avatar

KQL Cowboy

@KQLCowboy
The PrairieCompletionist
0 followers226 downloads70 copies1 like390 views

108 detections

This rule monitors for high-risk modifications to Zscaler security policies such as disabling SSL inspection or DLP engines, or deleting/modifying firewall and URL filtering rules. It also flags administrative logins from locations previously unseen for that user, which may indicate account compromise or unauthorized access.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
1013
Detects Cisco network devices experiencing unexpected reloads, crashes, or watchdog resets that are correlated with prior incoming WebVPN, AnyConnect, or SSL VPN HTTP requests. The rule also identifies multiple device reloads occurring within a short 15-minute window, which may indicate a distributed or repeated exploitation attempt against the SSL VPN infrastructure.
avatar
KQL Cowboy@KQLCowboy
avatar
Detections.ai Community
2 months ago
4013
Detects command-line activity indicative of attempts to disable, bypass, uninstall, or interfere with the Netskope security agent functionality on an endpoint.
avatar
KQL Cowboy@KQLCowboy
avatar
Netskope Detection Engineering
2 months ago
4010
This rule detects large file uploads (greater than 100MB) from endpoints to unmanaged or personal cloud storage services such as Google Drive, OneDrive, and Dropbox. This behavior may indicate unauthorized data exfiltration or the improper use of unapproved cloud storage platforms to move sensitive data outside of corporate control.
avatar
KQL Cowboy@KQLCowboy
avatar
Netskope Detection Engineering
2 months ago
409
KQL Query
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
009
Detects users who have downloaded more than 50 files from cloud storage applications within a single hour, potentially indicating data exfiltration or mass data harvesting.
avatar
KQL Cowboy@KQLCowboy
avatar
Netskope Detection Engineering
2 months ago
308
This rule detects potentially malicious, unauthenticated GraphQL mutation requests targeting common data modification operations ('delete', 'destroy', 'remove', 'update'). By checking for missing Authorization and Session tokens during frequent mutation attempts, it identifies potential exploitation attempts or unauthorized data manipulation attempts against an exposed GraphQL endpoint.
avatar
KQL Cowboy@KQLCowboy
avatar
Detections.ai Community
2 months ago
508
This rule monitors the health of Netskope Private Access (NPA) publishers by tracking their connectivity status, event failure rates, and latency. An alert is triggered if a publisher reports a non-connected status, demonstrates a high failure rate exceeding 10%, or exhibits significant latency spikes (greater than three times the historical average). This is intended to identify infrastructure availability issues or potential service degradation.
avatar
KQL Cowboy@KQLCowboy
avatar
Netskope Detection Engineering
2 months ago
206
This rule monitors Netskope cloud application events to detect potential data exfiltration. It triggers if there is a significant volume anomaly (z-score >= 2) for any cloud application activity, or if a 'Share' or 'Upload' activity occurs that is only configured to 'Alert' rather than being blocked. This helps identify unusual spikes in data movement or sensitive operations that bypass formal enforcement controls.
avatar
KQL Cowboy@KQLCowboy
avatar
Netskope Detection Engineering
2 months ago
006
Detects instances where Zscaler web security logs identify malware, threats, or viruses, specifically flagging users and destination hosts involved in these blocked or allowed security events.
avatar
KQL Cowboy@KQLCowboy
avatar
Zscaler Detection Engineering
2 months ago
007
Page 1 of 11