Semantic labels
Four labels group rules by what they are about, across the vendors the search covers.
These labels are this site's own reading of each rule, not something the vendors publish, so expect gaps and check a rule's predicates before you rely on a match. Who or what acted. The access at stake. What the rule looks at. What happened.Identity
Value Meaning Rules applicationapplication / OAuth client identity 207 service_principalservice principal (Entra app-only or AD SPN) 172 useruser or delegated identity 781 rootAWS root account or Linux UID-0 identity 57 assumed_roletemporary STS-assumed-role or web-identity session 13 service_accountnon-human workload identity (K8s / GCP / Linux daemon) 37 externalexternal or guest identity (guest, B2B, outside collaborator) 28 Permission
Value Meaning Rules application_roleapplication role or permission assignment 20 mail_readMail.Read permission or equivalent 5 mail_readwriteMail.ReadWrite permission 3 mail_sendMail.Send permission 4 full_access_as_appExchange full mailbox access as an app 1 ews_mail_accessEWS mailbox access permission 3 pass_rolethe IAM PassRole action in an evaluated policy 10 wildcard_grantwildcard resource or principal in an IAM or resource policy 31 admin_rolenamed full-admin set (AdministratorAccess, Global Administrator) 21 Resource
Value Meaning Rules emailemail or message data 7 mailboxmailbox or mail folders 56 storageS3, GCS, or Azure Storage object or bucket 85 snapshotEC2/EBS or RDS snapshot 27 computeAzure VM, disk, or restore point 45 network_configsecurity group, NSG, firewall, or VPN configuration 64 fileSharePoint, OneDrive, or Drive document object 278 crypto_keycloud KMS or Key Vault cryptographic key 21 credentialcredential-bearing material (key, secret, token, credential path) 242 branch_protectionGitHub branch-protection rule or ruleset 12 ci_workflowGitHub Actions workflow run or job 8 workloadKubernetes Pod, Deployment, DaemonSet, Job, or CronJob 123 scheduled_taskcron or at persistence file 114 writable_directoryprocess run from a writable location (/tmp, /dev/shm) 112 kernel_modulekernel module load, removal, or enumeration 37 persistence_locationmacOS autostart directory (LaunchAgents, LaunchDaemons) 103 network_destinationnetwork destination (host, IP, port, or DNS query) 127 Operation
Value Meaning Rules mail_accessmailbox or message access 9 permission_grantpermission, role, or policy grant on any platform 70 oauth_consentOAuth application consent 17 logging_tamperaudit or detection logging disabled, deleted, or weakened 63 credential_creationnew durable credential material minted 33 data_deletiondestructive delete of a data or recovery resource 16 public_exposureresource made anonymously or internet-reachable 36 mfa_changeMFA factor or enforcement changed 46 policy_changeaccess-control policy changed (conditional access, Okta policy) 61 authenticationsign-in or logon telemetry, including failed auth 316 federation_changeexternal identity-provider trust relationship changed 41 mailbox_ruleinbox forwarding or transport rule created or modified 24 account_lifecycleuser, service, or guest identity created or deleted 44 secret_accessread or retrieval of stored secret material 21 service_tampersecurity-relevant Linux daemon stopped or disabled 80 interactive_accessinteractive or remote-shell session into compute 33 privileged_workloadKubernetes pod created with a container-escape spec 28 external_sharingcreation, use, or removal of a resource-sharing path across the tenant/org boundary 31 impersonationone identity acting as another 15 cryptominingcryptomining activity (mining pool, miner process) 22