
Lucas Pinho
@lucaslapinhoCompletionist
0 followers9 downloads111 copies0 likes282 views
62 detections
Filters
Last updated
All Time
Detection languages
61
1
Categories
18
16
6
6
5
Platforms
20
11
9
8
7
Products / Services
11
10
7
5
5
MITRE Techniques
12
12
11
10
9
Linux Ngrok Free Tunnel Domain Observed
Cortex XDR
Detects network or process telemetry containing the 'ngrok-free.app' domain, which indicates the use of ngrok tunnels to expose local services to the internet, potentially bypassing inbound firewall controls or serving as an unauthorized command-and-control channel.
Detects Cortex-managed endpoints that are currently in a disconnected state and are cross-referenced against an inventory of critical or sensitive assets. This rule highlights potential gaps in security monitoring and visibility for high-value systems.
Detects modifications to Active Directory objects of the class 'groupPolicyContainer' by monitoring Windows Security Event ID 5136. Unauthorized or unexpected GPO modifications can be used by attackers to weaken security controls, establish persistence, or facilitate privilege escalation across a domain.
Detects configuration events in BeyondTrust Password Safe where a user is added to a group containing 'Administrators' in its name. This behavior can indicate unauthorized privilege escalation or persistence within the BeyondInsight/Password Safe environment.
Imperva Protected Site Removed from WAF
Cortex XDR
Detects an audit event in Imperva Cloud WAF indicating that a protected site configuration has been removed. This action results in the loss of application-protection coverage for the specific site and may indicate unauthorized defensive impairment.
Detects configuration events in BeyondTrust Password Safe where a user is removed from a group containing 'Administrators' in its name. This monitors for potential unauthorized removal of administrative privileges or interference with operational access.
Detects FortiGate web-filter events where access to a domain categorized by FortiGuard as Newly Observed Domain or Newly Registered Domain was not blocked. Newly observed or recently registered domains can be legitimate, but they also warrant additional review because reputation and historical context may be limited.
Detects completed administrative actions associated with uninstalling the Cortex XDR endpoint agent. This operation significantly reduces security visibility and defense capabilities on the affected device and requires verification as an authorized action.
Generic rule content from file: MS_Entra_ID_Protection_Anonymous_IP_Risk.txt
Imperva New Protected Site Created
Cortex XDR
Detects the creation of a new site object within the Imperva Cloud WAF environment, as captured by audit trail logs. This event serves as an administrative signal to track onboarding of new applications and monitor for unauthorized or unexpected configuration changes.
Page 6 of 7
