpected executable extension
Rule ID: c1fcbbd7-74f8-4f32-8116-0a533ebd3878
CyberArkEPM - Unexpected executable location
Rule ID: abe1a662-d00d-482e-aa68-9394622ae02e
CyberBlindSpot - Any Issue Detected
Rule ID: 1932DCFD-A32E-49F9-A212-5BCD084FBD78
Cyble Advisory Alerts Advisory
Rule ID: 0012714c-c595-4dcd-8949-4a5c1d49aaa8
Cyble Vision Alerts Assets
Rule ID: f3c25011-4509-41c8-be27-35d891531c39
Cyble Vision Alerts Bitbucket
Rule ID: db417cee-529c-4eac-b7b9-36eb0166800a
Cyble Vision Alerts Cloud Storage
Rule ID: 33B07EAA-F451-4C38-AC9F-8AF3F7E99F0E
Cyble Vision Alerts Compromised Endpoint Cookies
Rule ID: 0f6a8287-09ee-4f82-b8c3-e35c4ac6212e
Cyble Vision Alerts Compromised Files
Rule ID: 359ddb25-eab1-4ef5-8303-ed3a9b680690
Cyble Vision Alerts Cyble Web Applications
Rule ID: 588a2ee5-978a-43f7-9c10-6d76d82026ef
Cyble Vision Alerts Darkweb Data Breaches
Rule ID: 6deaf986-a25b-47b4-afbe-667901aa313b
Cyble Vision Alerts Darkweb Ransomware Leak
Rule ID: 601a5859-0dc2-452d-8d1e-66dc651c16d5
Cyble Vision Alerts Discord Keyword
Rule ID: 7a0f79cc-8d28-44b5-ac1e-6176565bb7b8
Cyble Vision Alerts Discovered Subdomain
Rule ID: 47dee28d-fa74-49cd-b5fb-397b047a73c0
Cyble Vision Alerts Docker
Rule ID: 81404e99-ce27-45aa-aa19-a276a3d4c645
Cyble Vision Alerts Domain Expiry Alert
Rule ID: 0a54dc90-9a9d-4300-af21-feb5136e81da
Cyble Vision Alerts Domain Watchlist
Rule ID: 2c86652a-bbbe-4a32-8b1c-4b53aad0750e
Cyble Vision Alerts Flash Report
Rule ID: 117e8f7c-8f44-4061-bcc2-b444b98a3838
Cyble Vision Alerts Github
Rule ID: 6649e5a0-0365-452f-84b3-448a0aec7a59
Cyble Vision Alerts Hacktivism
Rule ID: d1cdfb8d-12cd-4a29-8caf-ef4a35ad67ed
Cyble Vision Alerts I2P Monitoring
Rule ID: c8cf42d5-8684-435f-9c4d-9dd0cc47eaec
Cyble Vision Alerts IOCS
Rule ID: 1e7c8d9f-1d42-42b3-b6ce-12a637e05f16
Cyble Vision Alerts IP Risk Score
Rule ID: 224a63ae-e278-4a11-b7c2-02ec3e17b56c
Cyble Vision Alerts Leaked Credentials
Rule ID: cf0a9691-5716-42e0-bfa1-49b35d3a7892
Cyble Vision Alerts Malicious Ads Detected
Rule ID: e52f36dd-7d4f-4aa8-a095-3b6fa2b28b8d
Cyble Vision Alerts New Vulnerability Detected
Rule ID: d205a93f-b2e3-4708-a359-5e0c88ee3e59
Cyble Vision Alerts News Feed Alert
Rule ID: 9ff985d8-57a8-4302-a8e6-34fa96c3c505
Cyble Vision Alerts OSINT Mention Detected
Rule ID: c1ebc79d-7f46-429e-bf2c-8bb0b75ba6b2
Cyble Vision Alerts OTICS Threat Activity Detected
Rule ID: dd37e041-3973-482a-aa8c-f484b4178940
Cyble Vision Alerts Pastebin
Rule ID: eb1d45fe-1b19-4b54-b146-971f282a6fd9
Cyble Vision Alerts Phishing Domain Detected
Rule ID: 88db8505-1889-46aa-a4e2-4e866262dcb9
Cyble Vision Alerts Physical Threat Alert
Rule ID: 99ca8956-5aad-4542-9fbc-8254182b424d
Cyble Vision Alerts Postman API Exposure Detection
Rule ID: c360341e-6ba6-472a-ae00-7be85967e240
Cyble Vision Alerts Product Vulnerability Detected
Rule ID: 231c2c16-3742-4cfb-a8e1-c1a7d09f080a
Cyble Vision Alerts Social Media Monitoring
Rule ID: A667D635-D2A7-47E7-8827-8FB243AF2AFD
Cyble Vision Alerts SSL Certificate Expiry
Rule ID: c56fcb78-b708-4a92-bad4-d50b1e15c42c
Cyble Vision Alerts Suspicious Domain
Rule ID: b9df1ec4-a572-4448-8da1-1bc4b7e1687f
Cyble Vision Alerts TOR Links
Rule ID: 0e0cdda9-4536-4cc9-91cf-736e8957ed26
Cyble Vision Alerts Vulnerability
Rule ID: 91a00e4f-3edb-49e9-ba6f-cec87a5bd2f8
Cyble Vision Alerts Website Defacement Content
Rule ID: 754dbb50-8dc2-4b8b-86d8-a890a020ddc3
Cyble Vision Alerts Website Defacement Keyword
Rule ID: 1dabe566-a0f1-4c27-8307-aea5a79eb5e9
Cyble Vision Alerts Website Defacement URL
Rule ID: b78c4641-cc16-48e0-9d05-c9b36a55d214
CybleVision Alerts Cyber Crime Forum Alerts
Rule ID: e80eedb4-cbae-45cc-b1be-a2a8dc31af3b
CybleVision Alerts Darkweb Marketplace Alerts
Rule ID: 6d55fefc-b334-4b79-b11c-667746b5bdde
CybleVision Alerts Mobile Apps
Rule ID: e0bf55c2-35ef-47ab-8846-5087618ae805
CybleVision Alerts Stealer Logs
Rule ID: 4238f545-8b6f-4f7c-80b5-14cca2cebc99
CybleVision Alerts Telegram Mentions
Rule ID: 87cd8b10-90f6-4967-a4a7-2142e848ec8f
CYFIRMA - Attack Surface - Cloud Weakness High Rule
Rule ID: b8a3c5e2-04d5-4b61-9b62-b4f53a417f74
CYFIRMA - Attack Surface - Cloud Weakness Medium Rule
Rule ID: 30206b45-75d2-4c6a-87c5-f0861c1f2870
CYFIRMA - Attack Surface - Configuration High Rule
Rule ID: e1f88d08-5c32-4d35-a8ce-2f21cdb4b6de
CYFIRMA - Attack Surface - Configuration Medium Rule
Rule ID: fbe4f5e0-d93e-4c93-8cf9-925eb8ea7f2e
CYFIRMA - Attack Surface - DomainIP Vulnerability Exposure High Rule
Rule ID: a2f2c91b-5796-45e4-82c7-61763e6c2c9c
CYFIRMA - Attack Surface - DomainIP Vulnerability Exposure Medium Rule
Rule ID: 7ff6f6d7-9672-4567-99fc-cb8a58c3bce7
CYFIRMA - Attack Surface - Malicious DomainIP Reputation High Rule
Rule ID: 70f137e4-e4ef-4635-92de-10c4f5b0fcd0
CYFIRMA - Attack Surface - Malicious DomainIP Reputation Medium Rule
Rule ID: 87e7eb3f-bb8e-46e5-8807-d3fc63d0f676
CYFIRMA - Attack Surface - Open Ports High Rule
Rule ID: 9e18b6c3-d172-4bc6-a7d9-cc7b0a03a69e
CYFIRMA - Attack Surface - Open Ports Medium Rule
Rule ID: 3b5a1c0e-7f3a-4d47-8416-6c0b8b91e9ce
CYFIRMA - Attack Surface - Weak Certificate Exposure - High Rule
Rule ID: 5a617ff2-3e3d-44e7-b761-9f0d542ae191
CYFIRMA - Attack Surface - Weak Certificate Exposure - Medium Rule
Rule ID: 10bdf525-5b89-4a25-933a-e63e73b915f1
CYFIRMA - Brand Intelligence - Domain Impersonation High Rule
Rule ID: 8f97ddbe-ab66-4f6c-b675-73b5eeb07259
CYFIRMA - Brand Intelligence - Domain Impersonation Medium Rule
Rule ID: 159d26a1-591c-4f70-b1ca-2843c881aaec
CYFIRMA - Brand Intelligence - ExecutivePeople Impersonation High Rule
Rule ID: 59aa22f2-5b4f-4679-b289-003228255413
CYFIRMA - Brand Intelligence - ExecutivePeople Impersonation Medium Rule
Rule ID: 3176ac89-b195-48b7-a01e-740a6b26fb2f
CYFIRMA - Brand Intelligence - Malicious Mobile App High Rule
Rule ID: b73e6628-d44c-4ad3-a801-ea225c5744ee
CYFIRMA - Brand Intelligence - Malicious Mobile App Medium Rule
Rule ID: 3a9a81bc-2f41-4d68-9cd1-7788326c92b1
CYFIRMA - Brand Intelligence - ProductSolution High Rule
Rule ID: 458d964f-d039-4ce0-9741-0b6245ba3374
CYFIRMA - Brand Intelligence - ProductSolution Medium Rule
Rule ID: 22f49d67-7da7-4809-8d07-89e4478aa6b0
CYFIRMA - Brand Intelligence - Social Media Handle Impersonation Detected High Rule
Rule ID: 710f4755-490d-4fa7-aef0-43b5a66edc7b
CYFIRMA - Brand Intelligence - Social Media Handle Impersonation Detected Medium Rule
Rule ID: 72d3fb86-d1eb-44d6-9352-170c6bb45bb7
CYFIRMA - Compromised Employees Detection Rule
Rule ID: ebd1bf8d-aa18-4e66-9cad-555b71a290f1
CYFIRMA - Customer Accounts Leaks Detection Rule
Rule ID: c3f1f55b-7e54-4416-8afc-7d7876b29b0f
CYFIRMA - Data Breach and Web Monitoring - Dark Web High Rule
Rule ID: c0afeda7-4832-49a6-8d03-a5d137d513b5
CYFIRMA - Data Breach and Web Monitoring - Dark Web Medium Rule
Rule ID: 00c7b41c-ddeb-4c49-acd7-2f7897e27fb4
CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule
Rule ID: 17cce4fc-9b4c-4eef-a4c7-083b44545e6e
CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule
Rule ID: d5f9a6fe-7fd2-488c-8690-0ca24fba43dc
CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule
Rule ID: ed1aabc1-e1c1-42f4-abac-fd5637730f13
CYFIRMA - Data Breach and Web Monitoring - Ransomware Exposure Detected Rule
Rule ID: 123fad02-6d9e-439e-8241-7a2fffa7e0a5
CYFIRMA - High Severity Asset based Vulnerabilities Rule Alert
Rule ID: 6cc62c46-dd44-46d7-8681-8422f780eabd
CYFIRMA - High Severity Attack Surface based Vulnerabilities Rule Alert
Rule ID: 6b61b716-afd9-4f6c-ad00-965d5987cafd
CYFIRMA - High severity Command Control Network Indicators with Block Recommendation Rule
Rule ID: 6d8fb3fe-2501-4103-8137-34261fa3a596
CYFIRMA - High severity Command Control Network Indicators with Monitor Recommendation Rule
Rule ID: 990fc0dc-e7a5-4f6d-bc24-8569652cd773
CYFIRMA - High severity File Hash Indicators with Block Action and Malware
Rule ID: 7cb829b2-915a-42c2-adb9-725e9ce9bf43
CYFIRMA - High severity File Hash Indicators with Block Action Rule
Rule ID: c919c911-8b01-44f8-9c3b-60b1edfc417f
CYFIRMA - High severity File Hash Indicators with Monitor Action and Malware
Rule ID: 952b7d77-a848-4888-a638-62fe877eb55d
CYFIRMA - High severity File Hash Indicators with Monitor Action Rule
Rule ID: c7c02bbf-b775-4e85-a3c7-7f8a9318fd2f
CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
Rule ID: c7b0b6da-e9dc-405d-ad71-37661f56d40a
CYFIRMA - High severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
Rule ID: 58ae2c87-fc07-434b-aacf-f66d25b25e7e
CYFIRMA - High severity Malicious Network Indicators with Block Action Rule
Rule ID: 8317de44-09e4-4a04-8fae-c38c1b72064b
CYFIRMA - High severity Malicious Network Indicators with Monitor Action Rule
Rule ID: 6f053867-dbd8-4755-924d-577e3db7f5a6
CYFIRMA - High severity Malicious Phishing Network Indicators - Block Recommended Rule
Rule ID: 359e2afb-b6d4-45db-90aa-c89ce7234d72
CYFIRMA - High severity Malicious Phishing Network Indicators - Monitor Recommended Rule
Rule ID: fa53ac37-a646-4106-91b6-ce478a1b5323
CYFIRMA - High severity TOR Node Network Indicators - Block Recommended Rule
Rule ID: 6f107cf8-02f9-4440-b5d8-1235293e5ad7
CYFIRMA - High severity TOR Node Network Indicators - Monitor Recommended Rule
Rule ID: 649f525a-1f92-412d-bfc2-ce642e7a7f1f
CYFIRMA - High severity Trojan File Hash Indicators with Block Action Rule
Rule ID: 4afd8960-8bee-4cac-bb5e-a4f200b1f9f3
CYFIRMA - High severity Trojan File Hash Indicators with Monitor Action Rule
Rule ID: 441204ca-274f-43d2-aeda-53409b94f447
CYFIRMA - High severity Trojan Network Indicators - Block Recommended Rule
Rule ID: 89fd02b8-3c21-492c-a8de-b3e728d39119
CYFIRMA - High severity Trojan Network Indicators - Monitor Recommended Rule
Rule ID: 6306f2d9-34a3-409a-850d-175b7bdd1ab1
CYFIRMA - Medium Severity Asset based Vulnerabilities Rule Alert
Rule ID: 4c1b282b-62f1-4783-bf40-94c44f0ae630
CYFIRMA - Medium Severity Attack Surface based Vulnerabilities Rule
Rule ID: b278be0f-0662-47b4-9ab5-71a0f1435c3f
CYFIRMA - Medium severity Command Control Network Indicators with Block Recommendation Rule
Rule ID: 75931755-27cd-4e4b-a51c-efcca452e2ff
CYFIRMA - Medium severity Command Control Network Indicators with Monitor Recommendation Rule
Rule ID: 24dcff02-123c-4e10-a531-2a22a609120a
CYFIRMA - Medium severity File Hash Indicators with Block Action and Malware
Rule ID: cd06dae8-7b79-436b-b1a6-9d256830f9dd
CYFIRMA - Medium severity File Hash Indicators with Block Action Rule
Rule ID: ca16daff-28dd-499d-93fe-0bb232d76d4f
CYFIRMA - Medium severity File Hash Indicators with Monitor Action and Malware
Rule ID: 5347c581-eb36-4bf5-a7e5-be1fb2d617f5
CYFIRMA - Medium severity File Hash Indicators with Monitor Action Rule
Rule ID: 77226d6e-1263-42b1-a40d-8a756407ad4c
CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Block Recommended Rule
Rule ID: ee2325cc-f5ba-49ac-b4d9-58ef0766e168
CYFIRMA - Medium severity Malicious Network Indicators Associated with Malware - Monitor Recommended Rule
Rule ID: 4e7d1851-5aab-478d-b348-4b83dc2b03d9
CYFIRMA - Medium severity Malicious Network Indicators with Block Action Rule
Rule ID: 52c2f8d4-1dc8-4141-9152-614c036390a0
CYFIRMA - Medium severity Malicious Network Indicators with Monitor Action Rule
Rule ID: 5468e012-6681-44fb-be2d-b1cd58b62ac7
CYFIRMA - Medium severity Malicious Phishing Network Indicators - Block Recommended Rule
Rule ID: 1b9603dd-4787-403e-8a35-387c554bd15b
CYFIRMA - Medium severity Malicious Phishing Network Indicators - Monitor Recommended Rule
Rule ID: aba36dc3-af43-4ab6-9349-3d1e37f1d4f3
CYFIRMA - Medium severity TOR Node Network Indicators - Block Recommended Rule
Rule ID: e41b7640-9ba6-42d6-a4c9-1ab6932a0b14
CYFIRMA - Medium severity TOR Node Network Indicators - Monitor Recommended Rule
Rule ID: 25686f44-5f5f-4388-95e2-eea244481438
CYFIRMA - Medium severity Trojan File Hash Indicators with Block Action Rule
Rule ID: b89c893e-650f-4569-afc3-c487efee2472
CYFIRMA - Medium severity Trojan File Hash Indicators with Monitor Action Rule
Rule ID: baa63d52-285d-43bf-a34e-8ed2fa260f9e
CYFIRMA - Medium severity Trojan Network Indicators - Block Recommended Rule
Rule ID: 104f4574-fc95-4f38-8aa2-02f0b78eba9b
CYFIRMA - Medium severity Trojan Network Indicators - Monitor Recommended Rule
Rule ID: 57602938-e95a-4fc3-9352-8d473ed256e1
CYFIRMA - Public Accounts Leaks Detection Rule
Rule ID: 4fe04459-13f1-4ff7-9b7c-f9be0c2aad6d
CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule
Rule ID: b8149f2f-54da-4f7b-98e1-c01ca47e1e55
CYFIRMA - Social and Public Exposure - Social Media Threats Activity Detected Rule
Rule ID: 67e9c4aa-a2fa-4e4e-9272-1a8da41475c6
CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule
Rule ID: a2984be5-8d69-4139-b98f-e89c9c421c27
CYFIRMA - Social and Public Exposure - Confidential Files Information Exposure Rule
Rule ID: 52d71822-41e4-4c21-b36f-400294f2b43a
CYFIRMA - Social and Public Exposure - Exposure of PIICII in Public Domain Rule
Rule ID: b484f224-687f-4406-af8a-ff019f9f2c24
CYFIRMA - Social and Public Exposure - Exposure of PIICII in Public Domain Rule
Rule ID: 28e315a3-725d-4261-a6c2-e597d51541f4
CYFIRMA - Social and Public Exposure - Source Code Exposure on Public Repositories Rule
Rule ID: 42e6f16a-7773-44cc-8668-8f648bd1aa4f
CYFIRMA - Social and Public Exposure - Source Code Exposure on Public Repositories Rule
Rule ID: 3d853a88-92d2-4aec-a680-2bf7bb560c56
Cynerio - Exploitation Attempt of IoT device
Rule ID: 84e0ea1f-766d-4775-836a-c0c9cca05085
Cynerio - IoT - Default password
Rule ID: 65db1346-6435-4079-bbf4-9a7113c98054
Cynerio - IoT - Weak password
Rule ID: 211e9f49-3fca-4598-bc6e-e2c28d86e72c
Cynerio - Medical device scanning
Rule ID: c0756978-baa6-4239-9174-bac1b1ca1a6a
Cynerio - Suspicious Connection to External Address
Rule ID: 7f9a0d5c-3b4c-6d7e-1f2a-e3f4a5b6c7d8
Cyren Feed Outage Detection
Rule ID: 5d7e8b3a-1f2c-4e5d-9a0b-c1d2e3f4a5b6
Cyren High-Risk IP Indicators
Rule ID: 6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7
Cyren High-Risk URL Indicators
Rule ID: 48ef0be4-8240-4a03-bbb9-320b562d6ce4
D3 Smart SOAR - High or critical severity incident detected
Rule ID: ffa2977f-3077-4bba-b1bf-f3417699cbb0
Darktrace AI Analyst Legacy
Rule ID: 05de0eaf-01bc-4615-99fc-2ec769864b34
Darktrace Incident Event
Rule ID: 9392a06f-63a4-4a5d-8ca3-647064b13c28
Darktrace Model Alert
Rule ID: a3c7b8ed-56a9-47b7-98e5-2555c16e17c9
Darktrace Model Breach Legacy
Rule ID: 2e629769-60eb-4a14-8bfc-bde9be66ebeb
Darktrace System Status Legacy
Rule ID: 64a46029-3236-4d03-b5df-207366a623f1
Dataminr - urgent alerts detected
Rule ID: 0820da12-e895-417f-9175-7c256fcfb33e
Dataverse - Anomalous application user activity
Rule ID: f1634822-b7e9-44f5-95ac-fa4a04f14513
Dataverse - Audit log data deletion
Rule ID: ea07523b-e6b8-469b-9e25-cdef1ae6fb45
Dataverse - Audit logging disabled
Rule ID: 6e480329-84bc-409a-b97b-22e8102af3ca
Dataverse - Bulk record ownership re-assignment or sharing
Rule ID: ba5e608f-7879-4927-8b0d-a9948b4fe6f3
Dataverse - Executable uploaded to SharePoint document management site
Rule ID: 0881b209-62c9-4b15-9f9a-e0c1d1b1eb7b
Dataverse - Export activity from terminated or notified employee
Rule ID: 39efbf4b-b347-4cc7-895e-99a868bf29ea
Dataverse - Guest user exfiltration following Power Platform defense impairment
Rule ID: 2df0adf5-92a8-4ee0-a123-3eb5be1eed02
Dataverse - Hierarchy security manipulation
Rule ID: 11650b85-d8cc-49c4-8c04-a8a739635983
Dataverse - Honeypot instance activity
Rule ID: f327816b-9328-4b17-9290-a02adc2f4928
Dataverse - Login by a sensitive privileged user
Rule ID: 666fef96-1bb8-4abf-ad72-e5cb49561381
Dataverse - Login from IP in the block list
Rule ID: 81c693fe-f6c4-4352-bc10-3526f6e22637
Dataverse - Login from IP not in the allow list
Rule ID: 2e3878bb-d519-43aa-9992-ea069df099e4
Dataverse - Malware found in SharePoint document management site
Rule ID: 716cf6d4-97ad-407b-923e-6790083acb58
Dataverse - Mass deletion of records
Rule ID: 95e02f1b-5886-4043-8f0e-a42e6e23330f
Dataverse - Mass download from SharePoint document management
Rule ID: 57000f0d-ff5d-4166-94b6-aa5fb62b16ec
Dataverse - Mass export of records to Excel
Rule ID: df577f0f-1d8a-4420-9057-a07f0edb15c8
Dataverse - Mass record updates
Rule ID: 5c768e7d-7e5e-4d57-80d4-3f50c96fbf70
Dataverse - New Dataverse application user activity type
Rule ID: 682e230c-e5da-4085-8666-701d1f1be7de
Dataverse - New non-interactive identity granted access
Rule ID: 4c1c9aee-8e44-4bb9-bd53-f3e7d6761282
Dataverse - New sign-in from an unauthorized domain
Rule ID: 34a5d79b-8f9a-420c-aa64-7f4d262ac29a
Dataverse - New user agent type that was not used before
Rule ID: 094b3c0a-1f63-42f7-9535-c8c7b7198328
Dataverse - New user agent type that was not used with Office 365
Rule ID: a6f6b734-3db8-4259-a988-69e0b8eac0c2
Dataverse - Organization settings modified
Rule ID: 1b1061be-2595-4492-af6d-1c8a5fc9576d
Dataverse - Removal of blocked file extensions
Rule ID: c4c3510a-0ee0-4561-9835-47882ffa7f46
Dataverse - SharePoint document management site added or updated
Rule ID: e44a58b2-b63a-4eb9-92da-85660d73495c
Dataverse - Suspicious security role modifications
Rule ID: d875af10-6bb9-4d6a-a6e4-78439a98bf4b
Dataverse - Suspicious use of TDS endpoint
Rule ID: 8a6ecba2-ccfe-4c8c-b086-fa3e6ff7fa86
Dataverse - Suspicious use of Web API
Rule ID: de039242-47e0-43fa-84d7-b6be24305349
Dataverse - Terminated employee exfiltration over email
Rule ID: c5e75cb6-cea0-49c2-a998-da414035aac1
Dataverse - Terminated employee exfiltration to USB drive
Rule ID: 56d5aa0c-d871-4167-ba13-61c2f0fd17bf
Dataverse - TI map IP to DataverseActivity
Rule ID: d88a0e22-3b6a-40c2-af28-c064b44d03b7
Dataverse - TI map URL to DataverseActivity
Rule ID: d7c9549c-7246-4555-8e53-d7b0db546764
Dataverse - Unusual sign-in following disabled IP address-based cookie binding protection
Rule ID: 08cb7ffc-59c6-4e7d-88e0-327371c9431b
Dataverse - User bulk retrieval outside normal activity
Rule ID: ddee1398-cf0b-46af-b583-78c3c29156dc
Datawiza - massive errors detected
Rule ID: 8f3c1a4e-6b52-4d19-9c07-2a5e8d0f7b41
Datazag - impersonation domain resolved in DNS
Rule ID: 2d7b90c5-41ae-4f83-a6d2-9b1c5e3407fa
Datazag - retro-hunt historical DNS against impersonation indicators
Rule ID: d58035ff-0bac-4c61-a7f4-f58939ff9764
DCOM Lateral Movement
Rule ID: c3ffdbe6-2e62-4984-9e80-933ed90b2f6a
DDoS attack detected
Rule ID: 402a42ad-f31c-48d1-8f80-0200846b7f25
DDoS Attack IP Addresses - Percent Threshold
Rule ID: 6e76fd9d-8104-41eb-bad3-26054a3ad5f0
DDoS Attack IP Addresses - PPS Threshold
Rule ID: a4dbc292-87eb-11ec-a8a3-0242ac120002
Decoy User Account Authentication Attempt
Rule ID: 8138863e-e55f-4f02-ac94-72796e203d27
Defender Alert Evidence
Rule ID: c25a8cd4-5b4a-45a8-9ba0-3b753a652f6b
Deimos Component Execution
Rule ID: a1b2c3d4-e5f6-4078-9012-3456789abcde
Deleted a Custom Field Mapping profile
Rule ID: 7d4a2b91-8e5c-4f2a-9d6b-3c1f0e4a5d8b
Deleted a Tenant
Rule ID: 03caa992-477f-4b19-8e2a-8cd58f8f9652
Deletion of data on multiple drives using cipher exe
Rule ID: e068187a-01f5-4737-bc13-25db4027b7ea
Denial of Service Microsoft Defender for IoT
Rule ID: e0d937ca-4582-4c3b-b95b-82fff33ed610
Detaching Backups Started
Rule ID: 077eb06a-c011-47f7-8d92-dfc2b1e1d71b
Detect AWS IAM Users
Rule ID: 011c84d8-85f0-4370-b864-24c13455aa94
Detect CoreBackUp Deletion Activity from related Security Alerts
Rule ID: cf687598-5a2c-46f8-81c8-06b15ed489b1
Detect DNS queries reporting multiple errors from different clients - Anomaly Based ASIM DNS Solution
Rule ID: 5b8344eb-fa28-4ac3-bcff-bc19d5d63089
Detect DNS queries reporting multiple errors from different clients - Static threshold based ASIM DNS Solution
Rule ID: 02f23312-1a33-4390-8b80-f7cd4df4dea0
Detect excessive NXDOMAIN DNS queries - Anomaly based ASIM DNS Solution
Rule ID: 4ab8b09e-3c23-4974-afbe-7e653779eb2b
Detect excessive NXDOMAIN DNS queries - Static threshold based ASIM DNS Solution
Rule ID: faa40333-1e8b-40cc-a003-51ae41fa886f
Detect instances of multiple client errors occurring within a brief period of time ASIM Web Session
Rule ID: a59ba76c-0205-4966-948e-3d5640140688
Detect instances of multiple server errors occurring within a brief period of time ASIM Web Session
Rule ID: 6a4dbcf8-f5e2-4b33-b34f-2db6487613f0
Detect known risky user agents ASIM Web Session
Rule ID: 7bb55d05-ef39-4a40-8079-0bc3c05e7881
Detect Local File InclusionLFI in web requests ASIM Web Session
Rule ID: 259de2c1-c546-4c6d-a17c-df639722f4d7
Detect Malicious Usage of Recovery Tools to Delete Backup Files
Rule ID: 9f921513-65f3-48a2-ae7d-326c5901c55e
Detect NET runtime being loaded in JScript for code execution
Rule ID: 1f3b4dfd-21ff-4ed3-8e27-afc219e05c50
Detect PIM Alert Disabling activity
Rule ID: cbf07406-fa2a-48b0-82b8-efad58db14ec
Detect port misuse by anomaly based detection ASIM Network Session schema
Rule ID: 156997bd-da0f-4729-b47a-0a3e02dd50c8
Detect port misuse by static threshold ASIM Network Session schema
Rule ID: b3731ce1-1f04-47c4-95c2-9827408c4375
Detect potential file enumeration activity ASIM Web Session
Rule ID: 12134de5-361b-427c-a1a0-d43f40a593c4
Detect Potential Kerberoast Activities
Rule ID: 6a71687f-00cf-44d3-93fc-8cbacc7b5615
Detect potential presence of a malicious file with a double extension ASIM Web Session
Rule ID: e3a7722a-e099-45a9-9afb-6618e8f05405
Detect presence of private IP addresses in URLs ASIM Web Session
Rule ID: 2d50d937-d7f2-4c05-b151-9af7f9ec747e
Detect presence of uncommon user agents in web requests ASIM Web Session
Rule ID: 7edde3d4-9859-4a00-b93c-b19ddda55320
Detect Print Processors Registry Driver Key CreationModification
Rule ID: dd041e4e-1ee2-41ec-ba4e-82a71d628260
Detect Registry Run Key CreationModification
Rule ID: c99cf650-c53b-4c4c-9671-7d7500191a10
Detect requests for an uncommon resources on the web ASIM Web Session
Rule ID: fa2f7d8a-6726-465a-aa72-6f6e3d4c99d7
Detect Suspicious Commands Initiated by Webserver Processes
Rule ID: 7d2ed1c7-da26-45fd-b4ea-b6f2bbeccea7
Detect threat information in web requests ASIM Web Session
Rule ID: 5965d3e7-8ed0-477c-9b42-e75d9237fab0
Detect unauthorized data transfers using timeseries anomaly ASIM Web Session
Rule ID: 32c08696-2e37-4730-86f8-97d9c8b184c9
Detect URLs containing known malicious keywords or commands ASIM Web Session
Rule ID: c6608467-3678-45fe-b038-b590ce6d00fb
Detect web requests to potentially harmful files ASIM Web Session
Rule ID: 056593d4-ca3b-47a7-be9d-d1d0884a1d36
Detect Windows Allow Firewall Rule AdditionModification
Rule ID: f1443a87-78d5-40c3-b051-f468f0f2def0
Detect Windows Update Disabled from Registry
Rule ID: 1399664f-9434-497c-9cde-42e4d74ae20e
Detecting Impossible travel with mailbox permission tampering Privilege Escalation attempt
Rule ID: e7470b35-0128-4508-bfc9-e01cfb3c2eb7
Detecting Macro Invoking ShellBrowserWindow COM Objects
Rule ID: 829a69ba-93e1-491f-8a1f-b19506e9d88a
Detecting UAC bypass - ChangePK and SLUI registry tampering
Rule ID: 2d5efc71-2e91-4ca2-8506-857eecb453ec
Detecting UAC bypass - elevated COM interface
Rule ID: 8b8fbf9c-35d4-474b-8151-a40173521293
Detecting UAC bypass - modify Windows Store settings
Rule ID: 3b443f22-9be9-4c35-ac70-a94757748439
Dev-0228 File Path Hashes November 2021
Rule ID: 29a29e5d-354e-4f5e-8321-8b39d25047bf
Dev-0228 File Path Hashes November 2021 ASIM Version
Rule ID: 422ca2bf-598b-4872-82bb-5f7e8fa731e7
Dev-0270 Malicious Powershell usage
Rule ID: 7965f0be-c039-4d18-8ee8-9a6add8aecf3
DEV-0270 New User Creation
Rule ID: 2566e99f-ad0f-472a-b9ac-d3899c9283e6
Dev-0270 Registry IOC - September 2022
Rule ID: 6b652b4f-9810-4eec-9027-7aa88ce4db23
Dev-0270 WMIC Discovery
Rule ID: d82eb796-d1eb-43c8-a813-325ce3417cef
Dev-0530 File Extension Rename
Rule ID: 5c8e1f2e-9d6b-4f4a-8f3e-123456789abc
Device Alert Surge
Rule ID: e36c6bd6-f86a-4282-93a5-b4a1b48dd849
Device Registration from Malicious IP
Rule ID: 5f75a873-b524-4ba5-a3b8-2c20db517148
Digital Guardian - Bulk exfiltration to external domain
Rule ID: a19885c8-1e44-47e3-81df-d1d109f5c92d
Digital Guardian - Exfiltration to external domain
Rule ID: f7b6ddef-c1e9-46f0-8539-dbba7fb8a5b8
Digital Guardian - Exfiltration to online fileshare
Rule ID: edead9b5-243a-466b-ae78-2dae32ab1117
Digital Guardian - Exfiltration to private email
Rule ID: 39e25deb-49bb-4cdb-89c1-c466d596e2bd
Digital Guardian - Exfiltration using DNS protocol
Rule ID: 07bca129-e7d6-4421-b489-32abade0b6a7
Digital Guardian - Incident with not blocked action
Rule ID: e8901dac-2549-4948-b793-5197a5ed697a
Digital Guardian - Multiple incidents from user
Rule ID: a374a933-f6c4-4200-8682-70402a9054dd
Digital Guardian - Possible SMTP protocol abuse
Rule ID: b52cda18-c1af-40e5-91f3-1fcbf9fa267e
Digital Guardian - Sensitive data transfer over insecure channel
Rule ID: a14f2f95-bbd2-4036-ad59-e3aff132b296
Digital Guardian - Unexpected protocol
Rule ID: f7abe9c1-1e6c-4317-b907-25769e7764c5
Digital Shadows Incident Creation for exclude-app
Rule ID: ede3071d-9317-45f9-b36c-6a6effee5294
Digital Shadows Incident Creation for include-app
Rule ID: 20d52a04-b5d8-402d-88e2-7929d12cbdcd
Disable or Modify Windows Defender
Rule ID: 32b29155-3fd3-4a9e-a0ca-a67e2593b60b
Disabling Security Services via Registry
Rule ID: 010bd98c-a6be-498c-bdcd-502308c0fdae
Discord CDN Risky File Download
Rule ID: 01e8ffff-dc0c-43fe-aa22-d459c4204553
Discord CDN Risky File Download ASIM Web Session Schema
Rule ID: 8c484ef9-d758-4827-9920-f4f77158f03e
Disks Alerts From Prancer
Rule ID: bfb1c90f-8006-4325-98be-c7fffbc254d6
Distributed Password cracking attempts in Microsoft Entra ID
Rule ID: 0d76e9cf-788d-4a69-ac7d-f234826b5bed
DNS events related to mining pools
Rule ID: c094384d-7ea7-4091-83be-18706ecca981
DNS events related to mining pools ASIM DNS Schema
Rule ID: a83ef0f4-dace-4767-bce3-ebd32599d2a0
DNS events related to ToR proxies
Rule ID: 3fe3c520-04f1-44b8-8398-782ed21435f8
DNS events related to ToR proxies ASIM DNS Schema
Rule ID: f8c223c1-1a28-4b28-8e9f-5e33b610916b
DomainTools New Domain Discovery Indicators Ingested
Rule ID: f8c223c1-1a28-4b28-8e9f-5e34b610916b
DomainTools Newly Added Domains Feeds Ingested
Rule ID: f8c223c1-1a28-4b28-8e9f-5e35b610916b
DomainTools Newly Observed Domains Feeds Ingested
Rule ID: f8c223c1-1a28-4b28-8e9f-5e36b610916b
DomainTools Newly Observed Hostnames Feeds Ingested
Rule ID: 5bdc1504-880c-4b30-a39c-7c746535928d
Doppelpaymer Stop Services
Rule ID: 1be34fb9-f81b-47ae-84fb-465e6686d76c
DopplePaymer Procdump
Rule ID: 9a74fe72-4c21-4ac5-80d9-37434e809721
Dragos Notifications
Rule ID: 237c3855-138c-4588-a68f-b870abd3bfc9
Drop attempts stateful anomaly on database
Rule ID: 979c42dd-533e-4ede-b18b-31a84ba8b3d6
DSRM Account Abuse
Rule ID: a7b9df32-1367-402d-b385-882daf6e3020
Dumping LSASS Process Into a File
Rule ID: 415978ff-074e-4203-824a-b06153d77bf7
Dynatrace - Problem detection
Rule ID: 1b0b2065-8bac-5a00-83c4-1b58f69ac212
Dynatrace Application Security - Attack detection
Rule ID: 305093b4-0fa2-57bc-bced-caea782a6e9c
Dynatrace Application Security - Code-Level runtime vulnerability detection
Rule ID: ff0af873-a2f2-4233-8412-0ef4e00b0156
Dynatrace Application Security - Non-critical runtime vulnerability detection
Rule ID: af99b078-124b-543a-9a50-66ef87c09f6a
Dynatrace Application Security - Third-Party runtime vulnerability detection
Rule ID: 5a7fccb8-3ed0-44f2-8477-540af3ef4d92
EatonForeseer - Unauthorized Logins
Rule ID: a0e55dd4-8454-4396-91e6-f28fec3d2cab
Egress Defend - Dangerous Attachment Detected
Rule ID: a896123e-03a5-4a4d-a7e3-fd814846dfb2
Egress Defend - Dangerous Link Click
Rule ID: 7a0f78b3-9a55-4ad0-a56d-b6616fdbff6a
Elevation of Privilege attempt detected
Rule ID: 2f561e20-d97b-4b13-b02d-18b34af6e87c
Email access via active sync
Rule ID: 8a2cc466-342d-4ebb-8871-f9e1d83a24a5
Employee account deleted
Rule ID: c4d442a8-8227-4735-ac13-d84704e1b371
Empty group with entitlements
Rule ID: cfc967be-0428-4ab0-8c15-06c85649078f
Encryption Password Added
Rule ID: 58fcb721-35ec-4ea2-9f29-c99acde676b8
Encryption Password Changed
Rule ID: a2c6fe48-0d3d-416b-991c-a750ec50d7eb
Encryption Password Deleted
Rule ID: 009b9bae-23dd-43c4-bcb9-11c4ba7c784a
End-user consent stopped due to risk-based consent
Rule ID: 43df1e4c-61f8-4ab8-bc86-65eca7ecab9a
End-user consent to app with mailbox and offline access delegated scopes
Rule ID: 9d8b5a18-b7db-4c23-84a6-95febaf7e1e4
Europium - Hash and IP IOCs - September 2022
Rule ID: 3d645a88-2724-41a7-adea-db74c439cf79
Excessive Amount of Denied Connections from a Single Source
Rule ID: fa0ab69c-7124-4f62-acdd-61017cf6ce89
Excessive Blocked Traffic Events Generated by User
Rule ID: 7a58b253-0ef2-4248-b4e5-c350f15a8346
Excessive Denied Proxy Traffic
Rule ID: c775a46b-21b1-46d7-afa6-37e3e577a27b
Excessive Failed Authentication from Invalid Inputs
Rule ID: f5217b4c-3f1f-4d89-b4f3-5d7581da1c1c
Excessive Login Attempts Microsoft Defender for IoT
Rule ID: 4902eddb-34f7-44a8-ac94-8486366e9494
Excessive number of failed connections from a single source ASIM Network Session schema
Rule ID: a1bddaf8-982b-4089-ba9e-6590dfcf80ea
Excessive number of HTTP authentication failures from a source ASIM Web Session schema
Rule ID: b8266f81-2715-41a6-9062-42486cbc9c73
Excessive NXDOMAIN DNS Queries
Rule ID: c3b11fb2-9201-4844-b7b9-6b7bf6d9b851
Excessive NXDOMAIN DNS Queries ASIM DNS Schema
Rule ID: aba0b08c-aace-40c5-a21d-39153023dcaa
Excessive share permissions
Rule ID: 2391ce61-8c8d-41ac-9723-d945b2e90720
Excessive Windows Logon Failures
Rule ID: 194dd92e-d6e7-4249-85a5-273350a7f5ce
Exchange AuditLog Disabled
Rule ID: faf1a6ff-53b5-4f92-8c55-4b20e9957594
Exchange OAB Virtual Directory Attribute Containing Potential Webshell
Rule ID: 8955c0fb-3408-47b0-a3b9-a1faec41e427
Exchange Server Suspicious File Downloads
Rule ID: 968358d6-6af8-49bb-aaa4-187b3067fb95
Exchange SSRF Autodiscover ProxyShell - Detection
Rule ID: 2c701f94-783c-4cd4-bc9b-3b3334976090
Exchange Worker Process Making Remote Call
Rule ID: b4ceb583-4c44-4555-8ecf-39f572e827ba
Exchange workflow MailItemsAccessed operation anomaly
Rule ID: 3367fd5e-44b3-4746-a9a5-dc15c8202490
Execution attempts stateful anomaly on database
Rule ID: 26e81021-2de6-4442-a74a-a77885e96911
Execution of software vulnerable to webp buffer overflow of CVE-2023-4863
Rule ID: 433c3b0a-7278-4d74-b137-963ac6f9a7e7
Expired access credentials being used in Azure
Rule ID: a8130dcc-3617-41c0-a7ac-5f352bcfffaf
External Fabric Module XFM1 is unhealthy
Rule ID: acc4c247-aaf7-494b-b5da-17f18863878a
External guest invitation followed by Microsoft Entra ID PowerShell signin
Rule ID: cc47b9d6-a10e-4c5e-94a1-c73a68273e2d
External Repository Deleted
Rule ID: d035188d-d856-4a74-8226-f3bdf65033c4
External Repository Settings Updated
Rule ID: adc32a33-1cd6-46f5-8801-e3ed8337885f
External Upstream Source Added to Azure DevOps Feed
Rule ID: 8e267e91-6bda-4b3c-bf68-9f5cbdd103a3
External User Access Enabled
Rule ID: bff093b2-500e-4ae5-bb49-a5b1423cbd5b
External user added and removed in short timeframe
Rule ID: 910124df-913c-47e3-a7cd-29e1643fa55e
Failed AWS Console logons but success logon to AzureAD
Rule ID: 643c2025-9604-47c5-833f-7b4b9378a1f5
Failed AzureAD logons but success logon to AWS Console
Rule ID: 8ee967a2-a645-4832-85f4-72b635bcb3a6
Failed AzureAD logons but success logon to host
Rule ID: 1ce5e766-26ab-4616-b7c8-3b33ae321e80
Failed host logons but success logon to AzureAD
Rule ID: 223db5c1-1bf8-47d8-8806-bed401b356a4
Failed login attempts to Azure Portal
Rule ID: 884be6e7-e568-418e-9c12-89229865ffde
Failed Logins from Unknown or Invalid User
Rule ID: 0777f138-e5d8-4eab-bec1-e11ddfbc2be2
Failed logon attempts by valid accounts within 10 mins
Rule ID: e7ec9fa6-e7f7-41ed-a34b-b956837a3ee6
Failed logon attempts in authpriv
Rule ID: 760b8467-e6cc-4006-9149-5696845c1a54
Failed sign-ins into LastPass due to MFA
Rule ID: 5f6f5a46-42d3-4961-94db-68b6229bc84e
Failover Plan Deleted
Rule ID: 8f339b13-02f0-400f-be18-491ec0ba71f1
Failover Plan Failed
Rule ID: a053e7ba-e60c-482a-bbd8-89a25c53d905
Failover Plan Settings Updated
Rule ID: e06ec6d7-d9f6-4675-89bf-03fa8a0e0be0
Failover Plan Started
Rule ID: de4cc05b-2e4e-4104-9559-101b4c41c35e
Failover Plan Stopped
Rule ID: c1faf5e8-6958-11ec-90d6-0242ac120003
Fake computer account created
Rule ID: 6d2d6b3f-7d7b-4d4a-9b2b-9f7f3b8c2a11
Field Effect MDR Alert ARO Alert
Rule ID: d7f23105-6756-43ae-973c-48b7441559d5
File Server Deleted
Rule ID: 62008da4-627e-47fe-b78a-62e1e23b3eb9
File Server Settings Updated
Rule ID: 7ddaf8ef-b726-408b-b1a7-a7a4f92cbf6d
File Share Deleted
Rule ID: 3ab04acf-e0e7-4f7c-8995-748ab4c848c2
Files Copied to USB Drives
Rule ID: 9b784b65-2d16-4c9f-9f59-2a5d4c659f42
Filewall - Blocked emails
Rule ID: 86e7f6fd-5c29-4a3a-bced-3eca3fb0c621
Filewall - Blocked files
Rule ID: 20f87813-3de0-4a9f-a8c0-6aaa3187be08
Firewall errors stateful anomaly on database
Rule ID: 05030ca6-ef66-42ca-b672-2e84d4aaf5d7
Firewall rule manipulation attempts stateful anomaly on database
Rule ID: 7cad4b66-5e83-4756-8de4-f21315ab1e77
Firmware Updates Microsoft Defender for IoT
Rule ID: 2cfc3c6e-f424-4b88-9cc9-c89f482d016a
First access credential added to Application or Service Principal where no credential was present
Rule ID: 76210211-3ade-47b6-b7f2-c871cd05ec43
Flare chat results
Rule ID: 9cb7c337-f172-4af6-b0e8-b6b7552d762d
Flare cloud bucket results
Rule ID: 9cb7c337-f174-4af6-b0e8-b6b7552d762d
Flare google dork results
Rule ID: 9cb7c337-f175-4af6-b0e8-b6b7552d762d
Flare host results
Rule ID: 9cb7c337-f176-4af6-b0e8-b6b7552d762d
Flare infected device results
Rule ID: 9cb7c337-f170-4af6-b0e8-b6b7552d762d
Flare leaked credentials results
Rule ID: 8e5ae0d6-7f2d-475e-ada3-ed33441deeba
Flare lookalike domain results
Rule ID: 9265ae4d-6bb0-4c18-961d-f7aae67d1546
Flare marketplace results
Rule ID: 9cb7c337-f177-4af6-b0e8-b6b7552d762d
Flare paste results
Rule ID: 9cb7c337-f178-4af6-b0e8-b6b7552d762d
Flare source code results
Rule ID: 59336232-1bbc-4f66-90dd-5ac3708e4405
Flow Logs Alerts for Prancer
Rule ID: dccbdb5b-2ce7-4931-bfbe-f1ad6523ee64
FO - Bank account change following network alias reassignment
Rule ID: 5ab00fbb-ba2c-44dc-b02e-f119639b9a11
FO - Mass update or deletion of user records
Rule ID: 5b7cc7f9-fe54-4138-9fb0-d650807345d3
FO - Non-interactive account mapped to self or sensitive privileged user
Rule ID: 44b1021c-d517-4b7a-9ba6-a91eab94e632
FO - Reverted bank account number modifications
Rule ID: 919e939f-95e2-4978-846e-13a721c89ea1
FO - Unusual sign-in activity using single factor authentication
Rule ID: d272e277-f285-4dbc-ae2d-7f65ba64a79e
Forescout-DNS_Sniff_Event_Monitor
Rule ID: 1e6a8802-9129-44d4-a4f9-c6010b5725e8
FortiNDR Cloud - Security Event Detected
Rule ID: 3255ec41-6bd6-4f35-84b1-c032b18bbfcb
Fortinet - Beacon pattern detected
Rule ID: 86e9409f-b9ea-4e9a-8b72-5132ba43bcae
Fortiweb - WAF Allowed threat
Rule ID: 57a8ff3a-d4aa-456f-9c13-186026bae52e
Four-Eyes Authorization Disabled
Rule ID: fe6226cd-fee7-4d0d-88d2-160311207b57
Four-Eyes Authorization Request Created
Rule ID: a641dbe1-9590-46f8-a6d7-b5f24db6e126
Four-Eyes Authorization Request Expired
Rule ID: dfd1d756-623d-4951-84a5-ce51f726d322
Four-Eyes Authorization Request Rejected
Rule ID: 16da3a2a-af29-48a0-8606-d467c180fe18
Front Door Premium WAF - SQLi Detection
Rule ID: b7643904-5081-4920-917e-a559ddc3448f
Front Door Premium WAF - XSS Detection
Rule ID: 54e22fed-0ec6-4fb2-8312-2a3809a93f63
full_access_as_app Granted To Application
Rule ID: 0bd65651-1404-438b-8f63-eecddcec87b4
Gain Code Execution on ADFS Server via Remote WMI Execution
Rule ID: 12dcea64-bec2-41c9-9df2-9f28461b1295
Gain Code Execution on ADFS Server via SMB Remote Service or Scheduled Task
Rule ID: 8d2b6f4c-1a37-4e9b-b5c8-7f0e3a2d9c14
Gambit Security - Critical Policy Issue Promotion
Rule ID: b7da45ce-fcc8-43c7-a37c-c08454579d26
GCP Audit Logs - Data Access Logging Exemption Added for Principal
Rule ID: dfdffdc7-929f-4c7e-8f48-30e5ffddb067
GCP Audit Logs - Detect Bulk VM Snapshot Deletion
Rule ID: 205e1c9f-faee-43f1-b3b8-1952ffbbeea4
GCP Audit Logs - Detect Organization Policy Deletion or Updation
Rule ID: 9129a43e-e204-4a9a-969e-d8861ce3437c
GCP Audit Logs - DNSSEC Disabled on Managed DNS Zone
Rule ID: 8061c611-55f1-4ee5-a8f8-8f19f2c7aab2
GCP Audit Logs - Open Firewall Rule Created or Modified
Rule ID: 3a8d7f9e-4b2c-4e5d-8c6b-9f1a3d5e8c7b
GCP Audit Logs - Storage Bucket Made Public
Rule ID: 8f3e9c2d-5b4a-4d6e-9a7c-2f8b5e1d3c9a
GCP Audit Logs - VPC Flow Logs Disabled
Rule ID: 2530a631-9605-404d-ae58-58ef1f91b17c
GCP IAM - Disable Data Access Logging
Rule ID: 9e0d8632-d33d-4075-979e-c972674f77b3
GCP IAM - Empty user agent
Rule ID: 86112c4b-2535-4178-aa0e-ed9e32e3f054
GCP IAM - High privileged role added to service account
Rule ID: 80e4db30-5636-4fbd-8816-24c3ded8d243
GCP IAM - New Authentication Token for Service Account
Rule ID: a768aa52-453e-4e3e-80c2-62928d2e2f56
GCP IAM - New Service Account
Rule ID: fc135860-8773-4ead-b5be-9789af1ff8ff
GCP IAM - New Service Account Key
Rule ID: 52d88912-fa8b-4db2-b247-ee9225e41e8f
GCP IAM - Privileges Enumeration
Rule ID: 4a433846-4b05-4a27-99d7-92093feded79
GCP IAM - Publicly exposed storage bucket
Rule ID: 50e0437e-912d-4cd0-ac19-fef0aebdd3d7
GCP IAM - Service Account Enumeration
Rule ID: 7ad3cfed-18c0-44af-9e9d-9fb5472a2321
GCP IAM - Service Account Keys Enumeration
Rule ID: a9c7a4be-b7e7-4045-8028-0d1ffaa049af
GCP Security Command Center - Detect DNSSEC disabled for DNS zones
Rule ID: f4f92ca4-6ebe-4f2a-90e5-b0d04b709651
GCP Security Command Center - Detect Firewall rules allowing unrestricted high-risk ports
Rule ID: d8e30113-373a-4f49-a0ad-1a5d8b95b729
GCP Security Command Center - Detect OpenUnrestricted API Keys
Rule ID: 395f3ced-3923-4b83-b05d-8d077fd48c1e
GCP Security Command Center - Detect projects with API Keys present
Rule ID: d1fe8d30-4852-463a-b6ee-3b459788b75d
GCP Security Command Center - Detect Resources with Logging Disabled
Rule ID: 14003a45-da0b-47dc-8e20-9711ba7b5112
General Settings Updated
Rule ID: cd65aebc-7e85-4cbb-9f91-ff0376c5d37d
Generate alerts based on ExtraHop detections recommended for triage
Rule ID: 6bb50582-caac-4a9b-9afb-3fee766ebbf7
GitHub - A payment method was removed
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe10c5
GitHub - Oauth application - a client secret was removed
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe10c7
GitHub - pull request was created
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe10c6
GitHub - pull request was merged
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe10c2
GitHub - Repository was created
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe10c3
GitHub - Repository was destroyed
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe20c9
GitHub - User visibility Was changed
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe10c4
GitHub - User was added to the organization
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe10c8
GitHub - User was blocked
Rule ID: 0b85a077-8ba5-4cb5-90f7-1e882afe40c9
GitHub - User was invited to the repository
Rule ID: f041e01d-840d-43da-95c8-4188f6cef546
GitHub Activites from a New Country
Rule ID: 5436f471-b03d-41cb-b333-65891f887c43
GitHub Security Vulnerability in Repository
Rule ID: 5e7581e8-39e3-42bb-9104-f4b1e0dc53ec
GitHub Security Vulnerability in Repository
Rule ID: d3980830-dd9d-40a5-911f-76b44dfdce16
GitHub Signin Burst from Multiple Locations
Rule ID: 3ff0fffb-d963-40c0-b235-3404f915add7
GitHub Two Factor Auth Disable
Rule ID: 3efd09bd-a582-4410-b7ec-5ff21cfad7bd
GitLab - Abnormal number of repositories deleted
Rule ID: 2238d13a-cf05-4973-a83f-d12a25dbb153
GitLab - Brute-force Attempts
Rule ID: c1544d8f-cbbd-4e35-8d32-5b9312279833
GitLab - External User Added to GitLab
Rule ID: e0b45487-5c79-482d-8ac0-695de8c031af
GitLab - Local Auth - No MFA
Rule ID: 4d6d8b0e-6d9a-4857-a141-f5d89393cddb
GitLab - Personal Access Tokens creation over time
Rule ID: 8b291c3d-90ba-4ebf-af2c-0283192d430e
GitLab - Repository visibility to Public
Rule ID: 57b1634b-531d-4eab-a456-8b855887428f
GitLab - SSO - Sign-Ins Burst
Rule ID: 7241740a-5280-4b74-820a-862312d721a8
GitLab - TI - Connection from Malicious IP
Rule ID: 0f4f16a2-b464-4c10-9a42-993da3e15a40
GitLab - User Impersonation
Rule ID: 0995ccd8-16d4-4764-83b2-511235ca4e4b
Global Network Traffic Rules Deleted
Rule ID: c9faf1ee-57dd-4f54-8cd1-fcf35a1aa424
Global VM Exclusions Added
Rule ID: 2034c441-2850-4167-80ed-b4438155836d
Global VM Exclusions Changed
Rule ID: 141d7e3c-a72b-49f7-9e64-57f60c2fa927
Global VM Exclusions Deleted
Rule ID: 1267d53d-f5fd-418b-b8da-34453a5994c2
Google DNS - CVE-2020-1350 SIGRED exploitation pattern
Rule ID: e632e73a-06c4-47f6-8bed-b2498aa6e30f
Google DNS - CVE-2021-34527 PrintNightmare external exploit
Rule ID: 6758c671-e9ee-495d-b6b0-92ffd08a8c3b
Google DNS - CVE-2021-40444 exploitation
Rule ID: 424c2aca-5367-4247-917a-5d0f7035e40e
Google DNS - Exchange online autodiscover abuse
Rule ID: 35221a58-cacb-4174-9bb4-ee777784fbce
Google DNS - IP check activity
Rule ID: 75491db8-eaf7-40bb-a46a-279872cc82f5
Google DNS - Malicous Python packages
Rule ID: 7e81a935-5e91-45a5-92fd-3b58c180513b
Google DNS - Multiple errors for source
Rule ID: da04a5d6-e2be-4cba-8cdb-a3f2efa87e9e
Google DNS - Multiple errors to same domain
Rule ID: 705bed63-668f-4508-9d2d-26faf4010700
Google DNS - Possible data exfiltration
Rule ID: 09fc03e0-daec-4b22-8afa-4bba30d7e909
Google DNS - Request to dynamic DNS service
Rule ID: 22a613ea-c338-4f91-bbd3-3be97b00ebf9
Google DNS - UNC2452 Nobelium APT Group activity
Rule ID: f6b0c254-8f7d-4a1b-d5c2-0e4a6b9f2d8a
Google SecOps - Detection Alerts
Rule ID: b3e7f921-5c4a-4d8e-a2f9-7b1d3e6c9a5f
Google SecOps - GCTI Threat Intelligence Finding
Rule ID: d4f8a032-6d5b-4e9f-b3a0-8c2e4f7d0b6e
Google SecOps - Multi-Event Correlated Alert
Rule ID: e5a9b143-7e6c-4f0a-c4b1-9d3f5a8e1c7f
Google SecOps - Single-Event Alert
Rule ID: d9e1646c-dc17-4150-ac85-581f5c9cb41f
Google Threat Intelligence - Threat Hunting Domain
Rule ID: 8f9cd0e5-b4ab-4821-95e2-1082fcd784c7
Google Threat Intelligence - Threat Hunting Hash
Rule ID: 7edb2abb-7ef7-4685-92eb-a628703ccf9f
Google Threat Intelligence - Threat Hunting IP
Rule ID: 89290690-54c4-4196-91c5-d32b1df5d873
Google Threat Intelligence - Threat Hunting Url
Rule ID: e50657d7-8bca-43ff-a647-d407fae440d6
GreyNoise TI Map IP Entity to CommonSecurityLog
Rule ID: ddf47b6f-870c-5712-a296-1383acb13c82
GreyNoise TI Map IP Entity to DnsEvents
Rule ID: 536e8e5c-ce0e-575e-bcc9-aba8e7bf9316
GreyNoise TI map IP entity to Network Session Events ASIM Network Session schema
Rule ID: c51628fe-999c-5150-9fd7-660fc4f58ed2
GreyNoise TI map IP entity to OfficeActivity
Rule ID: f6c76cc9-218c-5b76-9b82-8607f09ea1b4
GreyNoise TI Map IP Entity to SigninLogs
Rule ID: a7564d76-ec6b-4519-a66b-fcc80c42332b
Group created then added to built in domain local or global group
Rule ID: e3b6a9e7-4c3a-45e6-8baf-1d3bfa8e0c2b
GSA - Detect Abnormal Deny Rate for Source to Destination IP
Rule ID: 4c9f0a9e-44d7-4c9b-b7f0-f6a6e0d8f8fa
GSA - Detect Connections Outside Operational Hours
Rule ID: f6a8d6a5-3e9f-47c8-a8d5-1b2b9d3b7d6a
GSA - Detect Protocol Changes for Destination Ports
Rule ID: 82cfa6b9-5f7e-4b8b-8b2f-a63f21b7a7d1
GSA - Detect Source IP Scanning Multiple Open Ports
Rule ID: 4ef07345-5d89-4f5b-9c64-a180d81a6176
GSA - TI Domain Entity
Rule ID: 3ebd25b1-6f54-49f9-b5a5-0246357ce4ca
GSA - TI IP Entity
Rule ID: 347c6cb3-33d2-4753-b7f6-eab946a8cd51
GSA - TI URL Entity
Rule ID: 4d284d59-1ce5-4ea7-8e97-52256b95aa10
GTI - Actively Exploited Vulnerability Detected
Rule ID: 650429cd-afc6-41a5-90e7-6e4a85b2335d
GTI - CISA Known Exploited Vulnerability Detected
Rule ID: 3794141b-9bd3-41ae-8303-79f97692998b
GTI - Critical CVSS Score Vulnerability Detected
Rule ID: d4e5f6a7-b8c9-0123-defa-234567890124
GTI - Data Leak Alert Detected
Rule ID: b2c3d4e5-f6a7-8901-bcde-f12345678902
GTI - High and Critical Priority Alerts
Rule ID: f6a7b8c9-d0e1-2345-fabc-456789012345
GTI - High Relevance Alert Detected
Rule ID: c3d4e5f6-a7b8-9012-cdef-123456789013
GTI - Initial Access Broker Alert Detected
Rule ID: e5f6a7b8-c9d0-1234-efab-345678901234
GTI - Insider Threat Alert Detected
Rule ID: ebd03de8-0cee-4923-b510-45337e0aed84
GTI - Zero-Day Vulnerability Detected
Rule ID: a1b2c3d4-e5f6-7890-abcd-ef1234567891
GTI Relevance System Alert - Incident by Alert ID
Rule ID: 9ff28525-3c6f-47ba-806b-ffd913406989
Guardian- Additional check JSON Policy Violation Detection
Rule ID: 97a76b2d-02ea-4ae5-b0c4-79e834036481
Guardian- Ban Topic Policy Violation Detection
Rule ID: e7493b80-88d0-44fb-b11d-40a0467cc497
Guardian- BII Detection Policy Violation Detection
Rule ID: e5d9eea1-3250-49ba-9e39-b5678ec7496b
Guardian- Block Competitor Policy Violation Detection
Rule ID: 9c63e0b5-bb83-4873-947a-4385386a6c21
Guardian- Blocks specific strings of text Policy Violation Detection
Rule ID: 90f50a0b-6903-4ddc-adcc-c13ebb77ffa7
Guardian- Code Detection Policy Violation Detection
Rule ID: aa88a190-d4d8-4f32-b533-3aa097c9ce3d
Guardian- Content Access Control Allowed List Policy Violation Detection
Rule ID: 4c7f0b49-d972-4d26-81ab-36cbe43ac437
Guardian- Content Access Control Blocked List Policy Violation Detection
Rule ID: de3ce72f-7826-4be1-ab1a-87a8299c54f6
Guardian- Content Safety Profanity Policy Violation Detection
Rule ID: 378e5160-70cf-4f1a-b3c8-3bc2f0c884ad
Guardian- Content Safety Toxicity Policy Violation Detection
Rule ID: cae24b9e-a614-4213-b382-00698e89b037
Guardian- Gender Bias Policy Violation Detection
Rule ID: 76fd5899-0dd1-4336-9519-3c2c0d5d6ecb
Guardian- Input Output Relevance Policy Violation Detection
Rule ID: 5d736bd5-b8ff-493c-bfbb-19674903fced
Guardian- Input Rate Limiter Policy Violation Detection
Rule ID: 1e31a465-e25d-4810-881b-8a79e0de9379
Guardian- Invisible Text Policy Violation Detection
Rule ID: e65938c4-1379-4f7a-bd22-78f670a239c3
Guardian- Language Detection Policy Violation Detection
Rule ID: 8644d9e0-b810-4b55-889b-b8a9b3795b5d
Guardian- Malicious URL Policy Violation Detection
Rule ID: c0598d69-221e-4235-a1e4-bfd57ada8ce5
Guardian- No LLM Output Policy Violation Detection
Rule ID: f472bd5e-ffb3-4c8e-8abd-97aaa8ebcdff
Guardian- Not Safe For Work Policy Violation Detection
Rule ID: d5065600-617b-4a16-b58a-4a46da9c1afd
Guardian- Privacy Protection PII Policy Violation Detection
Rule ID: 46103101-43d9-4c09-b8c8-898dcafe73c0
Guardian- Racial Bias Policy Violation Detection
Rule ID: d9ad323f-6115-4f19-9e81-feabceeb6730
Guardian- Regex Policy Violation Detection
Rule ID: b2841802-c53c-4667-be8a-9ea8771c944a
Guardian- Same InputOutput Language Detection Policy Violation Detection
Rule ID: 1cd8baa8-b8b4-436e-9f3f-4328f52a8e14
Guardian- Secrets Policy Violation Detection
Rule ID: d6b3372a-0fc4-40ec-9630-b96efb527fba
Guardian- Security Integrity Checks Prompt Injection Policy Violation Detection
Rule ID: 24538989-9dea-4cc7-aa78-0969ca116051
Guardian- Sentiment Policy Violation Detection
Rule ID: 7e37bf0f-1a10-4a71-8207-19615ee75894
Guardian- Special PII Detection Policy Violation Detection
Rule ID: b7798389-6823-4af0-94e6-6135c4f8264e
Guardian- Token Limit Policy Violation Detection
Rule ID: de6f4636-a51a-411d-95d8-4f9099865990
Guardian- URL Detection Policy Violation Detection
Rule ID: 93a56919-105a-4ffe-9a8c-4ef6d0b101ac
Guardian- URL Reachability Policy Violation Detection
Rule ID: 4cc63b34-61ec-4043-ae2f-c1424bf303da
Guest accounts added in Entra ID Groups other than the ones specified
Rule ID: 6ab1f7b2-61b8-442f-bc81-96afe7ad8c53
Guest accounts added in Entra ID Groups other than the ones specified
Rule ID: 572e75ef-5147-49d9-9d65-13f2ed1e3a86
Guest Users Invited to Tenant by New Inviters
Rule ID: 03f25156-6172-11ec-90d6-0242ac120003
GWorkspace - Admin permissions granted
Rule ID: e369d246-5da8-11ec-bf63-0242ac130002
GWorkspace - Alert events
Rule ID: ead87cd6-5da7-11ec-bf63-0242ac130002
GWorkspace - An Outbound Relay has been added to a G Suite Domain
Rule ID: c45a9804-5da8-11ec-bf63-0242ac130002
GWorkspace - API Access Granted
Rule ID: 6ff0e16e-5999-11ec-bf63-0242ac130002
GWorkspace - Multiple user agents for single source
Rule ID: 8f6cd9a4-5e57-11ec-bf63-0242ac130002
GWorkspace - Possible brute force attack
Rule ID: d80d02a8-5da6-11ec-bf63-0242ac130002
GWorkspace - Possible maldoc file name in Google drive
Rule ID: c8cc02d0-5da6-11ec-bf63-0242ac130002
GWorkspace - Two-step authentification disabled for a user
Rule ID: c02b0c8e-5da6-11ec-bf63-0242ac130002
GWorkspace - Unexpected OS update
Rule ID: 92fae638-5da8-11ec-bf63-0242ac130002
GWorkspace - User access has been changed
Rule ID: abe1a663-d00d-482e-aa68-9394622ae03e
HackerView - Any Issue Detected
Rule ID: caa4665f-21fa-462d-bb31-92226e746c68
High bandwidth in the network Microsoft Defender for IoT
Rule ID: 44a555d8-ecee-4a25-95ce-055879b4b14b
High count of connections by client IP on many ports
Rule ID: 19e01883-15d8-4eb6-a7a5-3276cd668388
High count of failed attempts from same client IP
Rule ID: 884c4957-70ea-4f57-80b9-1bca3890315b
High count of failed logons by a user
Rule ID: 3edb7215-250b-40c0-8b46-79093949242d
High Number of Urgent Vulnerabilities Detected
Rule ID: 9adbd1c3-a4be-44ef-ac2f-503fd25692ee
High risk Office operation conducted by IP Address that recently attempted to log into a disabled account
Rule ID: 504257c1-81e2-4609-8d40-b395e62f11c7
High severity malicious activity detected
Rule ID: 8e0403b1-07f8-4865-b2e9-74d1e83200a4
High Urgency IONIX Action Items
Rule ID: 9f82a735-ae43-4c03-afb4-d5d153e1ace1
High-Risk Admin Activity
Rule ID: f4a28082-2808-4783-9736-33c1ae117475
High-Risk Cross-Cloud User Impersonation
Rule ID: b39e6482-ab7e-4817-813d-ec910b64b26e
Highly Sensitive Password Accessed
Rule ID: 3084b487-fad6-4000-9544-6085b9657290
Hijack Execution Flow - DLL Side-Loading
Rule ID: c7061f05-d0ed-40e1-862e-bc52e454e3a1
HoneyLabs TI Map IP Entity to CommonSecurityLog
Rule ID: 5d3a1c77-2b40-4e6c-9f2d-71c0a8e4b912
HoneyLabs TI Map IP Entity to Network Session ASIM
Rule ID: a573396f-06ed-4139-bccc-e0f88a2cf625
HoneyLabs TI Map IP Entity to SigninLogs
Rule ID: afe2a5ff-f4fe-4dee-8b6b-fd28d29d6738
HoneyLabs TI Map URL Entity to CommonSecurityLog
Rule ID: 5601e894-2d3c-42fd-bc71-f0350b1b0bc6
Host Deleted
Rule ID: ac1a85f1-0e3f-4ae8-9f59-a240fc04b03f
Host Settings Updated
Rule ID: 4e41c85f-d495-4a23-a218-41b938140dce
Hypervisor Host Deleted
Rule ID: 580da4d1-8e39-4420-855d-3d4f653fe127
Hypervisor Host Settings Updated
Rule ID: dc728ba1-5204-4fde-ab48-eda19c8fad3a
IaaS admin detected
Rule ID: 57bae0c4-50b7-4552-9de9-19dfecddbace
IaaS policy not attached to any identity
Rule ID: 31f43e9d-1839-4baf-a668-54c28b98af3e
IaaS shadow admin detected
Rule ID: 40cf9670-d4be-4149-9082-5809a2b12ca1
iboss - Command-and-Control Detected
Rule ID: cad35734-b97a-4209-9269-b98c916379eb
iboss - Malware Detected
Rule ID: 813ccf3b-0321-4622-b0bc-63518fd14454
Identify instances where a single source is observed using multiple user agents ASIM Web Session
Rule ID: ce74dc9a-cb3c-4081-8c2f-7d39f6b7bae1
Identify Mango Sandstorm powershell commands
Rule ID: 277911cc-6d7a-4847-b0ba-77ef1da6cc8c
Identify SysAid Server web shell creation
Rule ID: 50eb4cbd-188f-44f4-b964-bab84dcdec10
Identify SysAid Server web shell creation
Rule ID: 3733e1ac-991b-4504-99e8-24ff4fbaf6e4
Idira - High-Risk Actions Outside Business Hours
Rule ID: bdf3cf98-d64f-4c55-97e4-43483d6d3237
Idira - Multiple Failed Actions Followed by Success 15m
Rule ID: 30938118-8812-4b5f-afa4-a8d4ba2b5d86
Idira - Sensitive SafePermissionEntitlement Changes with customData
Rule ID: 70be4a31-9d2b-433b-bdc7-da8928988069
Illegal Function Codes for ICS traffic Microsoft Defender for IoT
Rule ID: 599fdc92-eb6d-4b54-8d79-2a3f740a846a
Illumio Enforcement Change Analytic Rule
Rule ID: e9e4e466-3970-4165-bc8d-7721c6ef34a6
Illumio Firewall Tampering Analytic Rule
Rule ID: b3c4b8f4-c12c-471e-9999-023c05852276
Illumio VEN Clone Detection Rule
Rule ID: c18bd8c2-50f0-4aa2-8122-d449243627d7
Illumio VEN Deactivated Detection Rule
Rule ID: ec07fcd3-724f-426d-9f53-041801ca5f6c
Illumio VEN Offline Detection Rule
Rule ID: 7379f752-18a2-43ca-8b74-70747dd792f8
Illumio VEN Suspend Detection Rule
Rule ID: 1a7dbcf6-21a2-4255-84b2-c8dbbdca4630
Illusive Incidents Analytic Rule
Rule ID: bb46dd86-e642-48a4-975c-44f5ac2b5033
Imminent Ransomware
Rule ID: 363307f6-09ba-4926-ad52-03aadfd24b5e
Imperva - Abnormal protocol usage
Rule ID: 4d365217-f96a-437c-9c57-53594fa261c3
Imperva - Critical severity event not blocked
Rule ID: 7ebc9e24-319c-4786-9151-c898240463bc
Imperva - Forbidden HTTP request method in request
Rule ID: 2ff35ed4-b26a-4cad-93a6-f67adb00e919
Imperva - Malicious Client
Rule ID: 905794a9-bc46-42b9-974d-5a2dd58110c5
Imperva - Malicious user agent
Rule ID: 4e8032eb-f04d-4a30-85d3-b74bf2c8f204
Imperva - Multiple user agents from same source
Rule ID: 6214f187-5840-4cf7-a174-0cf9a72bfd29
Imperva - Possible command injection
Rule ID: 58300723-22e0-4096-b33a-aa9b992c3564
Imperva - Request from unexpected countries
Rule ID: 427c025d-c068-4844-8205-66879e89bcfa
Imperva - Request from unexpected IP address to admin panel
Rule ID: 0ba78922-033c-468c-82de-2974d7b1797d
Imperva - Request to unexpected destination port
Rule ID: 8db2b374-0337-49bd-94c9-cfbf8e5d83ad
Infoblox - Data Exfiltration Attack
Rule ID: dc7af829-d716-4774-9d6f-03d9aa7c27a4
Infoblox - High Threat Level Query Not Blocked Detected
Rule ID: a5e2df87-f0c9-4540-8715-96e71b608986
Infoblox - IQ for TD Detected Insights - API Source
Rule ID: d04f1963-df27-4127-b1ec-3d37148d65be
Infoblox - IQ for TD Insight Detected - CDC Source
Rule ID: 3822b794-fa89-4420-aad6-0e1a2307f419
Infoblox - Many High Threat Level Queries From Single Host Detected
Rule ID: 99278700-79ca-4b0f-b416-bf57ec699e1a
Infoblox - Many High Threat Level Single Query Detected
Rule ID: b2f34315-9065-488e-88d0-a171d2b0da8e
Infoblox - Many NXDOMAIN DNS Responses Detected
Rule ID: cf9847bb-ab46-4050-bb81-75cab3f893dc
Infoblox - SOC Insight Detected - API Source
Rule ID: a4bdd81e-afc8-4410-a3d1-8478fa810537
Infoblox - SOC Insight Detected - CDC Source
Rule ID: 5b0864a9-4577-4087-b9fa-de3e14a8a999
Infoblox - TI - CommonSecurityLog Match Found - MalwareC2
Rule ID: 568730be-b39d-45e3-a392-941e00837d52
Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains
Rule ID: 28ee3c2b-eb4b-44de-a71e-e462843fea72
Infoblox - TI - Syslog Match Found - URL
Rule ID: f0be11a9-ec48-4df6-801d-479556044d4e
Ingress Tool Transfer - Certutil
Rule ID: a4fb4255-f55b-4c24-b396-976ee075d406
Insider Risk_High User Security Alert Correlations
Rule ID: 28a75d10-9b75-4192-9863-e452c3ad24db
Insider Risk_High User Security Incidents Correlation
Rule ID: 69660e65-0e5c-4700-8b99-5caf59786606
Insider Risk_Microsoft Purview Insider Risk Management Alert Observed
Rule ID: 15386bba-dc70-463f-a09f-d392e7731c63
Insider Risk_Risky User Access By Application
Rule ID: b81ed294-28cf-48c3-bac8-ac60dcef293b
Insider Risk_Sensitive Data Access Outside Organizational Geo-location
Rule ID: 9ff3b13b-287a-4ed0-8f6b-7e7b66cbbcbd
Internet Access Microsoft Defender for IoT
Rule ID: 5220a0b0-ab15-43cf-a77e-2273d35cfe8e
Invalid Code for Multi-Factor Authentication Entered
Rule ID: a4ce20ae-a2e4-4d50-b40d-d49f1353b6cc
IP address of Windows host encoded in web request
Rule ID: ba144bf8-75b8-406f-9420-ed74397f9479
IP with multiple failed Microsoft Entra ID logins successfully logs in to Palo Alto VPN
Rule ID: 6098daa0-f05e-44d5-b5a0-913e63ba3179
Jamf Protect - Alerts
Rule ID: 44da53c3-f3b0-4b70-afff-f79275cb9442
Jamf Protect - Network Threats
Rule ID: 9eb2f758-003b-4303-83c6-97aed4c03e41
Jamf Protect - Unified Logs
Rule ID: 2c81c0a0-9823-4a14-b21a-2b4acd3335d2
Java Executing cmd to run Powershell
Rule ID: 5b0cec45-4a91-4f08-bb1b-392427e8f440
Jira - Global permission added
Rule ID: 6bf42891-b54d-4b4e-8533-babc5b3ea4c5
Jira - New site admin user
Rule ID: b894593a-2b4c-4573-bc47-78715224a6f5
Jira - New site admin user
Rule ID: 8c90f30f-c612-407c-91a0-c6a6b41ac199
Jira - New user created
Rule ID: 72592618-fa57-45e1-9f01-ca8706a5e3f5
Jira - Permission scheme updated
Rule ID: fb6a8001-fe87-4177-a8f3-df2302215c4f
Jira - Project roles changed
Rule ID: c13ecb19-4317-4d87-9a1c-52660dd44a7d
Jira - User removed from group
Rule ID: 5d3af0aa-833e-48ed-a29a-8cfd2705c953
Jira - User removed from project
Rule ID: 943176e8-b979-45c0-8ad3-58ba6cfd41f0
Jira - Users password changed multiple times
Rule ID: 398aa0ca-45a2-4f79-bc21-ee583bbb63bc
Jira - Workflow scheme copied
Rule ID: b4ea5da0-77a8-400e-ae2b-3ca8fdb779ef
Job Deleted
Rule ID: 61c576ae-f81a-4151-8524-b08c86f206a8
Job No Longer Used as Second Destination
Rule ID: f031fbbc-37d8-4667-b795-d386bf2b5ab2
Keeper Security - Password Changed
Rule ID: 75ffc8a4-86db-4f48-8506-cb4c049be484
Keeper Security - User MFA Changed
Rule ID: f11f245e-f77e-4dc5-95f1-ce602c2a36ba
KMS Key Rotation Job Finished
Rule ID: 9b5ab4b6-7cca-4779-9784-761b48a58e78
KMS Server Deleted
Rule ID: 594dafa1-e2d5-4f83-b32e-c629cb629b6f
KMS Server Settings Updated
Rule ID: b75a4a7a-dedb-47be-b7e6-344f4d50af19
KnowBe4 Defend - Dangerous Attachment Detected
Rule ID: af90173d-cc27-4166-a9b1-8c4347b1f4ac
KnowBe4 Defend - Dangerous Link Click
Rule ID: 074ce265-f684-41cd-af07-613c5f3e6d0d
Known Forest Blizzard group domains - July 2019
Rule ID: 9f86885f-f31f-4e66-a39d-352771ee789e
Known Malware Detected
Rule ID: 25bef734-4399-4c55-9579-4ebabd9cccf6
Lateral Movement Risk - Role Chain Length
Rule ID: 50cbf34a-4cdd-45d7-b3f5-8b53a1d0d14f
Lateral Movement via DCOM
Rule ID: 7d0d3050-8dac-4b83-bfae-902f7dc0c21c
LaZagne Credential Theft
Rule ID: 94724029-6ec3-4bf7-a0e9-c4e4cba0479f
License Expired
Rule ID: 79adb08a-8218-492d-acf0-f8aa596f3444
License Expiring
Rule ID: e4828d99-bb06-40b3-8f9d-0f68fb61e9ee
License Grace Period Started
Rule ID: 31ffa231-72da-49f0-88cd-de08eaf3bc52
License Limit Exceeded
Rule ID: 8e4986ac-7388-4782-b389-0b0288123dbc
License Removed
Rule ID: 7a6f7e95-b574-44ab-b215-f5c32a2378d1
License Support Expired
Rule ID: 3caa6e6d-a3e2-4776-be97-15d20e2675ed
License Support Expiring
Rule ID: b9e3b9f8-a406-4151-9891-e5ff1ddd8c1d
Linked Malicious Storage Artifacts
Rule ID: 63aa43c2-e88e-4102-aea5-0432851c541a
Local Admin Group Changes
Rule ID: 6e575295-a7e6-464c-8192-3e1d8fd6a990
Log4j vulnerability exploit aka Log4Shell IP IOC
Rule ID: 6b2d4e8a-5f7c-4b9e-8a1d-3c5e7a9b2f4d
Lookout - Critical Audit and Policy Changes v2
Rule ID: 7a3e5f9b-4c8d-4a2e-9f1b-6d8e2a4c7f9e
Lookout - Critical Smishing and Phishing Alerts v2
Rule ID: 9c5b6d8f-3a02-4e9b-af4c-2d7e9b1f5a8c
Lookout - Device Compliance and Security Status Changes v2
Rule ID: 8b4a5c7e-2f91-4d8a-9e3b-1c6f8a2d4e9f
Lookout - High Severity Mobile Threats Detected v2
Rule ID: 7593cc60-e294-402d-9202-279fb3c7d55f
Lookout - New Threat events found
Rule ID: c332b840-61e4-462e-a201-0e2d69bad45d
LSASS Credential Dumping with Procdump
Rule ID: 29bf5bcd-6795-4c79-a91f-aaef5a618bab
Lumen TI domain in DnsEvents
Rule ID: bc8a262a-5db3-4ac1-8757-519ed36ed929
Lumen TI IPAddress in CommonSecurityLog
Rule ID: fa566691-42a2-4136-6a8b-ffa3ea510000
Lumen TI IPAddress in DeviceEvents
Rule ID: a7cd18cd-1503-47ec-8dca-65d750540637
Lumen TI IPAddress in IdentityLogonEvents
Rule ID: 0e96c419-68eb-4235-947e-7e86e136cda0
Lumen TI IPAddress in OfficeActivity
Rule ID: 140a2cb5-4b4a-485c-aab3-2415c24d37e6
Lumen TI IPAddress in SecurityEvents
Rule ID: 1425aea5-a9e5-4288-886e-934b90664a91
Lumen TI IPAddress in SigninLogs
Rule ID: 4776281c-6c49-46ac-8444-4dd8ba2f4565
Lumen TI IPAddress in WindowsEvents
Rule ID: 4be5b645-1d08-49e4-b58d-07294ff19223
M2131_AssetStoppedLogging
Rule ID: eeb11b6b-e626-4228-b74d-3e730dca8999
M2131_DataConnectorAddedChangedRemoved
Rule ID: 1f8fcca5-47ed-409d-a8fa-d49ef821feaf
M2131_EventLogManagementPostureChanged_EL0
Rule ID: 036ce0a8-a1ff-4731-a078-02b3207fa4f3
M2131_EventLogManagementPostureChanged_EL1
Rule ID: e1bb07c4-066b-4069-9b8e-f5275c592b6d
M2131_EventLogManagementPostureChanged_EL2
Rule ID: 672bfd77-4542-4ef1-acf9-e006dcd70c51
M2131_EventLogManagementPostureChanged_EL3
Rule ID: 8178a514-1270-4e31-a1d9-aaafeb40122f
M2131_LogRetentionLessThan1Year
Rule ID: b3e0bfd4-52d2-4684-9514-716035cdbff2
M2131_RecommendedDatatableNotLogged_EL0
Rule ID: f9e0ae98-6828-4d5a-b596-7c4586bb14f6
M2131_RecommendedDatatableNotLogged_EL1
Rule ID: 76326a24-1223-4066-88a3-3826e3768932
M2131_RecommendedDatatableNotLogged_EL2
Rule ID: 8b415f2d-44c1-4edb-8ca6-ddf7d2d28b20
M2131_RecommendedDatatableNotLogged_EL3
Rule ID: c61b167a-59ae-42af-bc98-36c78c5acb5c
M2131_RecommendedDatatableUnhealthy
Rule ID: 779731f7-8ba0-4198-8524-5701b7defddc
M365D Alerts Correlation to non-Microsoft Network device network activity involved in successful sign-in Activity
Rule ID: 500415fb-bba7-4227-a08a-9857fb61b6a7
Mail redirect via ExO transport rule
Rule ID: 2560515c-07d1-434e-87fb-ebe3af267760
MailRead Permissions Granted to Application
Rule ID: a357535e-f722-4afe-b375-cff362b2b376
Malformed user agent
Rule ID: 8ac77493-3cae-4840-8634-15fb23f8fb68
Malicious BEC Inbox Rule
Rule ID: 7b907bf7-77d4-41d0-a208-5643ff75bf9a
Malicious Inbox Rule
Rule ID: 9699e4c9-dca9-404b-be0b-6e342dd31aff
Malicious web application requests linked with Microsoft Defender for Endpoint formerly Microsoft Defender ATP alerts
Rule ID: fbfbf530-506b-49a4-81ad-4030885a195c
Malicious web application requests linked with Microsoft Defender for Endpoint formerly Microsoft Defender ATP alerts
Rule ID: 9a7c80ef-8dc2-4b07-834d-b9ca18d603f7
Malware Activity Detected
Rule ID: 0558155e-4556-447e-9a22-828f2a7de06b
Malware attachment delivered
Rule ID: 072ee087-17e1-474d-b162-bbe38bcab9f9
Malware Detected
Rule ID: 401e91cb-b53f-41a5-b066-1c028b3b51db
Malware Detection Exclusions List Updated
Rule ID: 88b9223c-29ff-48a9-a745-c553aa0dbae2
Malware Detection Session Finished
Rule ID: effd8410-3119-41c8-a228-9c0c8ce10d67
Malware Detection Settings Updated
Rule ID: b42424a6-10f4-447b-92a0-55ac38f4a475
Malware Event Detected
Rule ID: 75bf9902-0789-47c1-a5d8-f57046aa72df
Malware in the recycle bin
Rule ID: 61988db3-0565-49b5-b8e3-747195baac6e
Malware in the recycle bin Normalized Process Events
Rule ID: 8675dd7a-795e-4d56-a79c-fc848c5ee61c
Malware Link Clicked
Rule ID: ed43bdb7-eaab-4ea4-be52-6951fcfa7e3b
Mass Cloud resource deletions Time Series Anomaly
Rule ID: 6267ce44-1e9d-471b-9f1e-ae76a6b7aa84
Mass Download copy to USB device by single user
Rule ID: 24f8c234-d1ff-40ec-8b73-96b17a3a9c1c
Mass secret retrieval from Azure Key Vault
Rule ID: dd22dc4f-ab7c-4d0a-84ad-cc393638ba31
Match Legitimate Name or Location - 2
Rule ID: 3c1425d3-93d4-4eaf-8aa0-370dbac94c82
McAfee ePO - Agent Handler down
Rule ID: 2eff5809-bf84-48e0-8288-768689672c37
McAfee ePO - Attempt uninstall McAfee agent
Rule ID: 155243f4-d962-4717-8a7b-b15b6d112660
McAfee ePO - Deployment failed
Rule ID: 1e3bcd0f-10b2-4fbd-854f-1c6f33acc36a
McAfee ePO - Error sending alert
Rule ID: b9d9fdfe-bc17-45ce-a70d-67a5cfd119f4
McAfee ePO - File added to exceptions
Rule ID: bd3cedc3-efba-455a-85bd-0cf9ac1b0727
McAfee ePO - Firewall disabled
Rule ID: 0c9243d6-d2ec-48e1-8593-e713859c8f3c
McAfee ePO - Logging error occurred
Rule ID: f53e5168-afdb-4fad-b29a-bb9cb71ec460
McAfee ePO - Multiple threats on same host
Rule ID: 5223c1b8-75ef-4019-9076-a19b1ef3e5d1
McAfee ePO - Scanning engine disabled
Rule ID: ffc9052b-3658-4ad4-9003-0151515fde15
McAfee ePO - Spam Email detected
Rule ID: 3e397e31-7964-417e-a3e0-0acfaa2056f4
McAfee ePO - Task error
Rule ID: 6d70a26a-c119-45b7-b4c6-44ac4fd1bcb7
McAfee ePO - Threat was not blocked
Rule ID: 9860e89f-72c8-425e-bac9-4a170798d3ea
McAfee ePO - Unable to clean or delete infected file
Rule ID: 4f0c91c3-1690-48f0-b538-4282dd5417a4
McAfee ePO - Update failed
Rule ID: dfbe3963-42fb-4ebe-a00c-1cc44e2aa9f0
Medium severity malicious activity detected
Rule ID: ae10c588-7ff7-486c-9920-ab8b0bdb6ede
Mercury - Domain Hash and IP IOCs - August 2022
Rule ID: c2697b81-7fe9-4f57-ba1d-de46c6f91f9c
MFA Fatigue OKTA
Rule ID: d99cf5c3-d660-436c-895b-8a8f8448da23
MFA Rejected by User
Rule ID: a8cc6d5c-4e7e-4b48-b4ac-d8a116c62a8b
MFA Spamming followed by Successful login
Rule ID: 2be4ef67-a93f-4d8a-981a-88158cb73abd
Microsoft COVID-19 file hash indicator matches
Rule ID: a333d8bf-22a3-4c55-a1e9-5f0a135c0253
Microsoft Defender for Endpoint MDE signatures for Azure Synapse pipelines and Azure Data Factory
Rule ID: f819c592-c5f9-4d5c-a79f-1e6819863533
Microsoft Entra ID Health Monitoring Agent Registry Keys Access
Rule ID: 06bbf969-fcbe-43fa-bac2-b2fa131d113a
Microsoft Entra ID Health Service Agents Registry Keys Access
Rule ID: 88f453ff-7b9e-45bb-8c12-4058ca5e44ee
Microsoft Entra ID Hybrid Health AD FS New Server
Rule ID: 86a036b2-3686-42eb-b417-909fc0867771
Microsoft Entra ID Hybrid Health AD FS Service Delete
Rule ID: d9938c3b-16f9-444d-bc22-ea9a9110e0fd
Microsoft Entra ID Hybrid Health AD FS Suspicious Application
Rule ID: a356c8bd-c81d-428b-aa36-83be706be034
Microsoft Entra ID Local Device Join Information and Transport Key Registry Keys Access
Rule ID: 50574fac-f8d1-4395-81c7-78a463ff0c52
Microsoft Entra ID PowerShell accessing non-Entra ID resources
Rule ID: 87d5cd18-211d-4fd4-9b86-65d23fed87ea
Microsoft Entra ID Rare UserAgent App Sign-in
Rule ID: 1ff56009-db01-4615-8211-d4fda21da02d
Microsoft Entra ID Role Management Permission Grant
Rule ID: 6a638d80-f6b2-473b-9087-3cac78a84b40
Microsoft Entra ID UserAgent OS Missmatch
Rule ID: 00cb180c-08a8-4e55-a276-63fb1442d5b5
Midnight Blizzard - Script payload stored in Registry
Rule ID: d82e1987-4356-4a7b-bc5e-064f29b143c0
Midnight Blizzard - suspicious rundll32exe execution of vbscript
Rule ID: bdf04f58-242b-4729-b376-577c4bdf5d3a
Midnight Blizzard - suspicious rundll32exe execution of vbscript Normalized Process Events
Rule ID: 9c5dcd76-9f6d-42a3-b984-314b52678f20
Mimecast Audit - Logon Authentication Failed
Rule ID: f00197ab-491f-41e7-9e22-a7003a4c1e54
Mimecast Audit - Logon Authentication Failed
Rule ID: 3e12b7b1-75e5-497c-ba01-b6cb30b60d7f
Mimecast Data Leak Prevention - Hold
Rule ID: 8e52bcf1-4f50-4c39-8678-d9efad64e379
Mimecast Data Leak Prevention - Hold
Rule ID: 1818aeaa-4cc8-426b-ba54-539de896d299
Mimecast Data Leak Prevention - Notifications
Rule ID: cfd67598-ad0d-430a-a793-027eb4dbe967
Mimecast Data Leak Prevention - Notifications
Rule ID: 72264f4f-61fb-4f4f-96c4-635571a376c2
Mimecast Secure Email Gateway - Attachment Protect
Rule ID: 72bd7b0c-493c-4fa5-8a95-7f6376b6cfb2
Mimecast Secure Email Gateway - Attachment Protect
Rule ID: 0f0dc725-29dc-48c3-bf10-bd2f34fd1cbb
Mimecast Secure Email Gateway - AV
Rule ID: 33bf0cc9-e568-42bf-9571-c22adf7be66d
Mimecast Secure Email Gateway - AV
Rule ID: 2ef77cef-439f-4d94-848f-3eca67510d2f
Mimecast Secure Email Gateway - Impersonation Protect
Rule ID: 7034abc9-6b66-4533-9bf3-056672fd9d9e
Mimecast Secure Email Gateway - Impersonation Protect
Rule ID: 5b66d176-e344-4abf-b915-e5f09a6430ef
Mimecast Secure Email Gateway - Internal Email Protect
Rule ID: d3bd7640-3600-49f9-8d10-6fe312e68b4f
Mimecast Secure Email Gateway - Internal Email Protect
Rule ID: 0cda82c8-e8f0-4117-896e-a10f1b43e64a
Mimecast Secure Email Gateway - Spam Event Thread
Rule ID: df1b9377-5c29-4928-872f-9934a6b4f611
Mimecast Secure Email Gateway - Spam Event Thread
Rule ID: 80f244cd-b0d6-404e-9aed-37f7a66eda9f
Mimecast Secure Email Gateway - URL Protect
Rule ID: ea19dae6-bbb3-4444-a1b8-8e9ae6064aab
Mimecast Secure Email Gateway - URL Protect
Rule ID: 30f73baa-602c-4373-8f02-04ff5e51fc7f
Mimecast Secure Email Gateway - Virus
Rule ID: d78d7352-fa5a-47d4-b48f-cb2c3252c0eb
Mimecast Secure Email Gateway - Virus
Rule ID: 617a55be-a8d8-49c1-8687-d19a0231056f
Mimecast Targeted Threat Protection - Attachment Protect
Rule ID: aa75944c-a663-4901-969e-7b55bfa49a73
Mimecast Targeted Threat Protection - Attachment Protect
Rule ID: c048fa06-0d50-4626-ae82-a6cea812d9c4
Mimecast Targeted Threat Protection - Impersonation Protect
Rule ID: d8e7eca6-4b59-4069-a31e-a022b2a12ea4
Mimecast Targeted Threat Protection - Impersonation Protect
Rule ID: 952faed4-c6a6-4873-aeb9-b348e9ce5aba
Mimecast Targeted Threat Protection - URL Protect
Rule ID: 9d5545bd-1450-4086-935c-62f15fc4a4c9
Mimecast Targeted Threat Protection - URL Protect
Rule ID: b8b8ba09-1e89-45a1-8bd7-691cd23bfa32
Missing Domain Controller Heartbeat
Rule ID: d714ef62-1a56-4779-804f-91c4158e528d
Modification of Accessibility Features
Rule ID: 95dc4ae3-e0f2-48bd-b996-cdd22b90f9af
Modified domain federation trust settings
Rule ID: 506f4d6b-3864-4bb1-8f75-a13fb066f97a
MosaicLoader
Rule ID: 6881f4f5-f58e-43d7-a05e-b5d05a4c09f9
Multi-Factor Authentication Disabled
Rule ID: 65c78944-930b-4cae-bd79-c3664ae30ba7
Multi-Factor Authentication Disabled for a User
Rule ID: 3fefd6c5-bbe9-49a9-95b2-d4b8a5591d9c
Multi-Factor Authentication for User Disabled
Rule ID: 4d8f5244-cb56-4e95-ba65-0a7bec114a13
Multi-Factor Authentication Token Revoked
Rule ID: ebdd9cf8-c41c-460e-95d8-e5bc3cd9763e
Multi-Factor Authentication User Locked
Rule ID: cda5928c-2c1e-4575-9dfa-07568bc27a4f
Multiple admin membership removals from newly created admin
Rule ID: d39f0c47-2e85-49b9-a686-388c2eb7062c
Multiple failed attempts of NetBackup login
Rule ID: 0b9ae89d-8cad-461c-808f-0494f70ad5c4
Multiple Password Reset by user
Rule ID: 78422ef2-62bf-48ca-9bab-72c69818a425
Multiple RDP connections from Single System
Rule ID: 493916d5-a094-4bfa-bdd1-d983a063ea3d
Multiple scans in the network Microsoft Defender for IoT
Rule ID: 4644baf7-3464-45dd-bd9d-e07687e25f81
Multiple Sources Affected by the Same TI Destination
Rule ID: 173f8699-6af5-484a-8b06-8c47ba89b380
Multiple Teams deleted by a single user
Rule ID: 871ba14c-88ef-48aa-ad38-810f26760ca3
Multiple users email forwarded to same destination
Rule ID: a1551ae4-f61c-4bca-9c57-4d0d681db2e9
Multiple users email forwarded to same destination
Rule ID: e92ba6bb-53ea-4347-b1a6-2e015298bbdc
NDMP Server Deleted
Rule ID: 77548170-5c60-42e5-bdac-b0360d0779bb
NetClean ProActive Incidents
Rule ID: fa4c4f1c-3c5f-4c3a-a13f-924c30db56e9
Netskope - Anomalous User Behavior High Volume from Unmanaged Device
Rule ID: cf103180-cb81-4796-921d-3cc7eef4e817
Netskope - Data Movement Tracking UploadDownload Monitoring
Rule ID: c3f8e4d6-0d57-4a3b-9e2c-4f6a8b0d3e52
Netskope - DLP Incident Spike
Rule ID: dd0ebd84-ffbe-45df-848b-0615ac446b04
Netskope - Excessive Downloads Detection Spike vs Baseline
Rule ID: 272f9bca-5fd0-4413-b494-03b2d9f0bb9b
Netskope - Heavy Personal Cloud Storage Usage Shadow IT
Rule ID: a1f6c2d4-8b35-4e19-9c7a-2d4e6f8a1b30
Netskope - High Severity Alert
Rule ID: 04e36dfa-05b3-45bd-b39f-28b6fac71337
Netskope - High Severity DLP Alert
Rule ID: d1b88716-3cd4-4585-a9a2-2dd2c9b04ecb
Netskope - Impossible Travel Detection Two Countries in Less Than 1 Hour
Rule ID: 71e6586e-0d3f-4e33-b390-faa50b5e08fa
Netskope - Large Outbound Data Transfer Sensitive Upload DLP
Rule ID: ba66b81c-2cf7-4c53-9db0-e8b6f537704a
Netskope - New Risky App Access vs 7-Day Baseline
Rule ID: dacab67e-fcf3-41c6-a191-579c7be1814d
Netskope - Repeated or Critical Policy Violations
Rule ID: b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41
Netskope - Suspicious Application Activity Low Confidence Risky App
Rule ID: 6d989fb0-933e-4ae6-88fa-10e7b51c8897
Netskope - Suspicious Network Context Unusual IPsGeoPorts
Rule ID: cdc01279-d6ea-41b1-a32d-49d726be95b8
Netskope - UnsanctionedRisky Cloud App Access Shadow IT
Rule ID: 66c4cd4c-d391-47e8-b4e6-93e55d86ca9f
Netskope - WebTransaction Error Detection
Rule ID: 3e9b7d54-2a6c-4f18-b0e5-c7a94d21f6b8
Netskope Client - Internet Security disabled by user
Rule ID: 8c1f6a2e-4b7d-4e3a-9f21-5d0c7b9e6a41
Netskope Client - Private Access disabled by user
Rule ID: 01f64465-b1ef-41ea-a7f5-31553a11ad43
Network endpoint to host executable correlation
Rule ID: cd8faa84-4464-4b4e-96dc-b22f50c27541
Network Port Sweep from External Network ASIM Network Session schema
Rule ID: a8babf91-b844-477c-8abf-d31e3df74933
NetworkSecurityGroups Alert From Prancer
Rule ID: 79566f41-df67-4e10-a703-c38a6213afd8
New access credential added to Application or Service Principal
Rule ID: 4ce177b3-56b1-4f0e-b83e-27eed4cb0b16
New Agent Added to Pool by New User or Added to a New OS Type
Rule ID: 6d7214d9-4a28-44df-aafb-0910b9e6ae3e
New CloudShell User
Rule ID: 7808c05a-3afd-4d13-998a-a59e2297693f
New country signIn with correct password
Rule ID: 41e843a8-92e7-444d-8d72-638f1145d1e1
New DeviceLocation sign-in along with critical operation
Rule ID: d7ee7bb5-d712-4d44-b201-b13379924934
New direct access policy was granted against organizational policy
Rule ID: 05b4bccd-dd12-423d-8de4-5a6fb526bb4f
New EXE deployed via Default Domain or Default Domain Controller Policies
Rule ID: 0dd2a343-4bf9-4c93-a547-adf3658ddaec
New EXE deployed via Default Domain or Default Domain Controller Policies ASIM Version
Rule ID: d722831e-88f5-4e25-b106-4ef6e29f8c13
New executable via Office FileUploaded Operation
Rule ID: d7424fd9-abb3-4ded-a723-eebe023aaa0b
New External User Granted Admin Role
Rule ID: 6116dc19-475a-4148-84b2-efe89c073e27
New High Severity Vulnerability Detected Across Multiple Hosts
Rule ID: 4f42b94f-b210-42d1-a023-7fa1c51d969f
New onmicrosoft domain added to tenant
Rule ID: 35ce9aff-1708-45b8-a295-5e9a307f5f17
New PA PCA or PCAS added to Azure DevOps
Rule ID: 6c17f270-cd56-48cc-9196-1728ffea6538
New service account gained access to IaaS resource
Rule ID: bcc3362d-b6f9-4de0-b41c-707fafd5a416
New Sonrai Ticket
Rule ID: 050b9b3d-53d0-4364-a3da-1b678b8211ec
New User Assigned to Privileged Role
Rule ID: aa1eff90-29d4-49dc-a3ea-b65199f516db
New user created and added to the built-in administrators group
Rule ID: b725d62c-eb77-42ff-96f6-bdc6745fc6e0
New UserAgent observed in last 24 hours
Rule ID: d84739ce-2f46-4391-b25e-a2edbea19d7e
NGINX - Command in URI
Rule ID: 9a7f5a97-354b-4eac-b407-a1cc7fc4b4ec
NGINX - Core Dump
Rule ID: a10c6551-bbf2-492c-aa8a-fe6efd8c9cc1
NGINX - Known malicious user agent
Rule ID: 42771afe-edb3-4330-bc4a-abf6a5714454
NGINX - Multiple client errors from single IP address
Rule ID: b3ae0033-552e-4c3c-b493-3edffb4473bb
NGINX - Multiple server errors from single IP address
Rule ID: 83a0b48f-1cb7-4b4f-a018-23c3203a239b
NGINX - Multiple user agents for single source
Rule ID: 1aa6bfed-f11b-402f-9007-0dccc1152ede
NGINX - Private IP address in URL
Rule ID: e04fa38e-9fb7-438d-887a-381d5dd235e6
NGINX - Put file and get file from same IP address
Rule ID: 2141ef6c-d158-4d44-b739-b145a4c21947
NGINX - Request to sensitive files
Rule ID: 3bac451d-f919-4c92-9be7-694990e0ca4b
NGINX - Sql injection patterns
Rule ID: 50b0dfb7-2c94-4eaf-a332-a5936d78c263
Ngrok Reverse Proxy on Network ASIM DNS Solution
Rule ID: dd834c97-4638-4bb3-a4e3-807e8b0580dc
NIST SP 800-53 Posture Changed
Rule ID: 208c3f5b-3ba2-49b5-9bca-c44e58cd5fd3
No traffic on Sensor Detected Microsoft Defender for IoT
Rule ID: b9d2eebc-5dcb-4888-8165-900db44443ab
Non Domain Controller Active Directory Replication
Rule ID: 9B6558C4-BA23-40AC-B95F-42F8A29A3B35
Non-admin guest
Rule ID: 800314a6-759a-4575-93e2-1e080b1d33f9
NordPass - Activity token revocation
Rule ID: 283d7506-f3c6-419a-ae9c-d9afe6a15d6d
NordPass - Declined invitation
Rule ID: 0068dca4-dea0-46a3-a970-655e067a145f
NordPass - Deleting items of deleted member
Rule ID: e3f2b6c9-df0c-4b36-a376-bb2762e4dbdc
NordPass - Domain data detected in breach
Rule ID: 693c5217-e840-427f-9661-3fa0ef266040
NordPass - Manual invitation suspension or deletion
Rule ID: c4d2eb42-a4ab-4db6-a270-3d2ed7e057a0
NordPass - User data detected in breach
Rule ID: f72f630f-c890-49fe-b747-80f4fb3b6348
NordPass - User deletes items in bulk
Rule ID: 27b261dc-68f3-489a-944f-bc252e0c1960
NordPass - User fails authentication
Rule ID: c7f14b43-7625-4516-b137-30b7fda65bcf
NordPass - Vault export
Rule ID: 29e99017-e28d-47be-8b9a-c8c711f8a903
NRT Authentication Methods Changed for VIP Users
Rule ID: 7cfa479a-7026-4727-8f96-6e9826a42014
NRT Authentication Methods Changed for VIP Users
Rule ID: 74ed028d-e392-40b7-baef-e69627bf89d1
NRT Azure DevOps Audit Stream Disabled
Rule ID: c3e5dbaa-a540-408c-8b36-68bdfb3df088
NRT Base64 Encoded Windows Process Command-lines
Rule ID: 56fe0db0-6779-46fa-b3c5-006082a53064
NRT Creation of expensive computes in Azure
Rule ID: d5b32cd4-2328-43da-ab47-cd289c1f5efc
NRT DNS events related to mining pools
Rule ID: 5336c0fe-e897-4857-9254-728617941477
NRT First access credential added to Application or Service Principal where no credential was present
Rule ID: b6988c32-4f3b-4a45-8313-b46b33061a74
NRT First access credential added to Application or Service Principal where no credential was present
Rule ID: 353b839b-0cef-465e-b366-8203ea577380
NRT GitHub Two Factor Auth Disable
Rule ID: 594c653d-719a-4c23-b028-36e3413e632e
NRT GitHub Two Factor Auth Disable
Rule ID: 73c803aa-1188-45dd-8379-62a3319d3d9f
NRT GravityZone Incident Alerts
Rule ID: b79f6190-d104-4691-b7db-823e05980895
NRT Malicious Inbox Rule
Rule ID: ec491363-5fe7-4eff-b68e-f42dcb76fcf6
NRT Microsoft Entra ID Hybrid Health AD FS New Server
Rule ID: 8540c842-5bbc-4a24-9fb2-a836c0e55a51
NRT Modified domain federation trust settings
Rule ID: 3b05727d-a8d1-477d-bbdd-d957da96ac7b
NRT Multiple users email forwarded to same destination
Rule ID: e42e889a-caaf-4dbb-aec6-371b37d64298
NRT New access credential added to Application or Service Principal
Rule ID: 5db427b2-f406-4274-b413-e9fcb29412f8
NRT PIM Elevation Request Rejected
Rule ID: 14f6da04-2f96-44ee-9210-9ccc1be6401e
NRT Privileged Role Assigned Outside PIM
Rule ID: 7ad4c32b-d0d2-411c-a0e8-b557afa12fce
NRT Process executed from binary hidden in Base64 encoded file
Rule ID: 508cef41-2cd8-4d40-a519-b04826a9085f
NRT Security Event log cleared
Rule ID: 884ead54-cb3f-4676-a1eb-b26532d6cbfd
NRT Sensitive Azure Key Vault operations
Rule ID: dd03057e-4347-4853-bf1e-2b2d21eb4e59
NRT Squid proxy events related to mining pools
Rule ID: 70fc7201-f28e-4ba7-b9ea-c04b96701f13
NRT User added to Microsoft Entra ID Privileged Groups
Rule ID: 56d70592-077e-4e7b-9d8a-b5d8b0a6a52b
Object Marked as Clean
Rule ID: 6e4d1832-2cf9-410d-a5e2-c12b33c7d9f7
Object Storage Deleted
Rule ID: 1f6897bf-a05a-47b2-a5f9-4ba6fd34f715
Object Storage Settings Updated
Rule ID: a8ebf22b-a050-434c-8095-2267f206257a
Objects Added to Malware Detection Exclusions
Rule ID: f4cad1aa-a1e2-46dc-bf09-6cf8dc67f0ca
Objects Deleted from Malware Detection Exclusions
Rule ID: 5367e8fc-a150-468f-84f2-90ac1dabef15
Objects for Job Deleted
Rule ID: af97a601-8fac-4628-bdad-5fc0511236b2
Objects for Protection Group Changed
Rule ID: 88a61215-b3e6-4c78-8acd-9078d9bcfdc3
Objects for Protection Group Deleted
Rule ID: 61f995d7-8038-4ff0-ad2b-eccfd18fcc8c
OCI - Discovery activity
Rule ID: 31b15699-0b55-4246-851e-93f9cefb6f5c
OCI - Event rule deleted
Rule ID: eb6e07a1-2895-4c55-9c27-ac84294f0e46
OCI - Inbound SSH connection
Rule ID: 9c4b1b9c-6462-41ce-8f2e-ce8c104331fc
OCI - Insecure metadata endpoint
Rule ID: a55b4bbe-a014-4ae9-a50d-441ba5e98b65
OCI - Instance metadata access
Rule ID: a79cf2b9-a511-4282-ba5d-812e14b07831
OCI - Multiple instances launched
Rule ID: 252e651d-d825-480c-bdeb-8b239354577d
OCI - Multiple instances terminated
Rule ID: 482c24b9-a700-4b2a-85d3-1c42110ba78c
OCI - Multiple rejects on rare ports
Rule ID: e087d4fb-af0b-4e08-a067-b9ba9e5f8840
OCI - SSH scanner
Rule ID: a0b9a7ca-3e6d-4996-ae35-759df1d67a54
OCI - Unexpected user agent
Rule ID: 174de33b-107b-4cd8-a85d-b4025a35453f
Office Apps Launching Wscipt
Rule ID: 30580043-2451-4d35-b49f-065728529f4a
Office ASR rule triggered from browser spawned office process
Rule ID: fbd72eb8-087e-466b-bd54-1ca6ea08c6d3
Office Policy Tampering
Rule ID: 8b4f03e7-3460-4401-824d-e65a8dd464f0
Office365 Sharepoint File transfer above threshold
Rule ID: 8a547285-801c-4290-aa2e-5e7e20ca157d
Office365 Sharepoint File transfer Folders above threshold
Rule ID: 78d2b06c-8dc0-40e1-91c8-66d916c186f3
Okta Fast Pass phishing Detection
Rule ID: dabd7284-004b-4237-b5ee-a22acab19eb2
OLE object manipulation attempts stateful anomaly on database
Rule ID: 3cc5ccd8-b416-4141-bb2d-4eba370e37a5
OMI Vulnerability Exploitation
Rule ID: 6ae36a5e-573f-11ec-bf63-0242ac130002
Oracle - Command in URI
Rule ID: 51d050ee-5740-11ec-bf63-0242ac130002
Oracle - Malicious user agent
Rule ID: 41775080-5740-11ec-bf63-0242ac130002
Oracle - Multiple client errors from single IP
Rule ID: 268f4fde-5740-11ec-bf63-0242ac130002
Oracle - Multiple server errors from single IP
Rule ID: 44c7d12a-573f-11ec-bf63-0242ac130002
Oracle - Multiple user agents for single source
Rule ID: 67950168-5740-11ec-bf63-0242ac130002
Oracle - Oracle WebLogic Exploit CVE-2021-2109
Rule ID: 153ce6d8-5740-11ec-bf63-0242ac130002
Oracle - Private IP in URL
Rule ID: 033e98d2-5740-11ec-bf63-0242ac130002
Oracle - Put file and get file from same IP address
Rule ID: edc2f2b4-573f-11ec-bf63-0242ac130002
Oracle - Put suspicious file
Rule ID: 9cc9ed36-573f-11ec-bf63-0242ac130002
Oracle - Request to sensitive files
Rule ID: e6c5ff42-0f42-4cec-994a-dabb92fe36e1
Oracle suspicious command execution
Rule ID: 54aa2c17-acfd-4e3a-a1c4-99c88cf34ebe
OracleDBAudit - Connection to database from external IP
Rule ID: 80b1dd6d-1aea-471e-be7a-a4a0afdeec80
OracleDBAudit - Connection to database from unknown IP
Rule ID: b3aa0e5a-75a2-4613-80ec-93a1be3aeb8f
OracleDBAudit - Multiple tables dropped in short time
Rule ID: cca7b348-e904-4a7a-8f26-d22d4d477119
OracleDBAudit - New user account
Rule ID: d7fdcad5-ce96-4db6-9a5e-4a86a5166e5e
OracleDBAudit - Query on Sensitive Table
Rule ID: 27cc2cdc-ba67-4906-a6ef-ecbc9c284f4e
OracleDBAudit - Shutdown Server
Rule ID: ab352f0d-7c55-4ab2-a22e-b1c2d995e193
OracleDBAudit - SQL injection patterns
Rule ID: 75024e1c-26e7-4e73-821d-95e5decdd8db
OracleDBAudit - Unusual user activity on multiple tables
Rule ID: 5e93a535-036b-4570-9e58-d8992f30e1ae
OracleDBAudit - User activity after long inactivity time
Rule ID: 39a0995e-f4a9-4869-a0ae-36d6d9049bfd
OracleDBAudit - User connected to database from new IP
Rule ID: c105513d-e398-4a02-bd91-54b9b2d6fa7d
Outgoing connection attempts stateful anomaly on database
Rule ID: 7caa1c03-d20b-42f2-ac95-5232f6e570da
PAC high severity
Rule ID: 5b72f527-e3f6-4a00-9908-8e4fee14da9f
Palo Alto - possible internal to external port scanning
Rule ID: 4d61bb9a-7f6d-45b1-ac0e-517e2a92f6fd
Palo Alto - possible nmap scan on with top 100 option
Rule ID: 2f8522fc-7807-4f0a-b53d-458296edab8d
Palo Alto - potential beaconing detected
Rule ID: f0be259a-34ac-4946-aa15-ca2b115d5feb
Palo Alto - potential beaconing detected
Rule ID: 5180e347-32fb-4a0a-9cfa-d6e0e10fc4eb
Palo Alto Prevention alert
Rule ID: 777d4993-31bb-4d45-b949-84f58e09fa2f
Palo Alto Prisma Cloud - Access keys are not rotated for 90 days
Rule ID: bd602b90-f7f9-4ae9-bf8c-3672a24deb39
Palo Alto Prisma Cloud - Anomalous access key usage
Rule ID: 617b02d8-0f47-4f3c-afed-1926a45e7b28
Palo Alto Prisma Cloud - High risk score alert
Rule ID: c5bf680f-fa37-47c3-9f38-e839a9b99c05
Palo Alto Prisma Cloud - High severity alert opened for several days
Rule ID: ac76d9c0-17a3-4aaa-a341-48f4c0b1c882
Palo Alto Prisma Cloud - IAM Group with Administrator Access Permissions
Rule ID: 7f78fa52-9833-41de-b5c5-76e61b8af9c1
Palo Alto Prisma Cloud - Inactive user
Rule ID: 119a574d-f37a-403a-a67a-4d6f5083d9cf
Palo Alto Prisma Cloud - Maximum risk score alert
Rule ID: 4f688252-bf9b-4136-87bf-d540b5be1050
Palo Alto Prisma Cloud - Multiple failed logins for user
Rule ID: 4264e133-eec2-438f-af85-05e869308f94
Palo Alto Prisma Cloud - Network ACL allow all outbound traffic
Rule ID: df89f4bf-720e-41c5-a209-15e41e400d35
Palo Alto Prisma Cloud - Network ACL allow ingress traffic to server administration ports
Rule ID: 6098b34a-1e6b-440a-9e3b-fb4d5944ade1
Palo Alto Prisma Cloud - Network ACLs Inbound rule to allow All Traffic
Rule ID: 89a86f70-615f-4a79-9621-6f68c50f365f
Palo Alto Threat signatures from Unusual IP addresses
Rule ID: 961672e7-15db-4df1-9bab-dc4f032b9b6f
Palo Alto WildFire Malware Detection
Rule ID: ba663b74-51f4-11ec-bf63-0242ac130002
PaloAlto - Dropping or denying session with traffic
Rule ID: 9150ad68-51c8-11ec-bf63-0242ac130002
PaloAlto - File type changed
Rule ID: 9fcc7734-4d1b-11ec-81d3-0242ac130003
PaloAlto - Forbidden countries
Rule ID: b2dd2dac-51c9-11ec-bf63-0242ac130002
PaloAlto - Inbound connection to high risk ports
Rule ID: 976d2eee-51cb-11ec-bf63-0242ac130002
PaloAlto - MAC address conflict
Rule ID: b6d54840-51d3-11ec-bf63-0242ac130002
PaloAlto - Possible attack without response
Rule ID: feb185cc-51f4-11ec-bf63-0242ac130002
PaloAlto - Possible flooding
Rule ID: 3575a9c0-51c9-11ec-bf63-0242ac130002
PaloAlto - Possible port scan
Rule ID: f12e9d10-51ca-11ec-bf63-0242ac130002
PaloAlto - Put and post method request in high risk file type
Rule ID: 38f9e010-51ca-11ec-bf63-0242ac130002
PaloAlto - User privileges was changed
Rule ID: 2e3c4ad5-8cb3-4b46-88ff-a88367ee7eaa
Password Exfiltration over SCIM application
Rule ID: 5533fe80-905e-49d5-889a-df27d2c3976d
Password spray attack against ADFSSignInLogs
Rule ID: 48607a29-a26a-4abf-8078-a06dbdd174a4
Password spray attack against Microsoft Entra ID application
Rule ID: fb7ca1c9-e14c-40a3-856e-28f3c14ea1ba
Password spray attack against Microsoft Entra ID Seamless SSO
Rule ID: e00f72ab-fea1-4a31-9ecc-eea6397cd38d
Password Spraying
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c02
Pathlock TDnR - ABAP Runtime Dumps
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c01
Pathlock TDnR - ABAP Source Code Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c62
Pathlock TDnR - Authorization Check Value Changes SU24
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c41
Pathlock TDnR - Authorization Profile Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c46
Pathlock TDnR - Authorization Role Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c05
Pathlock TDnR - Bank Master Data Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c06
Pathlock TDnR - Business Partner Bank Data Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c07
Pathlock TDnR - Credit Card Data Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c24
Pathlock TDnR - Critical File Integrity Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c17
Pathlock TDnR - CUA Settings Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c23
Pathlock TDnR - Database Cockpit Audit Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c69
Pathlock TDnR - DDIC Table Utility Changes SE14
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c08
Pathlock TDnR - Debitor Change Documents
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c40
Pathlock TDnR - Dynamic Access Control Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c50
Pathlock TDnR - Emergency User AdminTrack Activity
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c25
Pathlock TDnR - Function Module Tested in Production
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c09
Pathlock TDnR - Generic SAP Change Documents
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c67
Pathlock TDnR - Generic Table Content Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c15
Pathlock TDnR - GL Account Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c65
Pathlock TDnR - Global System Change Setting Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c10
Pathlock TDnR - GRC Access Control Change Documents
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c28
Pathlock TDnR - HANA Standalone DB Connection Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c30
Pathlock TDnR - HR User Master Change Requests
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c11
Pathlock TDnR - IBAN Change Documents
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c32
Pathlock TDnR - ICF Web Service Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c33
Pathlock TDnR - ICM Security Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c36
Pathlock TDnR - J2EE Security Audit Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c35
Pathlock TDnR - J2EE Security Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c12
Pathlock TDnR - Kerberos Keytab Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c58
Pathlock TDnR - LDAP Synchronization Application Log Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c38
Pathlock TDnR - Logical OS Command Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c37
Pathlock TDnR - Missing SAP Security Notes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c73
Pathlock TDnR - Multiple Login Sessions Detected
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c59
Pathlock TDnR - OData Application Log Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c39
Pathlock TDnR - Outbound SAP SMTP Email
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c60
Pathlock TDnR - Outgoing Spool Print Job Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c34
Pathlock TDnR - Pathlock Security Radar Internal Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c14
Pathlock TDnR - Payment Request Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c45
Pathlock TDnR - RFC Connection Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c52
Pathlock TDnR - RiskTrack Audit Results
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c03
Pathlock TDnR - SAP Authorization Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c04
Pathlock TDnR - SAP Batch Job Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c22
Pathlock TDnR - SAP BTP Cloud Foundry Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c20
Pathlock TDnR - SAP Client Configuration Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c21
Pathlock TDnR - SAP Cloud Account Administration Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c54
Pathlock TDnR - SAP Cloud Connector Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c51
Pathlock TDnR - SAP Download Observer Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c27
Pathlock TDnR - SAP HANA Database Audit Trail
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c29
Pathlock TDnR - SAP HANA Parameter Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c31
Pathlock TDnR - SAP HTTP Webserver Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c64
Pathlock TDnR - SAP Instance Profile Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c57
Pathlock TDnR - SAP Public Cloud Security Audit Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c43
Pathlock TDnR - SAP Read Access Logging Audit
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c44
Pathlock TDnR - SAP Read Access Logging Data
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c26
Pathlock TDnR - SAP RFC Gateway Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c49
Pathlock TDnR - SAP Router Log Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c56
Pathlock TDnR - SAP Security Audit Log Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c66
Pathlock TDnR - SAP System Job Monitoring Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c63
Pathlock TDnR - SAP System Log Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c77
Pathlock TDnR - SAP Web Dispatcher HTTP Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c55
Pathlock TDnR - SE16N Direct Table Change Documents
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c61
Pathlock TDnR - Spool Job Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c42
Pathlock TDnR - STRUST PSE Certificate Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c18
Pathlock TDnR - SU24 Table USOBT_C Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c19
Pathlock TDnR - SU24 Table USOBX_C Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c47
Pathlock TDnR - Switchable Authorization Design Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c48
Pathlock TDnR - Switchable Authorization Runtime Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c16
Pathlock TDnR - System Security Policy Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c68
Pathlock TDnR - Table Parameter Setting Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c71
Pathlock TDnR - TMS Transport and Import Events
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c70
Pathlock TDnR - Transaction and Report Statistics
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c53
Pathlock TDnR - User Access Management Password Resets
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c72
Pathlock TDnR - User Authorization Buffer Manipulation
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c74
Pathlock TDnR - User Master Data Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c75
Pathlock TDnR - User-Profile Assignment Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c76
Pathlock TDnR - User-Role Assignment Changes
Rule ID: 2a3b4c5d-6e7f-4a0b-8c1d-2e3f4a5b6c13
Pathlock TDnR - Vendor Change Documents
Rule ID: 0457b577-3864-42c9-9779-1c9441d86429
PCI App with Open Findings Before Audit Window
Rule ID: f68a5046-b7eb-4f69-9519-1e99708bb9e0
PE file dropped in Color Profile Folder
Rule ID: 2fed0668-6d43-4c78-87e6-510f96f12145
Phishing link click observed in Network Traffic
Rule ID: 7d7e20f8-3384-4b71-811c-f5e950e8306c
PIM Elevation Request Rejected
Rule ID: e45a7334-2cb4-4690-8156-f02cac73d584
Ping Federate - Abnormal password reset attempts
Rule ID: 6145efdc-4724-42a6-9756-5bd1ba33982e
Ping Federate - Abnormal password resets for user
Rule ID: 30583ed4-d13c-43b8-baf2-d75fbe727210
Ping Federate - Authentication from new IP
Rule ID: 14042f74-e50b-4c21-8a01-0faf4915ada4
Ping Federate - Forbidden country
Rule ID: 05282c91-7aaf-4d76-9a19-6dc582e6a411
Ping Federate - New user SSO success login
Rule ID: 85f70197-4865-4635-a4b2-a9c57e8fea1b
Ping Federate - OAuth old version
Rule ID: 2d201d21-77b4-4d97-95f3-26b5c6bde09f
Ping Federate - Password reset request from unexpected source IP address
Rule ID: fddd3840-acd2-41ed-94d9-1474b0a7c8a6
Ping Federate - SAML old version
Rule ID: 9578ef7f-cbb4-4e9a-bd26-37c15c53b413
Ping Federate - Unexpected authentication URL
Rule ID: 64e65105-c4fc-4c28-a4e9-bb1a3ce7652d
Ping Federate - Unexpected country for user
Rule ID: dc79de7d-2590-4852-95fb-f8e02b34f4da
Ping Federate - Unusual mail domain
Rule ID: a7d3f642-15d8-4e83-99ee-83ca3352525d
PLC Stop Command Microsoft Defender for IoT
Rule ID: f9df500a-e2a4-4104-a517-dc1d85bb654f
PLC unsecure key state Microsoft Defender for IoT
Rule ID: b2c5907b-1040-4692-9802-9946031017e8
Port Scan
Rule ID: 427e4c9e-8cf4-4094-a684-a2d060dbca38
Port Scan Detected
Rule ID: 1da9853f-3dea-4ea9-b7e5-26730da3d537
Port scan detected ASIM Network Session schema
Rule ID: 720335f4-ee8c-4270-9424-d0859222168c
Port Sweep
Rule ID: 16daa67c-b137-48dc-8eb7-76598a44791a
Possible AiTM Phishing Attempt Against Microsoft Entra ID
Rule ID: 4acd3a04-2fad-4efc-8a4b-51476594cec4
Possible contact with a domain generated by a DGA
Rule ID: 6c3a1258-bcdd-4fcd-b753-1a9bc826ce12
Possible Phishing with CSL and Network Sessions
Rule ID: 2937bc6b-7cda-4fba-b452-ea43ba8e835f
Possible Resource-Based Constrained Delegation Abuse
Rule ID: fa00014c-c5f4-4715-8f5b-ba567e19e41e
Possible SignIn from Azure Backdoor
Rule ID: fcb9d75c-c3c1-4910-8697-f136bfef2363
Potential beaconing activity ASIM Network Session schema
Rule ID: 5ef06767-b37c-4818-b035-47de950d0046
Potential Build Process Compromise
Rule ID: 1bf6e165-5e32-420e-ab4f-0da8558a8be2
Potential Build Process Compromise - MDE
Rule ID: 9176b18f-a946-42c6-a2f6-0f6d17cd6a8a
Potential communication with a Domain Generation Algorithm DGA based hostname ASIM Web Session schema
Rule ID: a0907abe-6925-4d90-af2b-c7e89dc201a6
Potential DGA detected
Rule ID: 983a6922-894d-413c-9f04-d7add0ecc307
Potential DGA detected ASIM DNS Schema
Rule ID: 01191239-274e-43c9-b154-3a042692af06
Potential DGADomain Generation Algorithm detected via Repetitive Failures - Anomaly based ASIM DNS Solution
Rule ID: 89ba52fa-96a7-4653-829a-ca49bb13336c
Potential DGADomain Generation Algorithm detected via Repetitive Failures - Static threshold based ASIM DNS Solution
Rule ID: 57e56fc9-417a-4f41-a579-5475aea7b8ce
Potential DHCP Starvation Attack
Rule ID: 56f3f35c-3aca-4437-a1fb-b7a84dc4af00
Potential Fodhelper UAC Bypass
Rule ID: ac9e233e-44d4-45eb-b522-6e47445f6582
Potential Fodhelper UAC Bypass ASIM Version
Rule ID: 1572e66b-20a7-4012-9ec4-77ec4b101bc8
Potential Kerberoasting
Rule ID: 64d16e62-1a17-4a35-9ea7-2b9fe6f07118
Potential Password Spray Attack
Rule ID: e27dd7e5-4367-4c40-a2b7-fcd7e7a8a508
Potential Password Spray Attack
Rule ID: 6a2e2ff4-5568-475e-bef2-b95f12b9367b
Potential Password Spray Attack Uses Authentication Normalization
Rule ID: 4bd9ce9d-8586-4beb-8fdb-bd018cacbe7d
Potential Ransomware activity related to Cobalt Strike
Rule ID: 720d12c6-a08c-44c4-b18f-2236412d59b0
Potential re-named sdelete usage
Rule ID: 5b6ae038-f66e-4f74-9315-df52fd492be4
Potential re-named sdelete usage ASIM Version
Rule ID: d2e8fd50-8d66-11ec-b909-0242ac120002
Potential Remote Desktop Tunneling
Rule ID: 7ec1e61d-f3b7-4f40-bb1a-357a63913c23
Power Apps - App activity from unauthorized geo
Rule ID: 943acfa0-9285-4eb0-a9c0-42e36177ef19
Power Apps - Bulk sharing of Power Apps to newly created guest users
Rule ID: ed88638d-8627-4c20-ba08-67c13807a9b1
Power Apps - Multiple apps deleted
Rule ID: 4bd7e93a-0646-4e02-8dcb-aa16d16618f4
Power Apps - Multiple users access a malicious link after launching new app
Rule ID: b1e11b8c-545a-4dea-a912-0008e160d183
Power Automate - Departing employee flow activity
Rule ID: 56cb646e-56a0-4f0e-8866-9bc1dd15da78
Power Automate - Unusual bulk deletion of flow resources
Rule ID: 71d829d6-eb50-4a17-8a64-655fae8d71e1
Power Platform - Account added to privileged Microsoft Entra roles
Rule ID: 886a5655-3d12-42f1-8927-4095789c575e
Power Platform - Connector added to a sensitive environment
Rule ID: 1b2e6172-85c5-417a-90c3-7cc80cb787f5
Power Platform - DLP policy updated or removed
Rule ID: 54d48840-1c64-4399-afee-ad39a069118d
Power Platform - Possibly compromised user accesses Power Platform services
Rule ID: ef88eb96-861c-43a0-ab16-f3835a97c928
Powershell Empire Cmdlets Executed in Command Line
Rule ID: 7b2f4d1a-9c3e-4f72-8b1d-3e6a9f2c4b8d
PowerShell Encoded Command Execution Living off the Land
Rule ID: e06b913f-7698-4b2c-96e6-d47a9f4f5de8
Preferred Networks Deleted
Rule ID: bca9c877-2afc-4246-a26d-087ab1cdcd5f
Prestige ransomware IOCs Oct 2022
Rule ID: b97e118c-b7fa-42a6-84de-2e13443fbb8f
Preview - TI map Domain entity to Cloud App Events
Rule ID: 47b9bb10-d216-4359-8cef-08ca2c67e5be
Preview - TI map Email entity to Cloud App Events
Rule ID: 4e0a6fc8-697e-4455-be47-831b41ea91ac
Preview - TI map IP entity to Cloud App Events
Rule ID: e8ae92dd-1d41-4530-8be8-85c5014c7b47
Preview - TI map URL entity to Cloud App Events
Rule ID: 0433c8a3-9aa6-4577-beef-2ea23be41137
Privileged Account Permissions Changed
Rule ID: 34c5aff9-a8c2-4601-9654-c7e46342d03b
Privileged Accounts - Sign in Failure Spikes
Rule ID: 72891de4-da70-44e4-9984-35fcea98d000
Privileged Machines Exposed to the Internet
Rule ID: 269435e3-1db8-4423-9dfc-9bf59997da1c
Privileged Role Assigned Outside PIM
Rule ID: 55073036-bb86-47d3-a85a-b113ac3d9396
Privileged User Logon from new ASN
Rule ID: c63ae777-d5e0-4113-8c9a-c2c9d3d09fcd
Probable AdFind Recon Tool Usage
Rule ID: 45076281-35ae-45e0-b443-c32aa0baf965
Probable AdFind Recon Tool Usage Normalized Process Events
Rule ID: fdbcc0eb-44fb-467e-a51d-a91df0780a81
Process Creation with Suspicious CommandLine Arguments
Rule ID: d6190dde-8fd2-456a-ac5b-0a32400b0464
Process executed from binary hidden in Base64 encoded file
Rule ID: 2c55fe7a-b06f-4029-a5b9-c54a2320d7b8
Process Execution Frequency Anomaly
Rule ID: 3fa85f64-5717-4562-b3fc-2c963f66afa6
Process-Level Anomaly
Rule ID: b300c7f8-dc5e-4fc6-879b-63f0013358ce
PROD TM0011 - GROUP - Added to Group Outside the Object Tier Level
Rule ID: b58adf25-fb44-4296-9b6c-0e6b97139dad
PROD TM0021 - OBJECT - Created or Deleted a Tier Level Object
Rule ID: 1d858e12-777d-4156-b0af-b5ef410739e6
PROD TM0031 - OBJECT - Moved or Recovered a Tier Level Account
Rule ID: 1da0cf44-c927-4b6f-9b43-91871b2391b3
PROD TM0041 - OBJECT - Enabled Disabled Unlocked or Password Reset of a Tier Level Object
Rule ID: 02cf2172-0eb7-4a4a-bce7-7251cdd3e233
PROD TM0051 - GPO - Linked Unlinked or Enforced at Tier Level OU
Rule ID: f3e2433b-6456-4009-a1cb-0d4eb3a36125
PROD TM0061 - ACL - Modified at Tier Level OU
Rule ID: 4e027b5f-fc4a-4de6-be24-3eb9324e2fc8
PROD TM0071 - OU - Created or Deleted at Tier Level
Rule ID: fe468726-b1dc-4e76-adad-3480de4a2c56
PROD TM0081 - GPO - Linked Unlinked or Enforced at Root of Domain
Rule ID: 7437402c-800b-4cf3-90d9-0c1f12204375
PROD TM0091 - ACL - Modified at Root of the Domain
Rule ID: eea9c640-afe0-4ce4-9a41-c409d4c2c924
PROD TM0101 - BITLOCKER - Stored Bitlocker Recovery Key to Tier Level Computer Object
Rule ID: daf2b9f7-dcf2-4b45-831a-d7142318c7e9
PROD TM0111 - LAPS - Tier Level Computer Object LAPS Password Expiration Time Set Manually
Rule ID: 05846968-15cc-4309-bddc-eaa296f84af1
PROD TM0121 - GPO - Enforced Outside of Tier Model
Rule ID: 17371300-904a-4af5-9550-cf57ee727bb7
PROD TM0131 - OU - Block Inheritance was Enabled on an OU
Rule ID: 38f2f6f4-2869-401c-8341-e3a5c11018a5
PROD TM0141 - GPO - Linked Unlinked or Enforced at the AD Site Level
Rule ID: a9f94bf1-856e-40ff-a176-24f967da1e27
PROD TM0151 - ACL - Modified at KRBTGT or AdminSDHolder Object Level
Rule ID: 763fc00b-4971-43c2-9cd1-f12b58a542bd
PROD TM0161 - GROUP - Added to Well-Known or Tier Model Group
Rule ID: 634a69b4-0e46-4349-8463-af1c8d191620
PROD TM0171 - GROUP - Tier 0 Added to Allow RODC Password Replication Group
Rule ID: ff1bec81-e241-44bf-98ed-c6e37805a2e3
PROD TM0181 - DOMAIN - Child Domain promoted within the Forest
Rule ID: 891315d2-e080-4ac8-af5a-50bae17f2d4d
PROD TM0191 - TRUST - A new AD Trust has been established
Rule ID: 5da571b5-54f6-42c2-8c3e-27edd987ceec
PRODAFT USTA - Compromised credential used in successful sign-in
Rule ID: 9ad6cf22-ffbb-4422-9933-9bbd0104f818
PRODAFT USTA - Corporate credential compromised
Rule ID: 674429c9-a858-436c-95b8-5808024ebd01
PRODAFT USTA - Non-expired payment card exposed
Rule ID: bd550c7f-5455-48de-b23d-30fced82d02b
PRODAFT USTA - Payment card exposed
Rule ID: c6f85aff-4ef0-4fde-b90e-e0ba1a9c3df6
PRODAFT USTA - TI map Domain to DnsEvents
Rule ID: 9c2cef4e-c3a3-4be9-8923-a2f820d4face
PRODAFT USTA - TI map File Hash to CommonSecurityLog
Rule ID: 99ae4d06-d352-4926-a1d7-9c28e25b1313
PRODAFT USTA - TI map URL to Syslog
Rule ID: 9bd18b63-f1ca-4375-95db-39fda00bfe20
Progress MOVEIt File transfer above threshold
Rule ID: 26a993ca-0a96-45a0-8405-05a210fb98f8
Progress MOVEIt File transfer folder count above threshold
Rule ID: eb68b129-5f17-4f56-bf6d-dde48d5e615a
ProofpointPOD - Binary file in attachment
Rule ID: 35a0792a-1269-431e-ac93-7ae2980d4dde
ProofpointPOD - Email sender in TI list
Rule ID: fff36bdc-279d-48c2-8c07-eb19ec83262b
ProofpointPOD - Email sender in TI list
Rule ID: 186cef98-4580-4d59-85f3-9fad5c40c71d
ProofpointPOD - Email sender IP in TI list
Rule ID: 78979d32-e63f-4740-b206-cfb300c735e0
ProofpointPOD - Email sender IP in TI list
Rule ID: c7cd6073-6d2c-4284-a5c8-da27605bdfde
ProofpointPOD - High risk message not discarded
Rule ID: bda5a2bd-979b-4828-a91f-27c2a5048f7f
ProofpointPOD - Multiple archived attachments to the same recipient
Rule ID: d1aba9a3-5ab1-45ef-8ed4-da57dc3c0d32
ProofpointPOD - Multiple large emails to the same recipient
Rule ID: f8127962-7739-4211-a4a9-390a7a00e91f
ProofpointPOD - Multiple protected emails to unknown recipient
Rule ID: aedc5b33-2d7c-42cb-a692-f25ef637cbb1
ProofpointPOD - Possible data exfiltration to private email
Rule ID: f6a51e2c-2d6a-4f92-a090-cfb002ca611f
ProofpointPOD - Suspicious attachment
Rule ID: 56b0a0cd-894e-4b38-a0a1-c41d9f96649a
ProofpointPOD - Weak ciphers
Rule ID: 5fda37e0-d67c-4e8d-b277-90e5eac2172c
Protection Group Deleted
Rule ID: e9b9efa5-4e19-4716-840b-51ef2feeaad1
Protection Group Settings Updated
Rule ID: d0c82b7f-40b2-4180-a4d6-7aa0541b7599
PulseConnectSecure - CVE-2021-22893 Possible Pulse Connect Secure RCE Vulnerability Attack
Rule ID: 1fa1528e-f746-4794-8a41-14827f4cb798
PulseConnectSecure - Large Number of Distinct Failed User Logins
Rule ID: 34663177-8abf-4db1-b0a4-5683ab273f44
PulseConnectSecure - Potential Brute Force Attempts
Rule ID: c317b007-84e7-4449-93f4-4444f6638fd0
Pure Controller Failed
Rule ID: ed32b115-5001-43a7-a2bb-f53026db4d97
Pure Failed Login
Rule ID: 47c02e21-3949-4e05-a28e-576cd75ff6f6
Qakbot Campaign Self Deletion
Rule ID: ba9db6b2-3d05-42ae-8aee-3a15bbe29f27
Qakbot Discovery Activies
Rule ID: 97ad71ed-e4c0-4f7a-b1a2-683108bece4f
Quokka - Malicious Results Detected
Rule ID: 6c028ebd-03ca-41cb-bce7-5727ddb43731
Radiflow - Exploit Detected
Rule ID: cde00cc5-5841-4aa9-96c5-dd836f9e3f26
Radiflow - Network Scanning Detected
Rule ID: 8177ecff-30a1-4d4f-9a82-7fbb69019504
Radiflow - New Activity Detected
Rule ID: ff0c781a-b30f-4acf-9cf1-75d7383d66d1
Radiflow - Platform Alert
Rule ID: a3f4cc3e-2403-4570-8d21-1dedd5632958
Radiflow - Policy Violation Detected
Rule ID: ecac26b8-147d-478a-9d50-99be4bf14019
Radiflow - Suspicious Malicious Activity Detected
Rule ID: 4d90d485-6d47-417e-80ea-9cf956c1a671
Radiflow - Unauthorized Command in Operational Device
Rule ID: cc33e1a9-e167-460b-93e6-f14af652dbd3
Radiflow - Unauthorized Internet Access
Rule ID: 7a075edf-1cf2-4038-ba9c-c354db6409de
Ransom Protect Detected a Ransomware Attack
Rule ID: d5d4766b-e547-44da-9d85-48ff393db201
Ransom Protect User Blocked
Rule ID: 6c8770fb-c854-403e-a64d-0293ba344d5f
Ransomware Attack Detected
Rule ID: 0c96a5a2-d60d-427d-8399-8df7fe8e6536
Ransomware Client Blocked
Rule ID: 957cb240-f45d-4491-9ba5-93430a3c08be
Rare and potentially high-risk Office operations
Rule ID: 83ba3057-9ea3-4759-bf6a-933f2e5bc7ee
Rare application consent
Rule ID: 15ae38a2-2e29-48f7-883f-863fb25a5a06
Rare client observed with high reverse DNS lookup count
Rule ID: 0fe6bde4-b215-480c-99b4-84a96edcdbd7
Rare client observed with high reverse DNS lookup count - Anomaly based ASIM DNS Solution
Rule ID: 77b7c820-5f60-4779-8bdb-f06e21add5f1
Rare client observed with high reverse DNS lookup count - Static threshold based ASIM DNS Solution
Rule ID: 91a451e3-178f-41b2-9e5d-da97d75b9971
Rare Process as a Service
Rule ID: 45b903c5-6f56-4969-af10-ae62ac709718
Rare RDP Connections
Rule ID: 23de46ea-c425-4a77-b456-511ae4855d69
Rare subscription-level operations in Azure
Rule ID: 69a45b05-71f5-45ca-8944-2e038747fb39
RDP Nesting
Rule ID: 0aded97e-4e2d-4e4d-93cf-4a7e45c7bab3
Recorded Future Alerts Incident Creation
Rule ID: b1c2d3e4-5678-90ab-cdef-444444444444
Recorded Future Identity - Credential Exposure Detected
Rule ID: 0aded97e-4e2d-4e4d-93cf-4a7e45c7bab2
Recorded Future Playbook Alerts Incident Creation
Rule ID: a1b2c3d4-5678-90ab-cdef-222222222222
Recorded Future Sandbox - Malicious Email Attachment
Rule ID: a1b2c3d4-5678-90ab-cdef-333333333333
Recorded Future Sandbox - Malicious File in Storage Account
Rule ID: acbf7ef6-f964-44c3-9031-7834ec68175f
RecordedFuture Threat Hunting Domain All Actors
Rule ID: 6db6a8e6-2959-440b-ba57-a505875fcb37
RecordedFuture Threat Hunting Hash All Actors
Rule ID: e31bc14e-2b4c-42a4-af34-5bfd7d768aea
RecordedFuture Threat Hunting IP All Actors
Rule ID: 3f6f0d1a-f2f9-4e01-881a-c55a4a71905b
RecordedFuture Threat Hunting Url All Actors
Rule ID: 9f37ded4-f27a-4ef6-b5e6-de6430070808
Recovery Token Deleted
Rule ID: 6d263abb-6445-45cc-93e9-c593d3d77b89
Red Canary Threat Detection
Rule ID: 8972b513-12a2-4b46-8263-3f091d88a8bc
Red Sift - Email with URL to previously unseen domain
Rule ID: c3d4e5f6-a7b8-9012-cdef-123456789012
Red Sift - Login from previously unseen IP address
Rule ID: 16f26d2c-6296-490b-af4f-b30bcf1c4461
Red Sift - MFA disabled on account
Rule ID: 6e0b70d4-0ab8-480e-9707-8ad45fc21a65
Red Sift - New email with URL from previously unseen sender
Rule ID: 6084dfd8-830b-4839-9a9c-5f08cc984729
Red Sift - New email with URL from previously unseen source
Rule ID: 642de064-c67b-4eb7-98bd-3f8cd51f282c
Refactor AWS policy based on activities in the last 60 days
Rule ID: 08706063-c15e-4d96-beae-9e8d92ccefbb
Registries Alerts for Prancer
Rule ID: c61ad0ac-ad68-4ebb-b41a-74296d3e0044
Registry Persistence via AppCert DLL Modification
Rule ID: 9367dff0-941d-44e2-8875-cb48570c7add
Registry Persistence via AppInit DLLs Modification
Rule ID: 36fbd4e7-5630-4414-aa42-702a7fdded21
Regsvr32 Rundll32 Image Loads Abnormal Extension
Rule ID: 2624fc55-0998-4897-bb48-1c6422befce4
Regsvr32 Rundll32 with Anomalous Parent Process
Rule ID: b7dc801e-1e79-48bb-91e8-2229a8e6d40b
Remote Desktop Network Brute force ASIM Network Session schema
Rule ID: cc46e76c-0d04-40b0-9c8b-929aa40513e7
Remote Desktop Protocol - SharpRDP
Rule ID: 35ab0d58-baab-4154-87ed-fa2f69797e9e
Remote File Creation with PsExec
Rule ID: A22B2ECF-1478-4400-877E-07A32E53A897
Removable storage ONLINE event from secRMM
Rule ID: 335ddff8-b615-42cd-b593-86e419b45d78
Rename System Utilities
Rule ID: 4d500e6d-c984-43a3-9f39-7edec8dcc04d
Request for single resource on domain
Rule ID: 9851c360-5fd5-4bae-a117-b66d8476bf5e
Response rows stateful anomaly on database
Rule ID: c4c6cb50-9fc3-4ca9-a2df-22d527240309
Restore Point Marked as Clean
Rule ID: bad9d4b8-41cb-41ba-82c8-e20e771b3440
Restore Point Marked as Infected
Rule ID: 042f2801-a375-4cfd-bd29-041fc7ed88a0
Risky user signin observed in non-Microsoft network device
Rule ID: 488c759d-a82e-44cd-91bb-d766573918d7
RSA ID Plus - Locked Administrator Account Detected
Rule ID: 54c70d21-696f-4f03-9238-9d7118d079fe
Rubrik Critical Anomaly
Rule ID: 0083cbc4-776e-42ca-8694-6950fd605df9
Rubrik Threat Monitoring
Rule ID: baedfdf4-7cc8-45a1-81a9-065821628b83
RunningRAT request parameters
Rule ID: 08330c3d-487e-4f5e-a539-1e7d06dea786
SailPointIdentityNowAlertForTriggers
Rule ID: 48bb92e2-bad4-4fd4-9684-26cb188299b7
SailPointIdentityNowEventType
Rule ID: 2151e8ea-4838-4c74-be12-4d6a950dde7a
SailPointIdentityNowEventTypeTechnicalName
Rule ID: c3835197-fd07-447e-a0ac-7540d51a1f64
SailPointIdentityNowFailedEvents
Rule ID: 175b79ef-0fc3-4b27-b92a-89b2db6c85c2
SailPointIdentityNowFailedEventsBasedOnTime
Rule ID: 2a215222-bfc5-4858-a530-6d4088ebfa15
SailPointIdentityNowUserWithFailedEvent
Rule ID: 215e89ca-cdbc-4661-b8b2-7041f6ecc7fb
Samsung Knox - Application Privilege Escalation or Change Events
Rule ID: fae7e371-aee8-4d3f-8311-2255a45a30b3
Samsung Knox - Mobile Device Boot Compromise Events
Rule ID: fbff0a97-1972-4df8-a78c-254ccb9879ef
Samsung Knox - Password Lockout Events
Rule ID: cd526f4d-dbe9-4149-8a0a-9ec43c3abb16
Samsung Knox - Peripheral Access Detection with Camera Events
Rule ID: e4032fd2-4d05-4302-b7c0-f3f0380e2313
Samsung Knox - Peripheral Access Detection with Mic Events
Rule ID: bf9be360-7f08-48b2-8e9d-ca240c48b404
Samsung Knox - Security Log Full Events
Rule ID: 18d4d4f3-6605-4fd2-968c-82c171409c1c
Samsung Knox - Suspicious URL Accessed Events
Rule ID: 8a3b5c7d-9e1f-4a2b-8c6d-3e5f7a9b1c2d
SAP BTP - Audit log service unavailable
Rule ID: 8e5f3a2c-9d1b-4c6e-a7f8-3b2d1e0c9a5f
SAP BTP - Build Work Zone unauthorized access and role tampering
Rule ID: 3f8a2c5e-7b9d-4e1a-8f6c-2d4b9a1e3c7f
SAP BTP - Cloud Identity Service application configuration monitor
Rule ID: 9e6f4b2c-0d3e-5a8f-c9b7-2f5d8a1e4c6b
SAP BTP - Cloud Integration access policy tampering
Rule ID: a1b2c3d4-5e6f-7a8b-9c0d-1e2f3a4b5c6d
SAP BTP - Cloud Integration artifact deployment
Rule ID: b2c3d4e5-6f7a-8b9c-0d1e-2f3a4b5c6d7e
SAP BTP - Cloud Integration JDBC data source changes
Rule ID: c3d4e5f6-7a8b-9c0d-1e2f-3a4b5c6d7e8f
SAP BTP - Cloud Integration package import or transport
Rule ID: 8d5f3a1b-9c2e-4f7d-b8a6-1e4c7f9d2b5a
SAP BTP - Cloud Integration tampering with security material
Rule ID: 74b243a6-3046-48aa-8b03-e43b3c529cc1
SAP BTP - Failed access attempts across multiple BAS subaccounts
Rule ID: 31997e9a-7447-47f3-8208-4f5d7efe497c
SAP BTP - Malware detected in BAS dev space
Rule ID: 6f1e58bd-cd95-4dfb-8883-94207f30929a
SAP BTP - Mass user deletion in a sub account
Rule ID: a3b8e7c4-5f2d-4a1e-9c6b-8d7f3e2a1b0c
SAP BTP - Mass user deletion in Cloud Identity Service
Rule ID: 62357c23-ecdc-4edc-9349-8338063af1ef
SAP BTP - Trust and authorization Identity Provider monitor
Rule ID: 5e8f2a1b-7c3d-4b9e-a6f0-1d2e3c4b5a6f
SAP BTP - Unaudited custom app with login-only activity
Rule ID: 7d4e9f2a-8b1c-4a5d-9e3f-6c2b1a0d8e7f
SAP BTP - User added to Cloud Identity Service privileged Administrators list
Rule ID: 5acbe4cb-a379-4acc-9ad3-28dc48ad33d3
SAP BTP - User added to sensitive privileged role collection
Rule ID: c6111e06-11e2-45eb-86ef-28313a06db35
SAP ETD - Execution of Sensitive Function Module
Rule ID: 5dd72ebe-03ac-43ac-851b-68cfe5106e4f
SAP ETD - Login from unexpected network
Rule ID: a9206c5a-3e72-4c10-807f-313a56075b20
SAP ETD - No new data received
Rule ID: b1413b43-9410-46f4-94d9-da507105d834
SAP ETD - SAP system stopped reporting data
Rule ID: 7a830484-e349-4527-85f6-7850c468c238
SAP ETD - Synch alerts
Rule ID: 5096db53-fad3-4844-a264-246f7b7e6e06
SAP ETD - Synch investigations
Rule ID: 4981469b-8618-43a7-b44c-5744594fa494
SAP LogServ - HANA DB - Assign Admin Authorizations
Rule ID: e8394afb-82a7-4718-8d31-cc57ad352fa8
SAP LogServ - HANA DB - Audit Trail Policy Changes
Rule ID: 8fb9fb88-693f-4906-8be2-4bb9771418fc
SAP LogServ - HANA DB - Deactivation of Audit Trail
Rule ID: a9e4b02a-5a8c-4c59-9836-a204d1028632
SAP LogServ - HANA DB - User Admin actions
Rule ID: 4ae9f294-410d-4c11-9072-0d8fcf5162d8
SAST Auth Finding Correlated with Brute Force
Rule ID: 4dc85727-573c-4722-8173-026e2a1d20db
Scale-Out Backup Repository Deleted
Rule ID: 12006091-95a7-4f21-b474-f74b0480a138
Scale-Out Backup Repository Settings Updated
Rule ID: 6dd2629c-534b-4275-8201-d7968b4fa77e
Scheduled Task Hide
Rule ID: d9f28fdf-abc8-4f1a-a7e7-1aaec87a2fc5
Sdelete deployed via GPO and run recursively
Rule ID: 30c8b802-ace1-4408-bc29-4c5c5afb49e1
Sdelete deployed via GPO and run recursively ASIM Version
Rule ID: a91e677a-46b5-428e-8a7d-29a2bb33bb6f
Secret Exposure with Anomalous SPN Sign-In
Rule ID: 80da0a8f-cfe1-4cd0-a895-8bc1771a720e
Security Event log cleared
Rule ID: 473d57e6-f787-435c-a16b-b38b51fa9a4b
Security Service Registry ACL Modification
Rule ID: 8c5c766a-ce9b-4112-b6ed-1b8fe33733b7
SecurityBridge A critical event occured
Rule ID: cf3ede88-a429-493b-9108-3e46d3c741f7
SecurityEvent - Multiple authentication failures followed by a success
Rule ID: 0e105444-fe13-4ce6-9239-21880076a3f9
Semperis DSP Failed Logons
Rule ID: 9ff3b26b-7636-412e-ac46-072b084b94cb
Semperis DSP Kerberos krbtgt account with old password
Rule ID: 1a6d0a49-64b3-4ca1-96c3-f154c16c218c
Semperis DSP Mimikatzs DCShadow Alert
Rule ID: 8f471e21-3bb2-466f-9bc2-0a0326a60788
Semperis DSP Operations Critical Notifications
Rule ID: e5edf3f3-de53-45e6-b0d7-1ce1c048df4a
Semperis DSP RBAC Changes
Rule ID: 64796da3-6383-4de2-9c97-866c83c459ae
Semperis DSP Recent sIDHistory changes on AD objects
Rule ID: ddd75d93-5b8b-4349-babe-c4e15343c5a3
Semperis DSP Well-known privileged SIDs in sIDHistory
Rule ID: 85c1f9e4-6f14-46bf-82d5-dbe495b92aab
Semperis DSP Zerologon vulnerability
Rule ID: 56910d7b-aae7-452c-a3ed-89f72ef59234
SenservaPro AD Applications Not Using Client Credentials
Rule ID: d6491be0-ab2d-439d-95d6-ad8ea39277c5
Sensitive Azure Key Vault operations
Rule ID: 7ae7e8b0-07e9-43cb-b783-b04082f09060
Sensitive Data Discovered in the Last 24 Hours
Rule ID: 79f296d9-e6e4-45dc-9ca7-1770955435fa
Sensitive Data Discovered in the Last 24 Hours - Customized
Rule ID: 382f37b3-b49a-492f-b436-a4717c8c5c3e
Sentinel One - Admin login from new location
Rule ID: 4ad87e4a-d045-4c6b-9652-c9de27fcb442
Sentinel One - Agent uninstalled from multiple hosts
Rule ID: 5f37de91-ff2b-45fb-9eda-49e9f76a3942
Sentinel One - Alert from custom rule
Rule ID: de339761-2298-4b37-8f1b-80ebd4f0b5f6
Sentinel One - Blacklist hash deleted
Rule ID: 4224409f-a7bf-45eb-a931-922d79575a05
Sentinel One - Exclusion added
Rule ID: 47e427e6-61bc-4e24-8d16-a12871b9f939
Sentinel One - Multiple alerts on host
Rule ID: e73d293d-966c-47ec-b8e0-95255755f12c
Sentinel One - New admin created
Rule ID: e171b587-22bd-46ec-b96c-7c99024847a7
Sentinel One - Rule deleted
Rule ID: 84e210dd-8982-4398-b6f3-264fd72d036c
Sentinel One - Rule disabled
Rule ID: 5586d378-1bce-4d9b-9ac8-e7271c9d5a9a
Sentinel One - Same custom rule triggered on different hosts
Rule ID: 51999097-60f4-42c0-bee8-fa28160e5583
Sentinel One - User viewed agents passphrase
Rule ID: 7bce901b-9bc8-4948-8dfc-8f68878092d5
Server Oriented Cmdlet And User Oriented Cmdlet used
Rule ID: d29cc957-0ddb-4d00-8d6f-ad1bb345ff9a
Service Accounts Performing Remote PS
Rule ID: dd78a122-d377-415a-afe9-f22e08d2112c
Service Principal Assigned App Role With Sensitive Access
Rule ID: 84cccc86-5c11-4b3a-aca6-7c8f738ed0f7
Service Principal Assigned Privileged Role
Rule ID: 1baaaf00-655f-4de9-8ff8-312e902cda71
Service Principal Authentication Attempt from New Country
Rule ID: 875d0eb1-883a-4191-bd0e-dbfdeb95a464
Service Principal Name SPN Assigned to User Account
Rule ID: D308318A-B298-4E57-82BD-74AE33C4A539
Service principal not using client credentials
Rule ID: cbe9fcb2-8767-4965-887e-350710145386
Service Provider Deleted
Rule ID: 35fb4771-9b8f-47f7-bd5b-3085d584f7ce
Service Provider Updated
Rule ID: f8dad4e9-3f19-4d70-ab7f-8f19ccd43a3e
Several deny actions registered
Rule ID: bb6a74c8-889d-4c6e-8412-7d5efe33f4ed
SFTP File transfer above threshold
Rule ID: 7355434e-09d5-4401-b56d-e03e9379dfb1
SFTP File transfer folder count above threshold
Rule ID: 28c63a44-2d35-48b7-831b-3ed24af17c7e
Shadow Copy Deletions
Rule ID: 5dd76a87-9f87-4576-bab3-268b0e2b338b
SharePointFileOperation via devices with previously unseen user agents
Rule ID: 4b11568b-3f5f-4ba1-80c8-7f1dc8390eb7
SharePointFileOperation via previously unseen IPs
Rule ID: 500c103a-0319-4d56-8e99-3cec8d860757
Sign-ins from IPs that attempt sign-ins to disabled accounts
Rule ID: 95002681-4ecb-4da3-9ece-26d7e5feaa33
Sign-ins from IPs that attempt sign-ins to disabled accounts Uses Authentication Normalization
Rule ID: 95a15f39-d9cc-4667-8cdd-58f3113691c9
Silk Typhoon New UM Service Child Process
Rule ID: 23005e87-2d3a-482b-b03d-edbebd1ae151
Silk Typhoon Suspicious Exchange Request
Rule ID: 03e04c97-8cae-48b3-9d2f-4ab262e4ffff
Silk Typhoon Suspicious File Downloads
Rule ID: 0625fcce-6d52-491e-8c68-1d9b801d25b9
Silk Typhoon Suspicious UM Service Error
Rule ID: 9ae540c9-c926-4100-8f07-1eac22596292
Silverfort - Certifried Incident
Rule ID: d6abed70-4043-46da-9304-a98f3446fa5f
Silverfort - Log4Shell Incident
Rule ID: bdfd2c45-10a0-44e7-a90a-ba7b6bdd9ff2
Silverfort - NoPacBreach Incident
Rule ID: 46ff357b-9e98-465b-9e45-cd52fa4a7522
Silverfort - UserBruteForce Incident
Rule ID: bbeb2f26-cb99-4e4b-900f-24ce9809142d
Sites Alerts for Prancer
Rule ID: 04528635-a5f1-438b-ab74-21ca7bc3aa32
SlackAudit - Empty User Agent
Rule ID: 3db0cb83-5fa4-4310-a8a0-d8d66183f0bd
SlackAudit - Multiple archived files uploaded in short period of time
Rule ID: 93a91c37-032c-4380-847c-957c001957ad
SlackAudit - Multiple failed logins for user
Rule ID: 279316e8-8965-47d2-9788-b94dc352c853
SlackAudit - Public link created for file which can contain sensitive information
Rule ID: 132b98a5-07e9-401a-9b6f-453e52a53979
SlackAudit - Suspicious file downloaded
Rule ID: 3b11f06e-4afd-4ae6-8477-c61136619ac8
SlackAudit - Unknown User Agent
Rule ID: 9d85feb3-7f54-4181-b143-68abb1a86823
SlackAudit - User email linked to account changed
Rule ID: e6e99dcb-4dff-48d2-8012-206ca166b36b
SlackAudit - User login after deactivated
Rule ID: be6c5fc9-2ac3-43e6-8fb0-cb139e04e43e
SlackAudit - User role changed to admin or owner
Rule ID: 9da25366-2c77-41a5-a159-0da5e2f5fb90
SMBWindows Admin Shares
Rule ID: 1376f5e5-855a-4f88-8591-19eba4575a0f
Snowflake - Abnormal query process time
Rule ID: 5f8a81d9-7d27-4ff5-a0ce-4285ee02c2c8
Snowflake - Multiple failed queries
Rule ID: e05cc333-d499-430f-907c-7f28a9e4d1b5
Snowflake - Multiple login failures by user
Rule ID: b7d22407-1391-4256-b09a-414a9719443c
Snowflake - Multiple login failures from single IP
Rule ID: c2f93727-e4b0-4cb9-8f80-f52ebbd96ece
Snowflake - Possible data destraction
Rule ID: 09b8dfc7-87b0-4215-b34b-bab363d685cb
Snowflake - Possible discovery activity
Rule ID: 627a4ff1-036b-4375-a9f9-288d5e1d7d37
Snowflake - Possible privileges discovery activity
Rule ID: f258fa0c-e26c-4e2b-94fb-88b6cef0ca6e
Snowflake - Query on sensitive or restricted table
Rule ID: 1dd1d9e5-3ebf-43cb-be07-6082d5eabe79
Snowflake - Unusual query
Rule ID: 5ed33eee-0ab6-4bf5-9e9b-6100db83d39a
Snowflake - User granted admin privileges
Rule ID: 4a7b3c9e-2d15-4e8f-b6a3-9c2e7d5a1b4f
SOCRadar Alarm Volume Spike
Rule ID: 8f3e2c5a-7b91-4d6a-9e8f-1c4a2b5d7e3f
SOCRadar High or Critical Severity Alarm
Rule ID: 6e2f8d4b-5a71-4c9e-b3f6-8a1c9d4e7b2a
SOCRadar Unsynced Closed Incident
Rule ID: e70fa6e0-796a-4e85-9420-98b17b0bb749
Solorigate Defender Detections
Rule ID: 11b4c19d-2a79-4da3-af38-b067e1273dee
Solorigate Named Pipe
Rule ID: 27f1a570-5f20-496b-88f6-a9aa2c5c9534
SonicWall - Allowed SSH Telnet and RDP Connections
Rule ID: 3db9f99e-a459-41e0-8e02-8b332f5fcb2c
SonicWall - Capture ATP Malicious File Detection
Rule ID: 37a8d052-a3db-4dc6-9dca-9390cac6f486
Sonrai Ticket Assigned
Rule ID: f5d467de-b5a2-4b4f-96db-55e27c733594
Sonrai Ticket Closed
Rule ID: 0d29c93e-b83f-4dfb-bbbb-76824b77eeca
Sonrai Ticket Escalation Executed
Rule ID: 822fff15-ea68-4d0f-94ee-b4482ddb6f3a
Sonrai Ticket Escalation Executed
Rule ID: b60129ab-ce22-4b76-858d-3204932a13cc
Sonrai Ticket Reopened
Rule ID: 080191e8-271d-4ae6-85ce-c7bcd4b06b40
Sonrai Ticket Risk Accepted
Rule ID: 10e6c454-5cad-4f86-81ce-800235cb050a
Sonrai Ticket Snoozed
Rule ID: af9b8eb1-a8ef-40aa-92a4-1fc73a1479c7
Sonrai Ticket Updated
Rule ID: a7c3f9e2-4d18-4b6a-9f0c-2e5d8b1a6c43
Speculus - Network traffic to or from high-risk IP indicator
Rule ID: e1b8d4a6-9c27-45f3-8a1e-7f2c0d9b5e64
Speculus - Sign-in attempt from high-risk IP indicator
Rule ID: c4f2a8d1-6e39-4c07-b5a2-1d8e3f7c9a25
Speculus - Threat intelligence feed outage
Rule ID: cb410ad5-6e9d-4278-b963-1e3af205d680
SpyCloud Enterprise Breach Detection
Rule ID: 7ba50f9e-2f94-462b-a54b-8642b8c041f5
SpyCloud Enterprise Malware Detection
Rule ID: cd8ec49c-b654-49be-b040-e552b8eba7c8
SpyCloud identity access record exposure
Rule ID: ead4deed-9d48-4646-aee0-6b46c2dd1ae6
SpyCloud infostealer malware credential exposure
Rule ID: a25eba0e-ff42-4c97-a379-d76bdb2aa1e3
SpyCloud plaintext credential exposure detected
Rule ID: 90d3f6ec-80fb-48e0-9937-2c70c9df9bad
Squid proxy events for ToR proxies
Rule ID: 80733eb7-35b2-45b6-b2b8-3c51df258206
Squid proxy events related to mining pools
Rule ID: d41fa731-45a2-4b23-bb1d-29896fbc5298
SSG_Security_Incidents
Rule ID: e1ce0eab-10d1-4aae-863f-9a383345ba88
SSH - Potential Brute Force
Rule ID: 40b8e739-1077-42d8-9501-b68736c2c4d2
SSH Credentials Changed
Rule ID: 766a3b1b-0d5b-4a8d-b0d6-7dd379e73567
Stale AWS policy attachment to identity
Rule ID: ccdf3f87-7890-4549-9d0f-8f43c1d2751d
Stale IAAS policy attachment to role
Rule ID: 645A8724-5C7E-4A1F-81CB-C33AFF1439EB
Stale last password change
Rule ID: 2149d9bb-8298-444c-8f99-f7bf0274dd05
Star Blizzard C2 Domains August 2022
Rule ID: 2bc7b4ae-eeaa-4538-ba15-ef298ec1ffae
Starting or Stopping HealthService to Avoid Detection
Rule ID: e3a8b2f1-5c7d-4d89-9b6e-0f1a2c3d4e5f
StealthTalk - After hours work
Rule ID: a7c3e9b1-4f5d-4e2a-9b8c-1d2e3f4a5b6c
StealthTalk - Login outside work zone
Rule ID: f9d4c2a8-1b6e-4a3f-9c7d-8e2b1a3c5d7e
StealthTalk - Multi new devices registration
Rule ID: b8e5f3a2-9c4d-4d1f-8a7b-3c2d1e0f9a8b
StealthTalk - Password brute force
Rule ID: 4dd31bd5-11a3-4b9c-a7c5-4927ab4f2a77
Stopping multiple processes using taskkill
Rule ID: 4adf2b5d-6b88-4b96-8cc2-a3c7fbbee10b
Storage Accounts Alerts From Prancer
Rule ID: 7cf8c19b-6cd2-4d0c-814b-45d34e68568b
Storage Deleted
Rule ID: be47e508-e35b-4c63-979b-a75b72102344
Storage Settings Updated
Rule ID: 10be8f37-d83c-4b7e-81c2-1271c51ac09f
Subnets Alerts for Prancer
Rule ID: 48c026d8-7f36-4a95-9568-6f1420d66e37
Subscription moved to another tenant
Rule ID: 1c23715c-3a28-4b98-b135-fece6e7dcb8b
Subtenant Deleted
Rule ID: e1d0d9ce-b7c9-4e28-883d-04429f80d6d7
Subtenant Updated
Rule ID: 188db479-d50a-4a9c-a041-644bae347d1f
Successful AWS Console Login from IP Address Observed Conducting Password Spray
Rule ID: f8e7d6c5-b4a3-4122-8110-0987654321fe
Successful logins to SOC Prime platform from bad IP addresses
Rule ID: 02ef8d7e-fc3a-4d86-a457-650fa571d8d2
Successful logon from IP and failure from a different IP
Rule ID: a3c144f9-8051-47d4-ac29-ffb0c312c910
SUNBURST and SUPERNOVA backdoor hashes
Rule ID: bc5ffe2a-84d6-48fe-bc7b-1055100469bc
SUNBURST and SUPERNOVA backdoor hashes Normalized File Events
Rule ID: ce1e7025-866c-41f3-9b08-ec170e05e73e
SUNBURST network beacons
Rule ID: 4a3073ac-7383-48a9-90a8-eb6716183a54
SUNBURST suspicious SolarWinds child processes
Rule ID: 631d02df-ab51-46c1-8d72-32d0cfec0720
SUNBURST suspicious SolarWinds child processes Normalized Process Events
Rule ID: 53e936c6-6c30-4d12-8343-b8a0456e8429
SUNSPOT malware hashes
Rule ID: 2acc91c3-17c2-4388-938e-4eac2d5894e8
SUPERNOVA webshell
Rule ID: a8f689e5-7f84-4658-b816-75aa94c8b833
SUPERNOVA webshell
Rule ID: b7409bbb-6f0c-43c4-bb63-b20add5eb717
SureBackup Job Failed
Rule ID: cd8d946d-10a4-40a9-bac1-6d0a6c847d65
Suspicious access of BEC related documents
Rule ID: f3e2d35f-1202-4215-995c-4654ef07d1d8
Suspicious access of BEC related documents in AWS S3 buckets
Rule ID: 3533f74c-9207-4047-96e2-0eb9383be587
Suspicious application consent for offline access
Rule ID: f948a32f-226c-4116-bddd-d95e91d97eb9
Suspicious application consent similar to O365 Attack Toolkit
Rule ID: 39198934-62a0-4781-8416-a81265c03fd6
Suspicious application consent similar to PwnAuth
Rule ID: b51fe620-62ad-4ed2-9d40-5c97c0a8231f
Suspicious AWS console logins by credential access alerts
Rule ID: 3a3c6835-0086-40ca-b033-a93bf26d878f
Suspicious Entra ID Joined Device Update
Rule ID: b2c15736-b9eb-4dae-8b02-3016b6a45a32
Suspicious granting of permissions to an account
Rule ID: 1218175f-c534-421c-8070-5dcaabf28067
Suspicious link sharing pattern
Rule ID: 22a320c2-e1e5-4c74-a35b-39fc9cdcf859
Suspicious linking of existing user to external User
Rule ID: defe4855-0d33-4362-9557-009237623976
Suspicious Login from deleted guest account
Rule ID: 6fb1acd5-356d-40f7-9b97-78d993c6a183
Suspicious malware found in the network Microsoft Defender for IoT
Rule ID: 48602a24-67cf-4362-b258-3f4249e55def
Suspicious modification of Global Administrator user properties
Rule ID: ddf7c669-db26-4215-acaf-11e2953a04e6
Suspicious named pipes
Rule ID: 361dd1e3-1c11-491e-82a3-bb2e44ac36ba
Suspicious number of resource creation or deployment activities
Rule ID: 5ee34fa1-64ed-48c7-afa2-794b244f6c60
Suspicious parentprocess relationship - Office child processes
Rule ID: b5153fb3-ada9-4ce4-9131-79c771efb50d
Suspicious Powershell Commandlet Executed
Rule ID: a4d8e681-6f30-440a-a2f3-c312bc1389d0
Suspicious Process Injection from Office application
Rule ID: 9fb57e58-3ed8-4b89-afcf-c8e786508b1c
Suspicious Resource deployment
Rule ID: 6852d9da-8015-4b95-8ecf-d9572ee0395d
Suspicious Service Principal creation activity
Rule ID: 2cd8b3d5-c9e0-4be3-80f7-0469d511c3f6
Suspicious Sign In by Entra ID Connect Sync Account
Rule ID: aec77100-25c5-4254-a20a-8027ed92c46c
Suspicious Sign In Followed by MFA Modification
Rule ID: 1cc0ba27-c5ca-411a-a779-fbc89e26be83
Suspicious VM Instance Creation Activity Detected
Rule ID: 3192085a-e97e-440f-acb7-9227622949a4
Synqly Alert Event
Rule ID: c815008d-f4d1-4645-b13b-8b4bc188d5de
Syntax errors stateful anomaly on database
Rule ID: b2c3d4e5-f6a7-8901-bcde-f23456789012
TacitRed - High Confidence Compromise
Rule ID: a1b2c3d4-e5f6-7890-abcd-ef1234567890
TacitRed - Repeat Compromise Detection
Rule ID: 6b052c8d-5de8-eab0-1956-69a297765a32
Tailscale Auth key created
Rule ID: b1a2c3d4-1234-5678-90ab-cdef12345001
Tailscale Device key expiring within 7 days
Rule ID: c2b3d4e5-2345-6789-01ab-cdef12345002
Tailscale Device started advertising subnet routes
Rule ID: f0a1b2c3-4567-8901-23de-f12345670041
Tailscale Device Tailscale SSH newly enabled
Rule ID: c5d6e7f8-2345-6789-01ab-cdef12345011
Tailscale DNS nameservers modified
Rule ID: f42f2906-c8e6-23d0-e48c-0620e50d5510
Tailscale Exit node advertised or approved
Rule ID: b2c3d4e5-6789-0123-4567-890123450043
Tailscale External shared-in device added
Rule ID: f8a9b0c1-4567-8901-23ab-cdef12345020
Tailscale MagicDNS disabled
Rule ID: f817e2fa-6fa0-fc25-5369-cef9b58771af
Tailscale Mass credential revocation in short window
Rule ID: 668b43fd-cf28-961a-85af-957850df5027
Tailscale New API access token or OAuth client created
Rule ID: 7237a848-30f2-499b-9ad5-024aea1288bd
Tailscale OAuth client or API key created with write scopes
Rule ID: 1e7249c2-1a9d-05fd-45cb-c859eef5b8ae
Tailscale Policy file ACL modified
Rule ID: 0a1c8d12-e7d3-4890-8b89-8d6dbc1be2f0
Tailscale Premium DERP relay traffic surge
Rule ID: d2e3f4a5-2b3c-4d5e-6f7a-8b9c0d1e2f3a
Tailscale Premium Large outbound transfer over tailnet
Rule ID: f4a5b6c7-4d5e-6f7a-8b9c-0d1e2f3a4b5c
Tailscale Premium Mass fan-out from single node
Rule ID: e3f4a5b6-3c4d-5e6f-7a8b-9c0d1e2f3a4b
Tailscale Premium Network flow beaconing detected
Rule ID: b2c3d4e5-6789-0123-45ab-cdef12345031
Tailscale Premium New posture integration added
Rule ID: a1b2c3d4-5678-9012-34ab-cdef12345030
Tailscale Premium Posture integration disabled or removed
Rule ID: a5b6c7d8-5e6f-7a8b-9c0d-1e2f3a4b5c6d
Tailscale Premium Subnet router throughput anomaly
Rule ID: c1d2e3f4-1a2b-3c4d-5e6f-7a8b9c0d1e2f
Tailscale Premium Unexpected exit-node egress
Rule ID: b4c5d6e7-1234-5678-90ab-cdef12345010
Tailscale Split-DNS configuration modified
Rule ID: e9f0a1b2-3456-7890-12cd-ef1234560040
Tailscale Tailnet lock validation failed
Rule ID: a1b2c3d4-5678-9012-3456-789012340042
Tailscale Unauthorized device connected to control plane
Rule ID: d3c4e5f6-3456-7890-12ab-cdef12345003
Tailscale User role elevated to admin or owner
Rule ID: dd9aa0ff-7ac1-4448-879c-e1a18d5890b4
Tanium Threat Response Alerts
Rule ID: 06ba509c-606e-4967-baee-21815ae61f8e
Tape Erase Job Started
Rule ID: ecf98b4a-3986-4739-879d-dd446e839153
Tape Library Deleted
Rule ID: ceb625a3-a8d7-4a42-9ea1-40f01c337ecd
Tape Media Pool Deleted
Rule ID: 19ed623e-1b1c-45e0-ac74-c1e629fbf117
Tape Media Vault Deleted
Rule ID: d92b2d65-1037-41e2-8d04-c18b8403d895
Tape Medium Deleted
Rule ID: fda79d00-9e6a-46f8-b7a2-2bdccd5f598e
Tape Server Deleted
Rule ID: 738702fd-0a66-42c7-8586-e30f0583f8fe
TEARDROP memory-only dropper
Rule ID: 4639bb0a-ca12-4a57-8e53-f61c2c6034d6
Tenablead Active Directory attacks pathways
Rule ID: 861044f3-6eef-4f79-8609-e3764abb02f4
Tenablead DCShadow
Rule ID: 0c8d4de3-adb9-4161-a863-aa1e2c8bd959
Tenablead DCSync
Rule ID: d1abda25-f88a-429a-8163-582533cd0def
Tenablead Golden Ticket
Rule ID: 6405329a-8d20-48f3-aabc-e1b8a745568e
Tenablead Indicators of Attack
Rule ID: 55de1072-e93f-40f9-a14d-f7356d217cf6
Tenablead Indicators of Exposures
Rule ID: 6f7fa5f9-7d21-42c1-bc52-ac355b87c6cf
Tenablead LSASS Memory
Rule ID: 44d74560-0cd1-4e73-a8f5-d16eeeba219e
Tenablead Password Guessing
Rule ID: 2518b57f-1a8b-44ea-935d-7dc1cfe4f918
Tenablead Password issues
Rule ID: 29d350db-0ac0-4f4c-92ff-dac0f6335612
Tenablead Password Spraying
Rule ID: 353d6474-d795-4086-a179-ba1db4d8bbcb
Tenablead privileged accounts issues
Rule ID: 4f8ed6f3-8815-437d-9462-f0def9dc70d6
Tenablead user accounts issues
Rule ID: afec0070-2b46-4366-a272-e2d9cc8a50f2
Tenant Password Changed
Rule ID: da25b390-b97a-4ea4-abe3-5bbd7f90642c
Tenant Quota Changed
Rule ID: 16183d97-c348-4f72-a943-27e80c9dfbd5
Tenant Quota Deleted
Rule ID: c4d891cd-4b22-419c-8f40-7603eb1cc3a3
Tenant Replica Started
Rule ID: ef029652-d004-44e9-a70a-48dd71818aaa
Tenant Replica Stopped
Rule ID: 71711b77-486c-41d0-9de0-dcc411fa7b05
Tenant State Changed
Rule ID: b7fe8f27-7010-404b-aec5-6e5245cea580
The download of potentially risky files from the Discord Content Delivery Network CDN ASIM Web Session
Rule ID: 2ef36aaa-ec4a-473a-9734-f364ce8868f8
Theom - Critical data in API headers or body
Rule ID: 545fdcc7-2123-4b8a-baf6-409f29aad4b1
Theom - Dark Data with large fin value
Rule ID: 65200844-e161-47a7-a103-f61f7e3afe30
Theom - Dev secrets exposed
Rule ID: f2490f5b-269c-471d-9ff4-475f62ea498e
Theom - Dev secrets unencrypted
Rule ID: 0cead100-f6ca-4cbb-989d-424d20705f30
Theom - Financial data exposed
Rule ID: b568d2fb-b73c-4e6a-88db-2093457712af
Theom - Financial data unencrypted
Rule ID: 078b5614-54c7-41a6-8289-5b5870e4c0f9
Theom - Healthcare data exposed
Rule ID: fb1b0deb-2a8f-4d8d-8d9d-0a8d327442e7
Theom - Healthcare data unencrypted
Rule ID: 67b9ff50-5393-49d5-b66f-05b33e2f35d2
Theom - Least priv large value shadow DB
Rule ID: db95655e-bf5c-4c38-9676-501ec1878d4e
Theom - National IDs exposed
Rule ID: a655f6d1-4ffa-4bc9-8b5d-2ec31cad09d4
Theom - National IDs unencrypted
Rule ID: fb7769d0-e622-4479-95b4-f6266a5b41e2
Theom - Overprovisioned Roles Shadow DB
Rule ID: 7cf83fce-276a-4b12-a876-7b1bc0683cd6
Theom - Shadow DB large datastore value
Rule ID: 02bff937-ca52-4f52-a9cd-b826f8602694
Theom - Shadow DB with atypical accesses
Rule ID: 6b93d8b1-40cf-4973-adaa-6f240df21ff1
Theom - Unencrypted public data stores
Rule ID: bb9051ef-0e72-4758-a143-80c25ee452f0
Theom Critical Risks
Rule ID: 74b80987-0a62-448c-8779-47b02e17d3cf
Theom High Risks
Rule ID: d200da84-0191-44ce-ad9e-b85e64c84c89
Theom Insights
Rule ID: cf7fb616-ac80-40ce-ad18-aa18912811f8
Theom Low Risks
Rule ID: 4cb34832-f73a-49f2-8d38-c2d135c5440b
Theom Medium Risks
Rule ID: BFA7EE22-B5A9-42C8-BD50-2E95885640BB
Third party integrated apps
Rule ID: f8960f1c-07d2-512b-9c41-952772d40c84
Threat Connect TI map Domain entity to DnsEvents
Rule ID: d7c575b2-84f5-48cb-92c5-70d7e8246284
Threat Essentials - Mail redirect via ExO transport rule
Rule ID: fa2658fe-3714-4c55-bb12-2b7275c628e8
Threat Essentials - Mass Cloud resource deletions Time Series Anomaly
Rule ID: 199978c5-cd6d-4194-b505-8ef5800739df
Threat Essentials - Multiple admin membership removals from newly created admin
Rule ID: 0a627f29-f0dd-4924-be92-c3d6dac84367
Threat Essentials - NRT User added to Microsoft Entra ID Privileged Groups
Rule ID: b49a1093-cbf6-4973-89ac-2eef98f533c6
Threat Essentials - Time series anomaly for data size transferred to public internet
Rule ID: b09795c9-8dce-47ab-8f75-5a4afb78ef0c
Threat Essentials - User Assigned Privileged Role
Rule ID: 4f7ade3e-7121-5274-83ea-d7ed22a01fea
ThreatConnect TI map Email entity to OfficeActivity
Rule ID: ecb68ce7-c309-59a7-a8de-07ccf2a0ea4f
ThreatConnect TI map Email entity to SigninLogs
Rule ID: ee1fd303-2081-47b7-8f02-e38bfd0868e6
ThreatConnect TI map IP entity to Network Session Events ASIM Network Session schema
Rule ID: 12c3b31b-66a6-53ff-b6ab-6ae45e56dc92
ThreatConnect TI Map URL Entity to OfficeActivity Data
Rule ID: 2d8a60aa-c15e-442e-9ce3-ee924889d2a6
Threats detected by Eset
Rule ID: 64badfab-1dd8-4491-927b-3ca206fa9a17
Threats detected by ESET
Rule ID: a7d2b1e4-dd9c-40fd-9651-1a136eb8f0df
TI Map Domain entity to Cloud App Events
Rule ID: 1546f3b3-de8a-4e62-bfea-815422154981
TI Map Domain Entity to DeviceNetworkEvents
Rule ID: c308b2f3-eebe-4a20-905c-cb8293b062db
TI Map Domain Entity to DeviceNetworkEvents
Rule ID: 999e9f5d-db4a-4b07-a206-29c4e667b7e8
TI map Domain entity to Dns Events ASIM DNS Schema
Rule ID: 7c1ea2e6-6210-412c-92e4-180803a741b4
TI Map Domain entity to Dns Events ASIM DNS Schema
Rule ID: 85aca4d1-5d15-4001-abd9-acb86ca1786a
TI map Domain entity to DnsEvents
Rule ID: 03a8e294-3fc7-4d65-9da2-cff91fb5b6dc
TI Map Domain entity to DnsEvents
Rule ID: 96307710-8bb9-4b45-8363-a90c72ebf86f
TI map Domain entity to EmailEvents
Rule ID: bc3bb047-70b8-4a4b-ac21-e3b1172881a4
TI Map Domain entity to EmailEvents
Rule ID: 87cc75df-d7b2-44f1-b064-ee924edfc879
TI map Domain entity to EmailUrlInfo
Rule ID: b56e2290-c65b-45a5-9636-3651e85bbe5d
TI Map Domain entity to EmailUrlInfo
Rule ID: ec21493c-2684-4acd-9bc2-696dbad72426
TI map Domain entity to PaloAlto
Rule ID: 418192ba-01b8-4be8-89b7-5b5396a9d062
TI Map Domain entity to PaloAlto
Rule ID: dd0a6029-ecef-4507-89c4-fc355ac52111
TI map Domain entity to PaloAlto CommonSecurityLog
Rule ID: 094a4e6e-1a0d-4d49-9d64-cfc3b01a0be1
TI Map Domain entity to PaloAlto CommonSecurityLog
Rule ID: 87890d78-3e05-43ec-9ab9-ba32f4e01250
TI map Domain entity to SecurityAlert
Rule ID: df88b403-1cb9-49ea-a43d-b6613051cf7f
TI Map Domain entity to SecurityAlert
Rule ID: 532f62c1-fba6-4baa-bbb6-4a32a4ef32fa
TI map Domain entity to Syslog
Rule ID: cd19434e-10f2-4e2f-b3c1-ce6f08ac5357
TI Map Domain entity to Syslog
Rule ID: b1832f60-6c3d-4722-a0a5-3d564ee61a63
TI map Domain entity to Web Session Events ASIM Web Session schema
Rule ID: afa4cb9e-6fec-4742-a17f-f494b54c01e7
TI Map Domain entity to Web Session Events ASIM Web Session schema
Rule ID: cca3b4d9-ac39-4109-8b93-65bb284003e6
TI map Email entity to AzureActivity
Rule ID: a9a4d1ee-0f52-4a1f-8def-a2fb4462104c
TI Map Email entity to AzureActivity
Rule ID: 0385e99c-ae45-45f4-aecf-00104485cd6b
TI Map Email entity to Cloud App Events
Rule ID: 11f7c6e3-f066-4b3c-9a81-b487ec0a6873
TI map Email entity to EmailEvents
Rule ID: 18b61c3f-55fa-4eb9-8721-72dabd1eb3cb
TI Map Email entity to EmailEvents
Rule ID: 4a3f5ed7-8da5-4ce2-af6f-c9ada45060f2
TI map Email entity to OfficeActivity
Rule ID: 795d43a3-6edc-4c99-971f-00d05841e5ac
TI Map Email entity to OfficeActivity
Rule ID: ffcd575b-3d54-482a-a6d8-d0de13b6ac63
TI map Email entity to PaloAlto CommonSecurityLog
Rule ID: 17fe80fe-072f-44d4-b62c-97a5bce56a64
TI Map Email entity to PaloAlto CommonSecurityLog
Rule ID: a2e36ce0-da4d-4b6e-88c6-4e40161c5bfc
TI map Email entity to SecurityAlert
Rule ID: 4b451ade-ed28-48e2-8fe7-60ae83ab2fa5
TI Map Email entity to SecurityAlert
Rule ID: 2fc5d810-c9cc-491a-b564-841427ae0e50
TI map Email entity to SecurityEvent
Rule ID: 0a59051d-aed4-4fb6-bf84-bc80534482b2
TI Map Email entity to SecurityEvent
Rule ID: 30fa312c-31eb-43d8-b0cc-bcbdfb360822
TI map Email entity to SigninLogs
Rule ID: 4b5a7f32-899d-4d22-8de2-0ec90b911a72
TI Map Email entity to SigninLogs
Rule ID: 5d33fc63-b83b-4913-b95e-94d13f0d379f
TI map File Hash to CommonSecurityLog Event
Rule ID: 432996e9-8a93-4407-985f-13707b318a0b
TI Map File Hash to CommonSecurityLog Event
Rule ID: bc0eca2e-db50-44e6-8fa3-b85f91ff5ee7
TI map File Hash to DeviceFileEvents Event
Rule ID: d6f04915-4471-4cb3-b163-a8b72997cf72
TI Map File Hash to DeviceFileEvents Event
Rule ID: a7427ed7-04b4-4e3b-b323-08b981b9b4bf
TI map File Hash to Security Event
Rule ID: 9f7dc779-1e51-4925-ae4a-db1db933077f
TI Map File Hash to Security Event
Rule ID: f9949656-473f-4503-bf43-a9d9890f7d08
TI map IP entity to AppServiceHTTPLogs
Rule ID: 206277b1-9a2c-4c62-9ee8-a4c888810d3c
TI Map IP entity to AppServiceHTTPLogs
Rule ID: f110287e-1358-490d-8147-ed804b328514
TI map IP entity to AWSCloudTrail
Rule ID: 69f55be4-1b13-42d0-b975-a1e59c996dd2
TI Map IP entity to AWSCloudTrail
Rule ID: 57c7e832-64eb-411f-8928-4133f01f4a25
TI map IP entity to Azure Key Vault logs
Rule ID: 7c8051a7-3d29-4c0d-a340-893423f7b0a5
TI Map IP entity to Azure Key Vault logs
Rule ID: 239d987e-ee1b-4c49-b146-e88d682930a4
TI Map IP Entity to Azure SQL Security Audit Events
Rule ID: d0aa8969-1bbe-4da3-9e76-09e5f67c9d85
TI Map IP Entity to Azure SQL Security Audit Events
Rule ID: 2441bce9-02e4-407b-8cc7-7d597f38b8b0
TI Map IP Entity to AzureActivity
Rule ID: 7a0c9989-1618-4126-9290-fb77b976d181
TI Map IP Entity to AzureActivity
Rule ID: 0b904747-1336-4363-8d84-df2710bfe5e7
TI map IP entity to AzureFirewall
Rule ID: 4992d2f3-d6c0-4271-adac-b23532ba4492
TI Map IP entity to AzureFirewall
Rule ID: a4025a76-6490-4e6b-bb69-d02be4b03f07
TI map IP entity to AzureNetworkAnalytics_CL NSG Flow Logs
Rule ID: 929160b7-4449-4307-a3f9-bb742d1b8f01
TI Map IP entity to AzureNetworkAnalytics_CL NSG Flow Logs
Rule ID: 16a45aee-5e39-4d1b-b508-40f847c99353
TI Map IP entity to Cloud App Events
Rule ID: 66c81ae2-1f89-4433-be00-2fbbd9ba5ebe
TI Map IP Entity to CommonSecurityLog
Rule ID: cdd1933b-ef94-48a4-b94a-18d45b902751
TI Map IP Entity to CommonSecurityLog
Rule ID: 2474343c-9135-42ec-9c40-a1bace43da5c
TI Map IP Entity to DeviceNetworkEvents
Rule ID: b2df4979-d34a-48b3-a7d9-f473a4bf8058
TI Map IP Entity to DeviceNetworkEvents
Rule ID: 67775878-7f8b-4380-ac54-115e1e828901
TI map IP entity to DNS Events ASIM DNS schema
Rule ID: b306fba8-1a28-449f-aa24-30362e16d4f5
TI Map IP entity to DNS Events ASIM DNS schema
Rule ID: 6418fd33-92f2-407b-bd61-91c0d4bbcb8a
TI Map IP Entity to DnsEvents
Rule ID: 69b7723c-2889-469f-8b55-a2d355ed9c87
TI Map IP Entity to DnsEvents
Rule ID: 4988c238-a118-442c-80bd-6c689a1b2e97
TI Map IP Entity to Duo Security
Rule ID: d23ed927-5be3-4902-a9c1-85f841eb4fa1
TI Map IP Entity to Duo Security
Rule ID: aac495a9-feb1-446d-b08e-a1164a539452
TI map IP entity to GitHub_CL
Rule ID: 43d6c173-64c8-4416-b32e-636a9f318d15
TI Map IP entity to GitHub_CL
Rule ID: 2a723664-22c2-4d3e-bbec-5843b90166f3
TI map IP entity to LastPass data
Rule ID: e2399891-383c-4caf-ae67-68a008b9f89e
TI map IP entity to Network Session Events ASIM Network Session schema
Rule ID: 54f4ceb4-fd83-4633-b5b0-c0de9feb8890
TI Map IP entity to Network Session Events ASIM Network Session schema
Rule ID: f15370f4-c6fa-42c5-9be4-1d308f40284e
TI map IP entity to OfficeActivity
Rule ID: f50280e5-5eb1-4e95-99fd-9d584a987bdd
TI Map IP entity to OfficeActivity
Rule ID: edfc9d8a-6fb3-49e2-80c9-fea15d941799
TI Map IP Entity to SigninLogs
Rule ID: f2eb15bd-8a88-4b24-9281-e133edfba315
TI Map IP Entity to SigninLogs
Rule ID: 9713e3c0-1410-468d-b79e-383448434b2d
TI Map IP Entity to VMConnection
Rule ID: aed70d71-adb2-4f73-becd-02150b13950b
TI Map IP Entity to VMConnection
Rule ID: 5e45930c-09b1-4430-b2d1-cc75ada0dc0f
TI Map IP Entity to W3CIISLog
Rule ID: 888c4736-e604-48eb-b2c7-3462356d9510
TI Map IP Entity to W3CIISLog
Rule ID: e2559891-383c-4caf-ae67-55a008b9f89e
TI map IP entity to Web Session Events ASIM Web Session schema
Rule ID: 0548be6c-135e-4eb6-b9ff-14a09df62c77
TI Map IP entity to Web Session Events ASIM Web Session schema
Rule ID: a924d317-03d2-4420-a71f-4d347bda4bd8
TI map IP entity to WorkdayASimAuditEventLogs
Rule ID: 92e8e945-6e99-4e4b-bef8-468b4c19fc3a
TI Map IP entity to WorkdayASimAuditEventLogs
Rule ID: 712fab52-2a7d-401e-a08c-ff939cc7c25e
TI Map URL Entity to AuditLogs
Rule ID: 9991c277-e0a1-4079-8c40-fbfca2705615
TI Map URL Entity to AuditLogs
Rule ID: 526df43b-f514-477c-af7a-c8d3586457fb
TI Map URL entity to Cloud App Events
Rule ID: 4f0356b2-d344-4c19-9375-31b9575d80cb
TI Map URL Entity to DeviceNetworkEvents
Rule ID: 6ddbd892-a9be-47be-bab7-521241695bd6
TI Map URL Entity to DeviceNetworkEvents
Rule ID: 9e32e545-e60c-47de-9941-f9ca1ada0a42
TI Map URL Entity to EmailUrlInfo
Rule ID: a0038239-72f4-4f7b-90ff-37f89f7881e0
TI Map URL Entity to EmailUrlInfo
Rule ID: 36a9c9e5-3dc1-4ed9-afaa-1d13617bfc2b
TI Map URL Entity to OfficeActivity Data [Deprecated]
Rule ID: 106813db-679e-4382-a51b-1bfc463befc3
TI Map URL Entity to PaloAlto Data
Rule ID: 32b437c4-dddb-45b3-9aae-5188e80624b0
TI Map URL Entity to PaloAlto Data
Rule ID: 3b6bdb38-93c5-452f-ab3a-97a3d1320d16
TI Map URL Entity to SecurityAlert Data
Rule ID: f30a47c1-65fb-42b1-a7f4-00941c12550b
TI Map URL Entity to SecurityAlert Data
Rule ID: 4de24a28-dcd0-4a0d-bf14-96d8483dc05a
TI Map URL Entity to Syslog Data
Rule ID: b31037ea-6f68-4fbd-bab2-d0d0f44c2fcf
TI Map URL Entity to Syslog Data
Rule ID: 23391c84-87d8-452f-a84c-47a62f01e115
TI Map URL Entity to UrlClickEvents
Rule ID: ad4fa1f2-2189-459c-9458-f77d2039d2f5
TI Map URL Entity to UrlClickEvents
Rule ID: 3b4a8c72-5a2e-4f1e-b61a-9d8b2a6d7a21
TI Map URL entity to Web Session Events ASIM Web Session schema
Rule ID: de549a62-f595-4810-88bd-621338186588
TIE Active Directory attacks pathways
Rule ID: 874e3530-552e-437b-ba2e-227979e7e43c
TIE DCShadow
Rule ID: 19d1f964-ddcf-437b-92ce-b9c1c14d24f1
TIE DCSync
Rule ID: 216e12dd-165a-4537-b241-32e1bd3330c7
TIE Golden Ticket
Rule ID: 6c75f0d2-2973-4188-bb05-ec7bc8696120
TIE Indicators of Attack
Rule ID: f6ae2eb2-97c9-4e0f-ae73-7420ef80d99d
TIE Indicators of Exposures
Rule ID: 7851f57c-98b6-43c6-9747-9bb7cf11f21c
TIE LSASS Memory
Rule ID: d1416c25-5a56-4a88-8d7c-568e6551a307
TIE Password Guessing
Rule ID: 87af910a-e9c0-4c96-8045-f778ba405251
TIE Password issues
Rule ID: f47eb8cb-4acb-4ee4-887d-0247c6d73a72
TIE Password Spraying
Rule ID: 5c170c73-75ba-48ea-8dfc-e4e2d4f23979
TIE privileged accounts issues
Rule ID: c4562ef3-d821-4089-b6c0-120d95c855e6
TIE user accounts issues
Rule ID: 06a9b845-6a95-4432-a78b-83919b28c375
Time series anomaly detection for total volume of traffic
Rule ID: f2dd4a3a-ebac-4994-9499-1a859938c947
Time series anomaly for data size transferred to public internet
Rule ID: 91f59cea-486f-11ec-81d3-0242ac130003
Tomcat - Commands in URI
Rule ID: 5e77a818-5825-4ff6-a901-80891c4774d1
Tomcat - Known malicious user agent
Rule ID: 4fa66058-4870-11ec-81d3-0242ac130003
Tomcat - Multiple client errors from single IP address
Rule ID: 7c9a1026-4872-11ec-81d3-0242ac130003
Tomcat - Multiple empty requests from same IP
Rule ID: de9df79c-4872-11ec-81d3-0242ac130003
Tomcat - Multiple server errors from single IP address
Rule ID: 103d5ada-4874-11ec-81d3-0242ac130003
Tomcat - Put file and get file from same IP address
Rule ID: a45dd6ea-4874-11ec-81d3-0242ac130003
Tomcat - Request from localhost IP address
Rule ID: 0c851bd4-4875-11ec-81d3-0242ac130003
Tomcat - Request to sensitive files
Rule ID: 875da588-4875-11ec-81d3-0242ac130003
Tomcat - Server errors after multiple requests from same IP
Rule ID: ce84741e-4875-11ec-81d3-0242ac130003
Tomcat - Sql injection patterns
Rule ID: 1ddeb8ad-cad9-4db4-b074-f9da003ca3ed
Trend Micro CAS - DLP violation
Rule ID: 3649dfb8-a5ca-47dd-8965-cd2f633ca533
Trend Micro CAS - Infected user
Rule ID: 65c2a6fe-ff7b-46b0-9278-61265f77f3bc
Trend Micro CAS - Multiple infected users
Rule ID: 9e7b3811-d743-479c-a296-635410562429
Trend Micro CAS - Possible phishing mail
Rule ID: 0bec3f9a-dbe9-4b4c-9ff6-498d64bbef90
Trend Micro CAS - Ransomware infection
Rule ID: 38e043ce-a1fd-497b-8d4f-ce5ca2db90cd
Trend Micro CAS - Ransomware outbreak
Rule ID: 52c4640a-1e2b-4155-b69e-e1869c9a57c9
Trend Micro CAS - Suspicious filename
Rule ID: c8e2ad52-bd5f-4f74-a2f7-6c3ab8ba687a
Trend Micro CAS - Threat detected and not blocked
Rule ID: de54f817-f338-46bf-989b-4e016ea6b71b
Trend Micro CAS - Unexpected file on file share
Rule ID: 201fd2d1-9131-4b29-bace-ce5d19f3e4ee
Trend Micro CAS - Unexpected file via mail
Rule ID: 2f668615-c372-4673-a5cd-773e4da715b9
TrendAI Vision One - Create Incident for Workbench Alerts
Rule ID: 8dcf7238-a7d0-4cfd-8d0c-b230e3cd9182
Trust Monitor Event
Rule ID: 5c2bb446-926f-4160-a233-21e335c2c290
Trusted Developer Utilities Proxy Execution
Rule ID: db60ca0b-b668-439b-b889-b63b57ef20fb
Ubiquiti - Connection to known malicious IP or C2
Rule ID: fe232837-9bdc-4e2b-8c08-cdac2610eed3
Ubiquiti - connection to non-corporate DNS server
Rule ID: 6df85d74-e32f-4b71-80e5-bfe2af00be1c
Ubiquiti - Large ICMP to external server
Rule ID: 7feb3c32-2a11-4eb8-a2d7-e3792b31cb80
Ubiquiti - Possible connection to cryptominning pool
Rule ID: 95d5ca9b-72c5-4b80-ad5c-b6401cdc5e08
Ubiquiti - RDP from external source
Rule ID: 0998a19d-8451-4cdd-8493-fc342816a197
Ubiquiti - SSH from external source
Rule ID: 9757cee3-1a6c-4d8e-a968-3b7e48ded690
Ubiquiti - Unknown MAC Joined AP
Rule ID: 14a23ded-7fb9-48ee-ba39-859517a49b51
Ubiquiti - Unusual DNS connection
Rule ID: fd200125-9d57-4838-85ca-6430c63e4e5d
Ubiquiti - Unusual FTP connection to external server
Rule ID: 31e868c0-91d3-40eb-accc-3fa73aa96f8e
Ubiquiti - Unusual traffic
Rule ID: 479bc6ef-ecb3-496f-9a2a-38c9635d77d3
Unauthenticated API Endpoint with Sensitive Data
Rule ID: f4c71e55-6192-47ca-92e2-0856ae502a46
Unauthorized device in the network Microsoft Defender for IoT
Rule ID: c52ec521-9188-4a9e-a4cd-34a3dfbc3d27
Unauthorized DHCP configuration in the network Microsoft Defender for IoT
Rule ID: c2fb27c7-5f67-49c4-aaf3-d82934234a69
Unauthorized PLC changes Microsoft Defender for IoT
Rule ID: 1ff4fa3d-150b-4c87-b733-26c289af0d49
Unauthorized remote access to the network Microsoft Defender for IoT
Rule ID: 60f31001-018a-42bf-8045-a92e1f361b7b
Unauthorized user access across AWS and Azure
Rule ID: 4f7b9e6c-5d1a-4392-8c2b-3e4f5a6b7c8d
UniFi Site Manager Console firmware likely security-relevant
Rule ID: 8e22eb19-51df-37f7-468f-9d112fff9098
UniFi Site Manager Console group membership churn
Rule ID: ac1efe0f-654e-264e-07be-c1b60e698343
UniFi Site Manager Controller Connection State Change
Rule ID: 1fb5c195-9bff-e18b-3e8f-5123f46bff9d
UniFi Site Manager Data Connector Health
Rule ID: f3fa4f3f-c8db-ae35-ee06-04de2dfac511
UniFi Site Manager Device Offline
Rule ID: 77bba2d0-92e1-408d-9e43-2d6e5e81538e
UniFi Site Manager Devices adopted outside business hours
Rule ID: 0f489145-b472-a821-a166-a6c68e346ad2
UniFi Site Manager Devices flapping onlineoffline
Rule ID: ef1a293a-9e2b-b087-7816-2610814ed2d4
UniFi Site Manager External WAN IP changed
Rule ID: 1d767977-460a-29c3-06f7-799a91a80daf
UniFi Site Manager Firmware drift hotspots
Rule ID: 83b88ab5-21ca-5dd2-df91-6db4354f9360
UniFi Site Manager Firmware Update Available
Rule ID: 2b0ca272-72fd-c2c2-6728-7f287c22e275
UniFi Site Manager Firmware version diversity within a model
Rule ID: aa188a24-783a-76a1-cd11-3bcac0e97de9
UniFi Site Manager IPS signature count dropped 50
Rule ID: 36a64027-729e-51d7-16bf-8e926c03712a
UniFi Site Manager IPSIDS disabled or misconfigured
Rule ID: b54123ef-cfa7-769e-a959-f437404a1192
UniFi Site Manager ISP Downtime
Rule ID: 77d8f6d0-b45c-ea6e-7c58-daac194a095f
UniFi Site Manager ISP High Latency
Rule ID: 6f2d71d6-e6c4-0da4-91da-e8192dc5b12c
UniFi Site Manager ISP Packet Loss
Rule ID: fecd4ab1-b24e-8413-9164-e3621c8d7caa
UniFi Site Manager ISP SLA Breach
Rule ID: 3f49ba8c-8995-9d38-579d-24afa09f5a2a
UniFi Site Manager Long-tail ISP latency hotspots P95
Rule ID: 9283b576-5350-fca1-3979-dacb6acd1d16
UniFi Site Manager Multiple Devices Offline
Rule ID: e4b75722-7239-f247-558f-d2e851ea0b38
UniFi Site Manager New critical notifications appeared
Rule ID: e69be544-9476-35bb-2533-fa8c650dcd46
UniFi Site Manager New Device Adopted
Rule ID: 17d09e1b-8a3f-776b-6981-dbe2cc74d097
UniFi Site Manager New WAN issue index recorded
Rule ID: b16f13ae-343b-9513-e684-469cdf9471b2
UniFi Site Manager New WAN2 secondary issue recorded
Rule ID: d943d401-861e-7186-d42c-c505fbf7c619
UniFi Site Manager Pending firmware updates outstanding for 7d
Rule ID: c8875ebb-cc6e-14e4-4216-d8b06fd92c90
UniFi Site Manager Site Health Critical
Rule ID: 2dbe3bb8-1522-e491-2eac-72bb0923c5eb
UniFi Site Manager Sites with persistent WAN issues
Rule ID: f32950bc-6553-4c03-2686-a9c29ef318e8
UniFi Site Manager System log shipping disabled
Rule ID: 9c0a7304-287e-f1b2-8b4f-c7444b8511ea
UniFi Site Manager WAN external IP geographic deviation
Rule ID: 2bb29f25-833a-5544-4a8e-9bf6c4d8da56
UniFi Site Manager WAN uptime below 99
Rule ID: f5130582-9e0e-cb47-af0b-dcd8b261fa04
UniFi Site Manager WiFi quality degraded high TX retry
Rule ID: 3939f01f-9563-4cd3-8423-97a82e82719b
Uniqkey - Credential export from newly created account
Rule ID: f3125212-6871-4adc-8335-98c9a920639b
Uniqkey - Data export activity
Rule ID: cee6bbae-e1ee-4b65-9782-6afce5c330e6
Uniqkey - Departing employee credential export
Rule ID: 97857198-99f2-48dd-b036-461d85a29570
Uniqkey - Event ingestion stopped
Rule ID: 755c7adb-1015-4be3-9e56-55e72009c088
Uniqkey - Excessive credential access
Rule ID: 712f5770-a5a9-4623-8adc-26cda17294a5
Uniqkey - Platform threat detection
Rule ID: ac008972-e70f-4040-96ad-bdce1c642839
Uniqkey - Security policy change
Rule ID: 4b1fefb3-419a-4bbe-8a74-ef8288a8d8d0
Uniqkey - Self-granted privilege or access change
Rule ID: 6909c70c-fb52-47a3-9eb9-3b8109b0b32a
Uniqkey - Sign-in from unfamiliar IP address
Rule ID: e0ae5f9e-865b-41f5-98bb-c04113888e85
Unused IaaS Policy
Rule ID: d0255b5f-2a3c-4112-8744-e6757af3283a
Unusual Anomaly
Rule ID: 0a3f4f4f-46ad-4562-acd6-f17730a5aef4
Unusual identity creation using exchange powershell
Rule ID: e5f8e196-3544-4a8b-96a9-17c1b6a49710
Unusual Volume of file deletion by users
Rule ID: a3bbdf60-0a6d-4cc2-b1d1-dd70aca184ce
Unusual Volume of Password Updated or Removed
Rule ID: 017e095a-94d8-430c-a047-e51a11fb737b
URL Added to Application from Unknown Domain
Rule ID: fb0f4a93-d8ad-4b54-9931-85bdb7550f90
User Accessed Suspicious URL Categories
Rule ID: a35f2c18-1b97-458f-ad26-e033af18eb99
User account added to built in domain local or global group
Rule ID: 4b93c5af-d20b-4236-b696-a28b8c51407f
User account created and deleted within 10 mins
Rule ID: ee55dc85-d2da-48c1-a6c0-3eaee62a8d56
User Account Created Using Incorrect Naming Format
Rule ID: dc99e38c-f4e9-4837-94d7-353ac0b01a77
User account created without expected attributes defined
Rule ID: 3d023f64-8225-41a2-9570-2bd7c2c4535e
User account enabled and disabled within 10 mins
Rule ID: 3a9d5ede-2b9d-43a2-acc4-d272321ff77c
User Accounts - Sign in Failure due to CA Spikes
Rule ID: 2a09f8cb-deb7-4c40-b08b-9137667f1c0b
User Added to Admin Role
Rule ID: 4d94d4a9-dc96-410a-8dea-4d4d4584188b
User added to Microsoft Entra ID Privileged Groups
Rule ID: 29283b22-a1c0-4d16-b0a9-3460b655a46a
User agent search for log4j exploitation attempt
Rule ID: 746ddb63-f51b-4563-b449-a8b13cf302ec
User Assigned New Privileged Role
Rule ID: c04ed74c-3b23-48cd-9c11-fd10cffddc64
User assigned to a default admin role
Rule ID: 11c3d541-5fa5-49df-8218-d1c98584473b
User impersonation by Identity Protection alerts
Rule ID: 58fc0170-0877-4ea8-a9ff-d805e361cfae
User joining Zoom meeting from suspicious timezone
Rule ID: 2954d424-f786-4677-9ffc-c24c44c6e7d5
User Login from Different Countries within 3 hours
Rule ID: 09ec8fa2-b25f-4696-bfae-05a7b85d7b9e
User login from different countries within 3 hours Uses Authentication Normalization
Rule ID: 25111c10-44b5-4275-996d-d62f15a7d072
User or Group Added
Rule ID: d297961f-f8a3-4f84-865d-ec3a07641699
User or Group Deleted
Rule ID: 35846296-4052-4de2-8098-beb6bb5f2203
User Session ImpersonationOkta
Rule ID: 3094e036-e5ae-4d6e-8626-b0f86ebc71f2
User Sign in from different countries
Rule ID: a09a0b8e-30fe-4ebf-94a0-cffe50f579cd
User State changed from Guest to Member
Rule ID: 71a7b0de-f13d-44b9-9caa-668f1bad0ce6
User without MFA
Rule ID: 24E0132F-61D1-41BD-9393-06136D1039C7
UserAccountDisabled
Rule ID: f7f4a77e-f68f-4b56-9aaf-a0c9d87d7a8e
Users searching for VIP user activity
Rule ID: 9b1a3b3e-7e16-4a3b-8a8f-7f1f2b1c0a03
Utimaco ESKM - Burst of KMIP DESTROY operations by a single user
Rule ID: 9b1a3b3e-7e16-4a3b-8a8f-7f1f2b1c0a01
Utimaco ESKM - Multiple KMIP authentication failures from same IP
Rule ID: 9b1a3b3e-7e16-4a3b-8a8f-7f1f2b1c0a02
Utimaco ESKM - PERMISSION_DENIED burst for a KMIP user
Rule ID: 54262ad1-f346-4246-a13f-9557595ff7bd
Vaikora - Agent policy violation
Rule ID: c0984707-0855-430e-9c36-5e2d0d0ce56f
Vaikora - Behavioral anomaly detected
Rule ID: e61258ec-1a7f-454c-95b5-458a6edb1ea4
Vaikora - Behavioral anomaly detected
Rule ID: 968b70c1-b468-418a-ac02-1eb74783a52a
Vaikora - Engine offline
Rule ID: 5f7789fa-0a6b-4dff-a2da-dfa4b682f3af
Vaikora - Feed outage detection
Rule ID: 017031f6-be1d-4c68-b4d3-182fa84378cc
Vaikora - High score quarantine
Rule ID: ac3ec787-fd49-4e93-88cc-aaa9b31061ac
Vaikora - High severity AI agent action
Rule ID: 15c49777-7cb7-4746-8064-6fa4c7a73df8
Vaikora - High severity AI agent action detected
Rule ID: 3b3eb1cd-578d-4198-9b7a-bd7253b0dc9f
Vaikora - Quarantine rate spike
Rule ID: d944d564-b6fa-470d-b5ab-a1a141878c5e
Valence Security Alerts
Rule ID: 44ec1fa4-a502-41ae-879a-3aad3557edce
Valimail Enforce - DMARC Policy Weakened to None
Rule ID: 483078c6-d029-40f3-931a-30af0032008b
Valimail Enforce - Email Authentication Key Deleted
Rule ID: e960f5b0-cd80-474a-996a-013ff3989772
Valimail Enforce - High-Value User Management Event
Rule ID: 3cbb78d9-81ac-42c9-b3cd-7e6baea7d9ff
Valimail Enforce - Unusual Rate of Configuration Changes or User Additions
Rule ID: a36de6c3-3198-4d37-92ae-e19e36712c2e
vArmour AppController - SMB Realm Traversal
Rule ID: 7d2c9a41-5b8e-4f36-9c1a-2e6b8d4f7a13
Varonis - High severity alerts detected
Rule ID: e5a7c93b-8d14-42f6-b7c0-3a9e1f6d5b28
Varonis - Informational alerts detected
Rule ID: 9b1f3e7a-6c42-4d18-a5e9-2b7f8c0d4e61
Varonis - Low severity alerts detected
Rule ID: c4e8b16f-3a92-4d75-8e21-6f9c0b5d2a84
Varonis - Medium severity alerts detected
Rule ID: 0b76eef3-5dc0-41b1-9f67-fffa7783f5f6
Vaults Alerts for Prancer
Rule ID: f1fcb22c-b459-42f2-a7ee-7276b5f1309c
vCenter - Root impersonation
Rule ID: ce54b5d3-4c31-4eaf-a73e-31412270b6ab
Vectra Accounts Behaviors
Rule ID: 39e48890-2c02-487e-aa9e-3ba494061798
Vectra AI Detect - Detections with High Severity
Rule ID: a34d0338-eda0-42b5-8b93-32aae0d7a501
Vectra AI Detect - New Campaign Detected
Rule ID: 321f9dbd-64b7-4541-81dc-08cf7732ccb0
Vectra AI Detect - Suspected Compromised Account
Rule ID: 60eb6cf0-3fa1-44c1-b1fe-220fbee23d63
Vectra AI Detect - Suspected Compromised Host
Rule ID: 6cb75f65-231f-46c4-a0b3-50ff21ee6ed3
Vectra AI Detect - Suspicious Behaviors by Category
Rule ID: e796701f-6b39-4c54-bf8a-1d543a990784
Vectra Create Detection Alert for Accounts
Rule ID: fb861539-da19-4266-831f-99459b8e7605
Vectra Create Detection Alert for Hosts
Rule ID: af6f2812-0187-4cc9-822a-952f8b5b6b7e
Vectra Create Incident Based on Priority for Accounts
Rule ID: 9b51b0fb-0419-4450-9ea0-0a48751c4902
Vectra Create Incident Based on Priority for Hosts
Rule ID: 87325835-dd8c-41e7-b686-fd5adbbd0aee
Vectra Create Incident Based on Tag for Accounts
Rule ID: 8b7a1a64-8ef2-4000-b8c9-9bca3b93aace
Vectra Create Incident Based on Tag for Hosts
Rule ID: 33e3b6da-2660-4cd7-9032-11be76db88d2
Vectra Hosts Behaviors
Rule ID: 231904f5-b670-4223-9bec-2e9aeca9cf5a
Vectra RUX - Create Incident for Escalated Account Detection or Unresolved Priority Account
Rule ID: 231904f5-b670-4223-9bec-2e9aeca9cf5b
Vectra RUX - Create Incident for Escalated Host Detection or Unresolved Priority Host
Rule ID: 73e36985-d65d-4852-b3cc-5e8f4b64b39c
Veeam ONE Application with No Recent Data Backup Sessions
Rule ID: 7fb6d1b6-48e4-442b-ba4d-1b5fb5fa379b
Veeam ONE Backup Copy RPO
Rule ID: 7ad4b9ff-8089-4b70-b98e-a2ca995611e9
Veeam ONE Backup Server Security and Compliance State
Rule ID: c0ead324-d8e8-484d-b590-9639f5ac5d93
Veeam ONE Computer with No Backup
Rule ID: 21ef1e12-75ac-43be-a77e-d2cee4c69225
Veeam ONE Immutability Change Tracking
Rule ID: b5785a66-3722-4bdc-9d12-bb40f2cf4824
Veeam ONE Immutability State
Rule ID: 1a9e31d6-2116-4ff1-8ee7-abc957c34350
Veeam ONE Job Disabled
Rule ID: 176abf3c-392a-47bd-b565-a4ecfd0ff7ec
Veeam ONE Job Disabled Veeam Backup for Microsoft 365
Rule ID: 2a860019-0eda-4b49-bc62-8f683aed4929
Veeam ONE Malware Detection Change Tracking
Rule ID: d48f9671-adc0-45e5-a477-670ef38bc132
Veeam ONE Possible Ransomware Activity Hyper-V
Rule ID: 37d97c4d-a42f-495b-a523-376416b278b5
Veeam ONE Possible Ransomware Activity vSphere
Rule ID: 8bb38c66-ca2a-4ad0-9b49-1e60368f8a19
Veeam ONE Suspicious Incremental Backup Size
Rule ID: 04530ba4-b26e-4a83-8057-a4fc286de848
Veeam ONE Unusual Job Duration
Rule ID: cab7396a-9a18-45e7-b685-945e8bf825cb
Veeam ONE Unusual Job Duration Veeam Backup for Microsoft 365
Rule ID: 0e76e420-fa55-4718-adc6-40a1a76411af
Veeam ONE VM with No Backup
Rule ID: ae880194-5766-46d3-a17b-c8c53e9ca96c
Veeam ONE VM with No Backup Hyper-V
Rule ID: 128ea2a4-1047-4f28-ad55-b1b88357d172
Veeam ONE VM with No Replica
Rule ID: 6117e317-4b90-4bcc-a71f-0c1f29d82ce3
Veeam ONE VM with No Replica Hyper-V
Rule ID: B1DB8B7E-9D74-48C3-9683-74483CBEFF4E
Versasec CMS - Multiple Failed Login Attempts
Rule ID: 5170c3c4-b8c9-485c-910d-a21d965ee181
VIP Mailbox manipulation
Rule ID: 384e92a7-103c-4a47-945d-381ae9653f91
Virtual Lab Deleted
Rule ID: a21eccd5-0148-4f88-a5d7-a8f86e9e4d8e
Virtual Lab Settings Updated
Rule ID: c13b025c-ea31-4e4b-8e08-955b8fa91fa0
Virtual Machines Alerts for Prancer
Rule ID: 6bd031cf-78d0-4edd-8191-60f84b6eef7a
VirtualNetworkPeerings Alerts From Prancer
Rule ID: d811ef72-66b9-43a3-ba29-cd9e4bf75b74
VMware Cloud Web Security - Data Loss Prevention Violation
Rule ID: 3efebd49-c985-431b-9da8-d7d397092d18
VMware Cloud Web Security - Policy Change Detected
Rule ID: b26a7d97-6b6e-43ab-870e-eb18460ae602
VMware Cloud Web Security - Policy Publish Event
Rule ID: b84a1f62-ad30-4ae1-8b21-3d304d8aa818
VMware Cloud Web Security - Web Access Policy Violation
Rule ID: 69c0644f-4ad5-41b6-9e09-a94c072ab80e
VMware Edge Cloud Orchestrator - New LAN-Side Client Device Detected
Rule ID: 4cdcd5d8-89df-4076-a917-bc50abb9f2ab
VMware ESXi - Dormant VM started
Rule ID: 48d992ba-d404-4159-a8c6-46f51d1325c7
VMware ESXi - Low patch disk space
Rule ID: 2ee727f7-b7c2-4034-b6c9-d245d5a29343
VMware ESXi - Low temp directory space
Rule ID: 22d177d5-588c-4f1a-a332-2695f52079bb
VMware ESXi - Multiple Failed Shell Login via SSH
Rule ID: bdea247f-7d17-498c-ac0e-c7e764cbdbbe
VMware ESXi - Multiple new VMs started
Rule ID: 5fe1af14-cd40-48ff-b581-3a12a1f90785
VMware ESXi - Multiple VMs stopped
Rule ID: 0f4a80de-344f-47c0-bc19-cb120c59b6f0
VMware ESXi - New VM started
Rule ID: 23a3cf72-9497-408e-8144-87958a60d31a
VMware ESXi - Root impersonation
Rule ID: deb448a8-6a9d-4f8c-8a95-679a0a2cd62c
VMware ESXi - Root login
Rule ID: 17b0ea43-5aeb-4dc4-ac3a-be84acb8d5b7
VMware ESXi - Root password changed
Rule ID: 9c496d6c-42a3-4896-9b6c-00254386928f
VMware ESXi - Shared or stolen root account
Rule ID: 4f5b5d79-ff4e-4edd-ae3e-9e1187f0b924
VMware ESXi - SSH Enable on ESXi Host
Rule ID: 395c5560-ddc2-45b2-aafe-2e3f64528d3d
VMware ESXi - Unexpected disk image
Rule ID: 43889f30-7bce-4d8a-93bb-29c9615ca8dd
VMware ESXi - VM stopped
Rule ID: 50c86f92-86b0-4ae3-bb94-698da076ca9e
VMware SD-WAN - Orchestrator Audit Event
Rule ID: 8d05cc90-d337-41f5-b5fa-614cbfe1a879
VMware SD-WAN Edge - All Cloud Security Service Tunnels DOWN
Rule ID: a88ead0a-f022-48d6-8f53-e5a164c4c72e
VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
Rule ID: 44f78dbf-9f29-4ec0-aaca-ab5bf0b559af
VMware SD-WAN Edge - IDSIPS Alert triggered Search API
Rule ID: a8e2bfd2-5d9c-4acc-aa55-30029e50d574
VMware SD-WAN Edge - IDSIPS Alert triggered Syslog
Rule ID: 27553108-4aaf-4a3e-8ecd-5439d820d474
VMware SD-WAN Edge - IDSIPS Signature Update Failed
Rule ID: 6364be84-9f13-4fd8-8b4a-8ccb43a89376
VMware SD-WAN Edge - IDSIPS Signature Update Succeeded
Rule ID: ce207901-ed7b-49ae-ada7-033e1fbb1240
VMware SD-WAN Edge - Network Anomaly Detection - Potential Fragmentation Attack
Rule ID: 840b050f-842b-4264-8973-d4f9b65facb5
VMware SD-WAN Edge - Network Anomaly Detection - RPF Check Failure
Rule ID: 03e8a895-b5ba-49a0-aed3-f9a997d92fbe
VMware vCenter - Root login
Rule ID: 17bf3780-ae0d-4cd9-a884-5df8b687f3f5
Votiro - File Blocked from Connector
Rule ID: 0b8b91de-c63e-4bc2-b5f4-b15d3b379ec9
Votiro - File Blocked in Email
Rule ID: 7be47078-657a-43cf-9c93-b4705a9f6134
VTI - High Severity Domain Collision Detection
Rule ID: dbd9e28f-973d-47f3-a8c3-9e18da846870
VTI - High Severity SHA1 Collision Detection
Rule ID: d096643d-6789-4c74-8893-dd3fc8a94069
Vulerabilities
Rule ID: 3d71fc38-f249-454e-8479-0a358382ef9a
Vulnerable Machines related to log4j CVE-2021-44228
Rule ID: 4d94d4a9-dc96-450a-9dea-4d4d4594199b
Vulnerable Machines related to OMIGOD CVE-2021-38647
Rule ID: 5b19f19b-d92c-486f-be98-ba2c5945e240
WAN Accelerator Deleted
Rule ID: 2e4fe360-ce67-433b-930e-42f83058dfd0
WAN Accelerator Settings Updated
Rule ID: 2790795b-7dba-483e-853f-44aa0bc9c985
Wazuh - Large Number of Web errors from an IP
Rule ID: f6502545-ae3a-4232-a8b0-79d87e5c98d7
WDigest downgrade attack
Rule ID: 8159a8d2-13a5-49af-847b-e062c45ab92b
Web Application attack detected
Rule ID: 84ad2f8a-b64c-49bc-b669-bdb4fd3071e9
Web sites blocked by Eset
Rule ID: 7b84fc5b-9ffb-4e9b-945b-5d480e330b3f
Website blocked by ESET
Rule ID: 32e7bcab-4424-516e-9c7c-dbe868144494
Whisper Security - ASN Reputation Degradation
Rule ID: 1c08a7cb-7ff4-5a37-a961-39c29f8d07bd
Whisper Security - BGP Route Anomaly with Traffic Spike
Rule ID: 00682c4c-b8b5-5ef7-af33-50891b271b7b
Whisper Security - C2 Communication Detection
Rule ID: 374a77f4-23ed-55dc-8441-8e47a1e079e9
Whisper Security - Co-Hosted Malware Cluster Detection
Rule ID: b6e26c67-f596-5c0f-8614-c88d715508c5
Whisper Security - Domain Registrar Change Anomaly
Rule ID: 4f80ee8e-901f-538a-8603-cc4b49e80164
Whisper Security - Newly Registered Domain on Threat ASN
Rule ID: 9c275139-b554-58f1-b390-8520b10e54ad
Whisper Security - SPF Record Unauthorized Include Detection
Rule ID: f5567c93-91de-577a-b35e-c2807715493d
Whisper Security - Tor Exit Node Communication
Rule ID: 15049017-527f-4d3b-b011-b0e99e68ef45
Windows Binaries Executed from Non-Default Directory
Rule ID: cbf6ad48-fa5c-4bf7-b205-28dbadb91255
Windows Binaries Lolbins Renamed
Rule ID: 6e715730-82c0-496c-983b-7a20c4590bd9
Windows host username encoded in base64 web request
Rule ID: 3c8e5f0b-1d4a-4b69-9c2e-7f0d3a5e8b1f
WMI Spawning Suspicious Child Process Living off the Land
Rule ID: a5b3429d-f1da-42b9-883c-327ecb7b91ff
Workspace deletion activity from an infected device
Rule ID: f8e7d6c5-4b3a-4912-8f0e-2d1c3b4a5678
XbowCriticalHighFindings
Rule ID: d2e4f1a8-7c9b-4356-8e0d-5a2b7c8e9f01
XbowLowFindings
Rule ID: b3c5e2f9-6a8d-4127-9b2e-4f6a8c9d0e12
XbowMediumFindings
Rule ID: e4c6a8b2-9d7f-4285-a1e3-6b9c2e4f1a85
XbowNewAssetDiscovered
Rule ID: a4ce12ca-d01d-460a-b15e-6c74ef328b82
Zero Networks Segement - Machine Removed from protection
Rule ID: 603a6b18-b54a-43b7-bb61-d2b0b47d224a
Zero Networks Segment - New API Token created
Rule ID: 58688058-68b2-4b39-8009-ac6dc4d81ea1
Zero Networks Segment - Rare JIT Rule Creation
Rule ID: deb45e6d-892f-40bf-9118-e2a6f26b788d
ZeroFox Alerts - High Severity Alerts
Rule ID: 6f7a7413-b72f-4361-84ee-897baeb9c6d4
ZeroFox Alerts - Informational Severity Alerts
Rule ID: e0c7a91a-7aa1-498a-9c20-cd6c721f9345
ZeroFox Alerts - Low Severity Alerts
Rule ID: a6496de5-911b-4199-b7db-d34ac9d70df3
ZeroFox Alerts - Medium Severity Alerts
Rule ID: 4942992d-a4d3-44b0-9cf4-b5a23811d82d
ZeroTrustTIC30 Control Assessment Posture Change
Rule ID: 9a7f6651-801b-491c-a548-8b454b356eaa
Zinc Actor IOCs files - October 2022
Rule ID: e4779bdc-397a-4b71-be28-59e6a1e1d16b
Zoom E2E Encryption Disabled
Rule ID: 66bc77ee-3e45-11ec-9bbc-0242ac130002
Zscaler - Connections by dormant user
Rule ID: b3d112b4-3e1e-11ec-9bbc-0242ac130002
Zscaler - Forbidden countries
Rule ID: 40a98355-0e52-479f-8c91-4ab659cba878
Zscaler - Shared ZPA session
Rule ID: 593e3e2a-43ce-11ec-81d3-0242ac130003
Zscaler - Unexpected event count of rejects by policy
Rule ID: 672e2846-4226-11ec-81d3-0242ac130003
Zscaler - Unexpected update operation
Rule ID: e07846e0-43ad-11ec-81d3-0242ac130003
Zscaler - Unexpected ZPA session duration
Rule ID: 236a7ec1-0120-40f2-a157-c1a72dde8bcb
Zscaler - ZPA connections by new user
Rule ID: c4902121-7a7e-44d1-810b-88d26db622ff
Zscaler - ZPA connections from new country
Rule ID: 24f0779d-3927-403a-aac1-cc8791653606
Zscaler - ZPA connections from new IP
Rule ID: 2859ad22-46c8-4cc7-ad7b-80ce0cba0af3