Databricks
Telemetry Evidence
These values show how indexed rules identify Databricks telemetry.Panther
Databricks.Audit databricks
Detection Rules
Panther #
- Databricks Access to Multiple Workspaces source medium: Detects users accessing 5 or more distinct workspaces within 24 hours, which may indicate lateral movement, reconnaissance, or compromised credentials.
T1021 - Databricks Access Token Revoked source informational: Detects revocation of Databricks access tokens. Token revocation may be routine credential rotation or could indicate an attacker covering their tracks after using a compromised token.
T1070 - Databricks Account Admin Privileged Role Assignment source medium: Detects when account-level admin privileges are granted in Databricks through direct role assignments or administrative group membership. Account admins have extensive control across all workspaces and should be carefully monitored. Successful grants are elevated to HIGH severity.
T1098,T1136 - Databricks Account-Level Configuration Changes source informational: Detects configuration changes at the Databricks account level, including account settings, metastore configurations, and SSO settings. Account-level changes affect all workspaces and should be monitored for unauthorized modifications.
T1098 - Databricks Attempted Logon From Denied IP source informational: Detects blocked login attempts from IP addresses explicitly denied by workspace IP access control policies. This excludes known service agents and telemetry operations. While these attempts were successfully blocked, they may indicate reconnaissance or unauthorized access attempts.
T1078 - Databricks Data Downloads From Control Plane source medium: Detects high volume data downloads from the control plane which may indicate data exfiltration. Monitors download actions including query results, notebooks, and models.
T1567 - Databricks Data Movement with Explicit Credentials source informational: Detects creation or modification of storage credentials, connections, and external locations that could facilitate data exfiltration. These operations establish direct paths to external storage and may indicate data movement preparation. Mount point creation is covered separately by Databricks.Audit.MountPointCreation.
T1537 - Databricks Delta Sharing IP Access Failures source medium: Detects blocked Delta Sharing access attempts due to IP access list restrictions, which may indicate unauthorized access attempts from unexpected locations.
T1078 - Databricks Delta Sharing Recipient Without IP ACLs source medium: Detects creation of Delta Sharing recipients without IP access list restrictions, which could allow unauthorized data access from any location.
T1685 - Databricks Destructive Activities source medium: Detects high volume destructive activities by a single user which may indicate malicious data destruction, ransomware, or insider threats.
T1485
Show 27 more
- Databricks Employee Logon source informational: Detects when a Databricks employee successfully logs into a workspace using GENIE_AUTH authentication. This is typically for legitimate support purposes but should be tracked for awareness.
T1078 - Databricks Global Init Script Changes source informational: Detects modifications to global initialization scripts which run on all clusters at startup. These scripts can be used for persistence or to execute malicious code across the environment. All script creations, updates, and deletions are monitored.
T1037,T1059 - Databricks Group Created source informational: Detects creation of user groups in Databricks. Group creation may be part of normal administration or could indicate privilege escalation preparation by creating a group that will later receive elevated permissions.
T1136 - Databricks Group Deleted source low: Detects group deletions in Databricks accounts. While often part of normal cleanup processes, unauthorized group deletions could indicate access control dismantling. Successful deletions are elevated to HIGH severity.
T1531 - Databricks High Priority Configuration Changes source medium: Detects high-priority security configuration changes including audit logging modifications, IP access list changes, and security-critical workspace settings. Severity is elevated for successful changes to high-risk settings.
T1098,T1685.002 - Databricks Install Library on All Clusters source medium: Detects use of the deprecated installLibraryOnAllClusters action. This anti-pattern can introduce security risks by installing potentially malicious libraries across the entire environment without proper review or controls.
T1203,T1543 - Databricks Long-Lifetime Token Generated source low: Detects generation of personal access tokens (PATs) with lifetime exceeding 72 hours. Long-lived tokens increase the risk of credential theft and unauthorized access if compromised. Tokens with lifetime >90 days are elevated to MEDIUM, >1 year to HIGH severity.
T1098,T1550 - Databricks Metastore Admin Privilege Granted source medium: Detects when metastore admin privileges are granted in Databricks through direct metastore ownership changes or addition to metastore admin groups. Metastore admins have extensive control over data access and governance policies in Unity Catalog.
T1098 - Databricks MFA Key Change source informational: Detects addition or deletion of MFA keys on Databricks accounts. MFA key deletion may indicate an attacker weakening account security, while unexpected additions may indicate enrollment of attacker-controlled authenticators.
T1556 - Databricks Mount Point Creation source informational: Detects creation of legacy mount points in Databricks. Mount points are deprecated in favor of Unity Catalog external locations and can pose security risks by bypassing access controls. This anti-pattern should be avoided in modern Databricks deployments.
T1021,T1074 - Databricks Non-SSO Login Detected source informational: Detects successful logins that bypass SSO (SAML). In organizations that enforce SSO, non-SAML logins may indicate credential compromise, misconfigured service accounts, or unauthorized access methods.
T1078 - Databricks Potential Privilege Escalation source high: Detects potential privilege escalation through high volume permission modifications (≥25 per hour) by the same user. Monitors various permission-related actions across account, workspace, and Unity Catalog.
T1078 - Databricks Principal Removed From Group source informational: Detects when principals (users or service principals) are removed from groups in Databricks accounts. This is often legitimate administrative activity but should be monitored for unauthorized membership changes.
T1098 - Databricks Repeated Access to Secrets source medium: Detects repeated secret access (≥10 times in 60 minutes) which may indicate credential harvesting or unauthorized secret enumeration.
T1555 - Databricks Repeated Failed Login Attempts source medium: Detects repeated failed login attempts within a 60-minute window, which may indicate credential stuffing, brute force attacks, or compromised credentials.
T1078,T1110 - Databricks Repeated Unauthorized UC Data Requests source high: Detects repeated unauthorized Unity Catalog data access attempts (>15 per hour) including credential generation failures and Delta Sharing access denials.
T1530 - Databricks Repeated Unauthorized Unity Catalog Requests source medium: Detects repeated unauthorized Unity Catalog API requests (>25 per hour) which may indicate reconnaissance, privilege enumeration, or unauthorized data access attempts.
T1087 - Databricks SSO Configuration Changed source low: Detects modifications to single sign-on (SSO) configurations in Databricks. While SSO changes may be part of planned identity provider updates, unauthorized modifications could indicate attempts to tamper with authentication mechanisms. Successful changes are elevated to MEDIUM severity.
T1556 - Databricks Terms of Service Changes source informational: Detects Terms of Service acceptance or distribution events for compliance tracking. These events should be monitored for audit and governance purposes.
- Databricks TruffleHog Scan Detected source medium: Detects TruffleHog secret scanning activity in Databricks. TruffleHog is a tool used to scan repositories and systems for exposed credentials and secrets. While it can be used legitimately for security audits, unauthorized scanning may indicate credential harvesting attempts. External IP sources are elevated to HIGH severity.
T1213,T1552 - Databricks User Account Created source informational: Detects creation of new user accounts in Databricks. Account creation may be part of normal onboarding or could indicate an attacker establishing persistence.
T1136 - Databricks User Account Deleted source low: Detects user account deletions in Databricks. While often part of normal offboarding processes, unauthorized deletions could indicate malicious activity or insider threats. Successful deletions are elevated to HIGH severity.
T1531 - Databricks User Password Changed source informational: Detects password change events on Databricks accounts. May indicate legitimate password rotation or an unauthorized reset following account compromise.
T1098 - Databricks User Role Modified source informational: Detects when user roles are modified or users are added to administrative groups in Databricks. This is often legitimate administrative activity but should be monitored for unauthorized changes.
T1098 - Databricks Verbose Audit Logging Disabled source high: Detects when verbose audit logging is disabled in a Databricks workspace. Disabling verbose audit logging significantly reduces the visibility of security-relevant events and is a common technique used by attackers to hide malicious activity. Successful disabling is elevated to CRITICAL severity.
T1685.002 - Databricks Workspace Admin Privileged Role Assignment source medium: Detects when workspace-level admin privileges are granted in Databricks through direct role assignments or administrative group membership. This simplified version detects direct admin grants and additions to admin groups. For nested group resolution (detecting when groups are added to admin groups), consider implementing a correlation rule. Successful grants to the system 'admins' group are elevated to HIGH severity.
T1098,T1136 - Databricks Workspace-Level Configuration Changes source informational: Detects configuration changes at the Databricks workspace level. Workspace-level changes affect a single workspace and include settings like cluster configurations, notebook settings, and workspace-specific security controls.
T1098