
Lucas Pinho
@lucaslapinhoCompletionist
0 followers9 downloads111 copies0 likes282 views
62 detections
Filters
Last updated
All Time
Detection languages
61
1
Categories
18
16
6
6
5
Platforms
20
11
9
8
7
Products / Services
11
10
7
5
5
MITRE Techniques
12
12
11
10
9
Detects High or Critical FortiGate IPS events where the security action indicates that matching traffic was detected or otherwise allowed to continue rather than being blocked. The detection is intended to identify potentially malicious network activity that reached an IPS signature but was not actively prevented.
Detects high or critical severity audit events generated by Cortex XDR Collectors, which may indicate health, connectivity, processing, or configuration issues leading to gaps in security visibility.
Detects a Cortex management audit event indicating that a Broker VM high-availability cluster has no available standby node, signaling reduced redundancy and potential risk to data collection services.
Cortex Agent Exception Rule Created
Cortex XDR
Detects the creation of a new exception rule within the Cortex endpoint agent management configuration. Exception rules can be used to exclude specific files, processes, or behaviors from security prevention policies, potentially leading to a reduction in defensive coverage.
Cortex RBAC Role Edited
Cortex XDR
Detects edits to an existing Cortex role-based access control (RBAC) role. Role modifications can change the permissions available to users associated with that role and should be reviewed for authorization, least-privilege impact, and unexpected expansion of administrative access.
Detects Microsoft Entra audit activity where a service principal is granted high-impact application permissions, such as directory, application, group, mail, file, or role-management write access. This activity is significant as compromised applications can leverage these permissions to perform actions without requiring an interactive user.
Detects Microsoft Entra ID Protection risk telemetry where authentication activity is associated with an IP address Microsoft has classified as malicious. The signal can indicate hostile infrastructure, but the event can represent either successful or failed authentication and therefore should not be statically mapped to a specific access technique.
Detects a Windows Registry modification where the EnableLUA value under HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System is set to 0, which disables the User Account Control (UAC) feature. This modification weakens system security by disabling Admin Approval Mode for administrators.
Windows High-Value Account Disabled
Cortex XDR
Detects Windows Security Event ID 4725 which signals that a user account has been disabled. This rule specifically correlates the event with a locally maintained inventory of high-value accounts, such as executive, privileged, or service accounts, to identify potentially disruptive or unauthorized account access removal.
Detects the deletion of an Active Directory Group Policy Object (GPO) by monitoring Windows Security Event ID 5141 where the deleted object class is 'groupPolicyContainer'. This activity may indicate an attempt to weaken domain security controls or impair defenses.
Page 4 of 7
