Skip to content

Commit

Permalink
Add references to rules (panther_audit_rules)
Browse files Browse the repository at this point in the history
  • Loading branch information
akozlovets098 committed Dec 12, 2023
1 parent 5c73412 commit 0b471c5
Show file tree
Hide file tree
Showing 4 changed files with 4 additions and 0 deletions.
1 change: 1 addition & 0 deletions rules/panther_audit_rules/panther_detection_deleted.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ Reports:
- TA0005:T1562
Description: Detection content has been removed from Panther.
Runbook: Ensure this change was approved and appropriate.
Reference: https://docs.panther.com/system-configuration/panther-audit-logs/querying-and-writing-detections-for-panther-audit-logs
SummaryAttributes:
- p_any_ip_addresses
Tests:
Expand Down
1 change: 1 addition & 0 deletions rules/panther_audit_rules/panther_saml_modified.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ Reports:
- TA0005:T1562
Description: An Admin has modified Panther's SAML configuration.
Runbook: Ensure this change was approved and appropriate.
Reference: https://docs.panther.com/system-configuration/saml
SummaryAttributes:
- p_any_ip_addresses
- p_any_usernames
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ Reports:
- TA0003:T1098
Description: A Panther user role has been created that contains admin level permissions.
Runbook: Contact the creator of this role to ensure its creation was appropriate.
Reference: https://docs.panther.com/system-configuration/rbac
SummaryAttributes:
- p_any_ip_addresses
Tests:
Expand Down
1 change: 1 addition & 0 deletions rules/panther_audit_rules/panther_user_modified.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ Reports:
- TA0003:T1098
Description: A Panther user's role has been modified. This could mean password, email, or role has changed for the user.
Runbook: Validate that this user modification was intentional.
Reference: https://docs.panther.com/panther-developer-workflows/api/operations/user-management
SummaryAttributes:
- p_any_ip_addresses
Tests:
Expand Down

0 comments on commit 0b471c5

Please sign in to comment.