Skip to content

#detection-rule

12 approved public terms with this tag.

Access Detection Rule is a security security analytic that matches suspicious behavior or known indicators for authorization and privilege control. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Application Detection Rule is a security security analytic that matches suspicious behavior or known indicators for software security and abuse resistance. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Cloud Detection Rule is a security security analytic that matches suspicious behavior or known indicators for cloud account and resource security. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Data Loss Detection Rule is a security security analytic that matches suspicious behavior or known indicators for sensitive data exposure risk. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Endpoint Detection Rule is a security security analytic that matches suspicious behavior or known indicators for user device and server protection. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Identity Detection Rule is a security security analytic that matches suspicious behavior or known indicators for user and workload identity. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Incident Response Detection Rule is a security security analytic that matches suspicious behavior or known indicators for security event handling. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Secrets Detection Rule is a security security analytic that matches suspicious behavior or known indicators for keys, tokens, and credentials. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Detection Rule is a security security analytic that matches suspicious behavior or known indicators for dependencies, builds, and artifacts. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Threat Intel Detection Rule is a security security analytic that matches suspicious behavior or known indicators for external risk and indicator context. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Vulnerability Detection Rule is a security security analytic that matches suspicious behavior or known indicators for weakness tracking and remediation. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Zero Trust Detection Rule is a security security analytic that matches suspicious behavior or known indicators for continuous verification model. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.