avatar

Lucas Pinho

@lucaslapinho
Completionist
0 followers9 downloads111 copies0 likes282 views

62 detections

Detects High or Critical FortiGate IPS events where the security action indicates that matching traffic was detected or otherwise allowed to continue rather than being blocked. The detection is intended to identify potentially malicious network activity that reached an IPS signature but was not actively prevented.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
004
Detects high or critical severity audit events generated by Cortex XDR Collectors, which may indicate health, connectivity, processing, or configuration issues leading to gaps in security visibility.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
404
Detects a Cortex management audit event indicating that a Broker VM high-availability cluster has no available standby node, signaling reduced redundancy and potential risk to data collection services.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
104
Detects the creation of a new exception rule within the Cortex endpoint agent management configuration. Exception rules can be used to exclude specific files, processes, or behaviors from security prevention policies, potentially leading to a reduction in defensive coverage.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
204
Detects edits to an existing Cortex role-based access control (RBAC) role. Role modifications can change the permissions available to users associated with that role and should be reviewed for authorization, least-privilege impact, and unexpected expansion of administrative access.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
204
Detects Microsoft Entra audit activity where a service principal is granted high-impact application permissions, such as directory, application, group, mail, file, or role-management write access. This activity is significant as compromised applications can leverage these permissions to perform actions without requiring an interactive user.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
303
Detects Microsoft Entra ID Protection risk telemetry where authentication activity is associated with an IP address Microsoft has classified as malicious. The signal can indicate hostile infrastructure, but the event can represent either successful or failed authentication and therefore should not be statically mapped to a specific access technique.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
103
Detects a Windows Registry modification where the EnableLUA value under HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System is set to 0, which disables the User Account Control (UAC) feature. This modification weakens system security by disabling Admin Approval Mode for administrators.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
303
Detects Windows Security Event ID 4725 which signals that a user account has been disabled. This rule specifically correlates the event with a locally maintained inventory of high-value accounts, such as executive, privileged, or service accounts, to identify potentially disruptive or unauthorized account access removal.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
003
Detects the deletion of an Active Directory Group Policy Object (GPO) by monitoring Windows Security Event ID 5141 where the deleted object class is 'groupPolicyContainer'. This activity may indicate an attempt to weaken domain security controls or impair defenses.
avatar
Lucas Pinho@lucaslapinho
avatar
Detections.ai Community
2 months ago
703
Page 4 of 7