
KQL Cowboy
@KQLCowboyThe PrairieCompletionist
0 followers226 downloads70 copies1 like390 views
108 detections
Filters
Last updated
All Time
Detection languages
76
32
Categories
23
18
17
14
13
Platforms
61
26
17
6
6
Products / Services
41
23
17
9
3
MITRE Techniques
22
11
9
8
8
This rule monitors for high-risk modifications to Zscaler security policies such as disabling SSL inspection or DLP engines, or deleting/modifying firewall and URL filtering rules. It also flags administrative logins from locations previously unseen for that user, which may indicate account compromise or unauthorized access.
Detects Cisco network devices experiencing unexpected reloads, crashes, or watchdog resets that are correlated with prior incoming WebVPN, AnyConnect, or SSL VPN HTTP requests. The rule also identifies multiple device reloads occurring within a short 15-minute window, which may indicate a distributed or repeated exploitation attempt against the SSL VPN infrastructure.
Detects command-line activity indicative of attempts to disable, bypass, uninstall, or interfere with the Netskope security agent functionality on an endpoint.
This rule detects large file uploads (greater than 100MB) from endpoints to unmanaged or personal cloud storage services such as Google Drive, OneDrive, and Dropbox. This behavior may indicate unauthorized data exfiltration or the improper use of unapproved cloud storage platforms to move sensitive data outside of corporate control.
KQL Query
Detects users who have downloaded more than 50 files from cloud storage applications within a single hour, potentially indicating data exfiltration or mass data harvesting.
This rule detects potentially malicious, unauthenticated GraphQL mutation requests targeting common data modification operations ('delete', 'destroy', 'remove', 'update'). By checking for missing Authorization and Session tokens during frequent mutation attempts, it identifies potential exploitation attempts or unauthorized data manipulation attempts against an exposed GraphQL endpoint.
This rule monitors the health of Netskope Private Access (NPA) publishers by tracking their connectivity status, event failure rates, and latency. An alert is triggered if a publisher reports a non-connected status, demonstrates a high failure rate exceeding 10%, or exhibits significant latency spikes (greater than three times the historical average). This is intended to identify infrastructure availability issues or potential service degradation.
This rule monitors Netskope cloud application events to detect potential data exfiltration. It triggers if there is a significant volume anomaly (z-score >= 2) for any cloud application activity, or if a 'Share' or 'Upload' activity occurs that is only configured to 'Alert' rather than being blocked. This helps identify unusual spikes in data movement or sensitive operations that bypass formal enforcement controls.
Detects instances where Zscaler web security logs identify malware, threats, or viruses, specifically flagging users and destination hosts involved in these blocked or allowed security events.
Page 1 of 11
