OOTB Rules

Datadog provides out-of-the-box (OOTB) detection rules to flag attacker techniques and potential misconfigurations so you can immediately take steps to remediate. Datadog continuously develops new default rules, which are automatically imported into your account, your App and API Protection library, and the Agent, depending on your configuration.

Datadog's Security Research team continuously adds new OOTB security detection rules. While the aim is to deliver high-quality detections with the release of integrations or other new features, the performance of these detections at scale often needs to be observed before making the rule generally available. These rules contain a Beta tag. This gives Datadog's Security Research team time to either refine or deprecate detection opportunities that do not meet Datadog's standards.

Click the following buttons to filter the detection rules. Security detection rules are available for App and API Protection, Cloud SIEM (log detection and signal correlation), CSM Misconfigurations (cloud and infrastructure), Workload Protection, CSM Identity Risks, and Attack Paths.

Application Security
>
application-security API scan detected on service
application-security Attack Tool
application-security Bruteforce attack
application-security Cassandra injection vulnerability triggered
application-security Command injection attempt detected
application-security Command injection exploited
application-security Commercial vulnerability scanner
application-security CQL injections attempts
application-security Credential Stuffing attack
application-security Distributed Credential Stuffing campaign (attacker fingerprint)
application-security Distributed Credential Stuffing campaign (attempt count)
application-security Distributed Credential Stuffing campaign (user count)
application-security Excessive account deletion from an IP
application-security Excessive payment failures from IP
application-security Excessive resource consumption of third-party API
application-security Excessive sensitive activity from an IP (SDK instrumented)
application-security Excessive sensitive activity from an IP (WAF instrumented)
application-security Feature returning private information abused by IP
application-security Impossible travel observed from business logic event
application-security Java code injections attempts
application-security JWT authentication bypass attempt
application-security Local File Inclusion (LFI) attack attempts
application-security Local file inclusion exploited
application-security Log4shell RCE attempts - CVE-2021-44228
application-security Log4shell vulnerability triggered (RCE) - CVE-2021-44228
application-security Mongo injections attempts
application-security OGNL injection attack attempts on routes parsing OGNL
application-security Password reset token bruteforce
application-security Reflected XSS attempts on routes returning HTML
application-security Resource enumeration detected
application-security Security scanner detected
application-security Spring4shell RCE attempts - CVE-2022-22963
application-security SQL injection exploited
application-security SQL injections attempts
application-security SSRF attempts on routes executing network queries
application-security SSRF exploited
application-security Unauthenticated activity detected
application-security Unauthorized activity detected
application-security Unusual account creations from an IP
application-security Unusual password reset rate activity
application-security User activity detected from outside authorized countries
application-security User activity detected from unauthorized countries
application-security User activity from Tor
application-security User enumeration through password reset
application-security User has changed country
application-security User has used a disposable email address
PREVIEWING: dgreen15/adding-custom-entities
Your Privacy Choices