
Lucas Pinho
@lucaslapinhoCompletionist
0 followers9 downloads111 copies0 likes282 views
62 detections
Filters
Last updated
All Time
Detection languages
61
1
Categories
18
16
6
6
5
Platforms
20
11
9
8
7
Products / Services
11
10
7
5
5
MITRE Techniques
12
12
11
10
9
Detects more than ten failed Password Safe authentication attempts for the same user within a ten-minute window, specifically when the failure reason is due to an invalid username or password. This pattern is indicative of potential brute-force or password-guessing activity.
FortiGate Conserve Mode Activated
Cortex XDR
Detects system events on FortiGate devices indicating that the FortiOS has entered 'conserve mode'. This state occurs when the system experiences high memory pressure, potentially triggering resource-protection mechanisms that can impact traffic processing, security inspection, and overall firewall stability.
Detects FortiGate web-filter events where access to selected high-risk or security-relevant FortiGuard categories was not blocked. The monitored categories include malicious websites, phishing, spam URLs, Dynamic DNS, peer-to-peer file sharing, and crypto-mining destinations. The event should be investigated according to the specific category and destination context.
Detects the creation of new endpoint prevention policy rules for Windows, Linux, or macOS within the Cortex management audit logs. This activity allows security administrators to monitor changes to security posture and endpoint protection configurations.
Detects edits to existing Windows, Linux, or macOS endpoint prevention policy rules within Cortex management audit telemetry. These modifications can impact endpoint security posture, necessitating audit and verification to ensure changes were authorized and do not reduce security coverage.
Cortex Broker VM Collection Error
Cortex XDR
Detects error-classified data collection audit events associated with designated Cortex Broker VMs, identifying collection failures that may interrupt or degrade data ingestion.
Detects the initiation of an AWS Systems Manager (SSM) Session Manager session. The 'StartSession' API call is used to establish interactive remote shell sessions to managed instances (such as EC2). Monitoring this activity is critical for identifying potential remote administrative access, which could be abused for unauthorized management of cloud resources.
Detects modifications to BeyondTrust Password Safe administrative groups. This activity is critical to monitor as it can indicate an unauthorized attempt to alter privileged access models or maintain persistence by modifying identity permissions within the BeyondTrust environment.
GitHub Public Repository Created
Cortex XDR
Detects the creation of a new public repository within GitHub. This activity, while often legitimate, poses a potential data exposure risk by making code or sensitive assets publicly accessible. The rule identifies events where repository visibility is explicitly set to public for governance and security review.
Linux su Login Shell Invocation
Cortex XDR
Detects the invocation of the 'su' command with a login-shell style argument (e.g., 'su -'), which is used to switch user contexts and potentially elevate privileges.
Page 5 of 7
