Skip to content

#detection-rule

12 approved public terms with this tag.

Access Detection Rule is a security security analytic that matches suspicious behavior or known indicators for authorization and privilege control. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Access Detection Rule when a role gained new permissions, so the team could surface actionable alerts before the risk review began.

Application Detection Rule is a security security analytic that matches suspicious behavior or known indicators for software security and abuse resistance. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Application Detection Rule when a form received unusual input, so the team could surface actionable alerts before the risk review began.

Cloud Detection Rule is a security security analytic that matches suspicious behavior or known indicators for cloud account and resource security. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Cloud Detection Rule when a storage bucket changed policy, so the team could surface actionable alerts before the risk review began.

Data Loss Detection Rule is a security security analytic that matches suspicious behavior or known indicators for sensitive data exposure risk. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Data Loss Detection Rule when a report included private metadata, so the team could surface actionable alerts before the risk review began.

Endpoint Detection Rule is a security security analytic that matches suspicious behavior or known indicators for user device and server protection. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Endpoint Detection Rule when a workstation reported suspicious activity, so the team could surface actionable alerts before the risk review began.

Identity Detection Rule is a security security analytic that matches suspicious behavior or known indicators for user and workload identity. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Identity Detection Rule when a service account requested access, so the team could surface actionable alerts before the risk review began.

Incident Response Detection Rule is a security security analytic that matches suspicious behavior or known indicators for security event handling. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Incident Response Detection Rule when an alert escalated to response, so the team could surface actionable alerts before the risk review began.

Secrets Detection Rule is a security security analytic that matches suspicious behavior or known indicators for keys, tokens, and credentials. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Secrets Detection Rule when a secret appeared in logs, so the team could surface actionable alerts before the risk review began.

Supply Chain Detection Rule is a security security analytic that matches suspicious behavior or known indicators for dependencies, builds, and artifacts. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Supply Chain Detection Rule when a package update arrived, so the team could surface actionable alerts before the risk review began.

Threat Intel Detection Rule is a security security analytic that matches suspicious behavior or known indicators for external risk and indicator context. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Threat Intel Detection Rule when a new campaign indicator appeared, so the team could surface actionable alerts before the risk review began.

Vulnerability Detection Rule is a security security analytic that matches suspicious behavior or known indicators for weakness tracking and remediation. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Vulnerability Detection Rule when a scanner found a critical issue, so the team could surface actionable alerts before the risk review began.

Zero Trust Detection Rule is a security security analytic that matches suspicious behavior or known indicators for continuous verification model. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

The security team used Zero Trust Detection Rule when a device changed posture, so the team could surface actionable alerts before the risk review began.