
Lucas Pinho
@lucaslapinhoCompletionist
0 followers9 downloads111 copies0 likes282 views
62 detections
Filters
Last updated
All Time
Detection languages
61
1
Categories
18
16
6
6
5
Platforms
20
11
9
8
7
Products / Services
11
10
7
5
5
MITRE Techniques
12
12
11
10
9
Windows Multiple User Account Creations
Cortex XDR
Detects five or more distinct Windows user-account creation events (Event ID 4720) associated with the same actor and host within a one-hour time bucket, which may indicate unauthorized account creation for persistence or mass provisioning.
FortiGate Local User Account Created
Cortex XDR
Detects the creation of a new locally defined user account on a FortiGate device by monitoring configuration change logs. Unauthorized local accounts can be used to establish persistent, unauthorized access to network infrastructure.
Detects a successful Microsoft Entra audit event where a new partner tenant is added to cross-tenant access settings. This change impacts trust-related configuration and inter-tenant access policies, requiring validation against approved organizational changes.
Microsoft Entra Application Created
Cortex XDR
Detects successful creation of a new application registration in Microsoft Entra ID. Application creation is common in development and integration workflows, but unexpected registrations should be reviewed because later credential or permission grants can turn an application into a persistence or privilege path.
Detects coordinated activity where a PowerShell process executes multiple distinct administrative utilities (such as wevtutil, vssadmin, wbadmin, or bcdedit) to perform destructive actions like clearing event logs, deleting shadow copies, or disabling system recovery settings. This rule uses correlation to identify sequences of at least three distinct commands and utilities, reducing false positives associated with single administrative tasks.
FortiGate High CPU Utilization Detected
Cortex XDR
Detects FortiGate devices whose average reported CPU utilization exceeds 90 percent during the correlation window. Sustained CPU pressure can degrade firewall throughput, session establishment, inspection performance, and management responsiveness and should be investigated as a device-health condition.
FortiGate High Memory Usage Alert
Cortex XDR
Detects instances where FortiGate network security appliances report sustained high memory utilization exceeding a defined threshold. Elevated memory usage may indicate performance degradation, excessive traffic volume, or resource-intensive configuration, and can precede entering FortiOS conserve mode.
Detects the execution of Windows processes where the file's web-origin metadata (Mark-of-the-Web) contains a referrer URL pointing to the public GitHub Desktop repository. This rule serves as a provenance and threat hunting signal to track the origin of binaries executed in the environment, identifying software potentially derived from this specific source repository.
Detects audit events in Imperva Cloud WAF where SSL/TLS configuration has been explicitly removed from a protected site. This change impacts the security posture of HTTPS delivery and requires validation to ensure it was an authorized administrative action.
Detects successful SSH authentication to a Linux system using public-key authentication by monitoring system logs for the 'Accepted publickey for' message. This rule identifies remote access attempts and serves as a foundation for monitoring lateral movement via SSH.
Page 3 of 7
