Analytics list

Prev Next

The following table provides a brief description of what each analytic detects.

Analytic

Description

abnormal_aws_ami

Abnormal Amazon Web Services (AWS) instance usage based on previously used AWS EC2 AMI types.

abnormal_aws_apikey_usage

Suspicious AWS API key usage.

abnormal_aws_console_login

Abnormal AWS Management Console login based on this user's previous login history.

abnormal_aws_ssh_keypair_generated_imported

Abnormal generation of AWS SSH keys and subsequent import to AWS regions based on previous activity.

abnormal_azure_resource_deployment

Abnormal Microsoft Azure deployment activity based on this user's previous resource deployments.

abnormal_box_logon

Abnormal Box cloud account login based on this user's previous login history.

abnormal_duo_logon

Abnormal Duo multi-factor authentication login based on this user's previous login history.

abnormal_exchange_online_mailbox_access

Abnormal Microsoft 365 Exchange Online mailbox access based on this user's mailbox access history.

abnormal_gcp_activity

Abnormal Google Cloud Platform (GCP) activity by a user.

abnormal_gigya_logon

Abnormal Gigya login based on this user's previous login history.

abnormal_google_workspace_logon

Abnormal Google Workspace login based on this user's previous login history.

abnormal_ibm_webseal_activity

Abnormal IBM WebSEAL activity based on this user's previous login history.

abnormal_lastpass_logon

Abnormal LastPass login activity based on this user's previous login history.

abnormal_named_pipe_operation

Abnormal Windows named pipe activity. Named pipes are typically used to transfer data between processes without needing to use the network stack. Malware also frequently uses named pipes, which could leave artifacts in the Windows event log.

abnormal_o365_logon

Abnormal Microsoft Office 365 login based on this user's previous login history.

abnormal_okta_logon

Abnormal Okta login based on this user's previous login history.

abnormal_salesforce_logon

Abnormal Salesforce.com login based on this user's previous login history.

abnormal_sharepoint_file_transfer

Abnormal SharePoint file download or upload based on this user's previous history.

abnormal_vmware_uag_logon

Abnormal VMware UAG login based on this user's previous login history.

abnormal_vpn_logon

Abnormal VPN login based on this user's previous login history.

abnormal_windows_rdp_logon

Abnormal Remote Desktop Protocol (RDP) login based on this user’s previous login history.

abnormal_windows_runas_logon

Abnormal RunAs login, commonly used to move laterally with stolen credentials. This may indicate anomalous originating processes, target users, or both.

abnormal_windows_service

Abnormal Windows service installation events (eventid=7045). This creates a baseline for and scores events that include never-before-seen (NBS) users creating a service, uncommon service names, uncommon file paths across the organization, and suspicious file paths.

abnormal_wmi_consumer_filter_binding

Abnormal Windows Management Instrumentation (WMI) filter bindings. This could indicate activities from creating the initial foothold on a system up to and including stealing data from the environment.

av_edr_outbreak

The same threat from antivirus (AV) sources, endpoint detection and response (EDR) sources, or both types of sources on several unique hosts at about the same time. This could indicate an outbreak.

aws_console_login_brute_force

AWS Management Console brute force detection. This performs checks for password spray and successful logins from the same source.

aws_recon

Many different list* and describe* actions from one AWS user. This could indicate AWS reconnaissance.

aws_s3_bucket_scan

GetBucketLocation actions from one AWS user to many Amazon S3 buckets. This could indicate S3 bucket reconnaissance.

azure_mfa_fatigue

Azure multi-factor authentication (MFA) fatigue. This detects instances of Azure MFA fatigue attacks. MFA fatigue attacks send multiple fraudulent push notifications in an attempt to gain access to a user’s account.

beacon_detect

Beaconing activity detection. This could indicate that a host is infected with malware, and reaching out to a command and control server.

box_brute_force

Box cloud account brute force detection. This performs checks for password spray and successful logins from the same source.

cisco_asa_brute_force

Cisco ASA brute force detection. This performs checks for password spray and successful logins from the same source.

cisco_ise_radius_brute_force

Cisco ISE radius logs brute force detection. This performs checks for password spray and successful logins from the same source.

citrix_netscaler_brute_force

Citrix NetScaler brute force detection. This performs checks for password spray and successful logins from the same source.

dc_alert_agg

Multiple detection rules matched events related to a domain controller.

disabled_user_list

List of disabled Microsoft Windows user accounts.

domain_hunter

A never-before-seen (NBS) domain was detected. This checks both the FQDN and parent domain. It looks for domains with recent registration dates, potential DNS tunneling, and potential domain masquerading.

druva_brute_force

Druva brute force detection. This performs checks for password spray and successful logins from the same source.

duo_mfa_fatigue

Duo multi-factor authentication (MFA) fatigue. This detects instances of Duo MFA fatigue attacks. MFA fatigue attacks send multiple fraudulent push notifications in an attempt to gain access to a user’s account.

entrust_brute_force

Entrust IntelliTrust brute force detection. This performs checks for password spray and successful logins from the same source.

epic_brute_force

Epic Systems brute force detection. This performs checks for password spray and successful logins from the same source.

gcp_cross_project_image

Google Cloud Platform (GCP) images inserted into a project that is not the source.

home_domain_permutation

Network traffic to domains that are similar to (permutations of) the customer’s discovered “home domain.” This may indicate a phishing attack or some other suspicious activity.

hx_weaksignal

Multiple unique Endpoint Security (HX) weak signal IOCs found on one system within a short time. This requires a list of Endpoint Security (HX) IOCs named "hx.weaksignal."

legitimate_web_service_url_analyzer

Anomalies found from analyzing this URL. This could indicate abuse of a legitimate web service to spread malware or to organize botnet command and control infrastructure.

linux_brute_force

Linux brute force detection. This performs checks for password spray and successful logins from the same source.

linux_decode

Linux auditd decoder.

logtracker

Detection of missing log source events and fluctuations in event volume.

multistage_rule

A multistage rule fired.

o365_brute_force

Office 365 brute force detection. This performs checks for password spray and successful logins from the same source.

okta_brute_force

Okta brute force detection. This performs checks for password spray and successful logins from the same source.

okta_mfa_fatigue

Okta multi-factor authentication (MFA) fatigue. This detects instances of Okta MFA fatigue attacks.

outbound_data

Anomaly detection for outbound network traffic volume.

phish_correlation

Phishing URL from a Trellix Email Security — Server alert that is correlated to unblocked HTTP traffic. This indicates that a user may be a victim of an unblocked phishing URL. Check logs for further evidence of compromise.

powershell_url

Suspicious powershell activity observed by detecting a sequence of process creation, URL request, and file write events within a short time frame. This analytic is powered by IOC streamer telemetry.

process_ip

Possible ingress tool transfer activity leveraging and chaining network and file write events that originate from the same process within a short time frame. This analytic is powered by IOC streamer telemetry.

process_tracker

A never-before-seen (NBS) process by this user on this host was detected in this environment. This analytic is powered by Windows logs.

process_url

Possible ingress tool transfer activity leveraging and chaining Internet traffic and file write events that originate from the same process within a short time frame. This analytic is powered by IOC streamer telemetry.

psexec_service_masquerading

Windows service installations that appear to be masquerading as the PsExec program.

rdp_multiple_hosts

Multiple host RDP logins by same user.

rdp_multiple_users

Multiple user RDP logins to same host.

salesforce_brute_force

Salesforce brute force detection. This performs checks for password spray and successful logins from the same source.

sourcefire_multiple_rules

Multiple distinct Sourcefire rules from one source IP address.

useragent_tracker

A never-before-seen (NBS) user agent was detected in this environment.

user_deleted_within_24hours

A user account was deleted within 24 hours of its creation.

windows_brute_force

Windows NT LAN Manager (NTLM) brute force detection. This performs checks for password spray and successful logins from the same source.

windows_kerberos_user_enum

Multiple "unique users not found" errors from one source. This could indicate a user enumeration attempt.

windows_recon_commands

Several unique processes from one user or host within a short period of time. This could indicate reconnaissance activity.

windows_scheduled_tasks_backdoor

Modification of a Windows scheduled task which is executed on the same host within a short period of time. This could indicate an attempt to use the task scheduler as a backdoor.

windows_share_scanning

Windows share scanning detection. This correlates a host with the following sequence of events: multiple failed Windows share attempts, successful access to shares, and new services being created on at least one target system.