Detection Coverage
Panther offers hundreds of ready-to-use detections! Search by keyword or log type below.
Detection
Log Type
Type
Description
Scheduled Query
Looks for OnePassword Logins from IP Addresses that aren't seen in CrowdStrike's AIP List. (crowdstrike_fdrevent table)
Rule
A system has been logged into from a non approved IP space.
Rule
A user authenticated with SAML, but from an unknown company domain
Rule
A User from the company domain(s) Logged in without SAML
Rule
A Panther user role has been created that contains admin level permissions.