Request a demo

Request a demo

Detection Coverage

Panther offers hundreds of ready-to-use detections! Search by keyword or log type below.

Detection

Log Type

Type

Description

Crowdstrike.FDREvent

Crowdstrike.FDREvent

OnePassword.SignInAttempt

OnePassword.SignInAttempt

Scheduled Query

Looks for OnePassword Logins from IP Addresses that aren't seen in CrowdStrike's AIP List. (crowdstrike_fdrevent table)

AWS.CloudTrail

AWS.CloudTrail

Rule

A CloudTrail Trail was created, updated, or enabled.

Osquery.Differential

Osquery.Differential

Rule

A system has been logged into from a non approved IP space.

Gravitational.TeleportAudit

Gravitational.TeleportAudit

Rule

An unusually long-lived Teleport certificate was created

Gravitational.TeleportAudit

Gravitational.TeleportAudit

Rule

A SAML connector was created or modified

Gravitational.TeleportAudit

Gravitational.TeleportAudit

Rule

A Teleport Lock was created

Gravitational.TeleportAudit

Gravitational.TeleportAudit

Rule

A Teleport Role was modified or created

Gravitational.TeleportAudit

Gravitational.TeleportAudit

Rule

A user authenticated with SAML, but from an unknown company domain

Gravitational.TeleportAudit

Gravitational.TeleportAudit

Rule

A User from the company domain(s) Logged in without SAML

Panther.Audit

Panther.Audit

Rule

A Panther user role has been created that contains admin level permissions.

Load More

Load More

Load More

Load More