The following table provides a brief description of what each analytic detects.
Analytic | Description |
|---|---|
abnormal_aws_ami | Abnormal Amazon Web Services (AWS) instance usage based on previously used AWS EC2 AMI types. |
abnormal_aws_apikey_usage | Suspicious AWS API key usage. |
abnormal_aws_console_login | Abnormal AWS Management Console login based on this user's previous login history. |
abnormal_aws_ssh_keypair_generated_imported | Abnormal generation of AWS SSH keys and subsequent import to AWS regions based on previous activity. |
abnormal_azure_resource_deployment | Abnormal Microsoft Azure deployment activity based on this user's previous resource deployments. |
abnormal_box_logon | Abnormal Box cloud account login based on this user's previous login history. |
abnormal_duo_logon | Abnormal Duo multi-factor authentication login based on this user's previous login history. |
abnormal_exchange_online_mailbox_access | Abnormal Microsoft 365 Exchange Online mailbox access based on this user's mailbox access history. |
abnormal_gcp_activity | Abnormal Google Cloud Platform (GCP) activity by a user. |
abnormal_gigya_logon | Abnormal Gigya login based on this user's previous login history. |
abnormal_google_workspace_logon | Abnormal Google Workspace login based on this user's previous login history. |
abnormal_ibm_webseal_activity | Abnormal IBM WebSEAL activity based on this user's previous login history. |
abnormal_lastpass_logon | Abnormal LastPass login activity based on this user's previous login history. |
abnormal_named_pipe_operation | Abnormal Windows named pipe activity. Named pipes are typically used to transfer data between processes without needing to use the network stack. Malware also frequently uses named pipes, which could leave artifacts in the Windows event log. |
abnormal_o365_logon | Abnormal Microsoft Office 365 login based on this user's previous login history. |
abnormal_okta_logon | Abnormal Okta login based on this user's previous login history. |
abnormal_salesforce_logon | Abnormal Salesforce.com login based on this user's previous login history. |
abnormal_sharepoint_file_transfer | Abnormal SharePoint file download or upload based on this user's previous history. |
abnormal_vmware_uag_logon | Abnormal VMware UAG login based on this user's previous login history. |
abnormal_vpn_logon | Abnormal VPN login based on this user's previous login history. |
abnormal_windows_rdp_logon | Abnormal Remote Desktop Protocol (RDP) login based on this user’s previous login history. |
abnormal_windows_runas_logon | Abnormal RunAs login, commonly used to move laterally with stolen credentials. This may indicate anomalous originating processes, target users, or both. |
abnormal_windows_service | Abnormal Windows service installation events (eventid=7045). This creates a baseline for and scores events that include never-before-seen (NBS) users creating a service, uncommon service names, uncommon file paths across the organization, and suspicious file paths. |
abnormal_wmi_consumer_filter_binding | Abnormal Windows Management Instrumentation (WMI) filter bindings. This could indicate activities from creating the initial foothold on a system up to and including stealing data from the environment. |
av_edr_outbreak | The same threat from antivirus (AV) sources, endpoint detection and response (EDR) sources, or both types of sources on several unique hosts at about the same time. This could indicate an outbreak. |
aws_console_login_brute_force | AWS Management Console brute force detection. This performs checks for password spray and successful logins from the same source. |
aws_recon | Many different list* and describe* actions from one AWS user. This could indicate AWS reconnaissance. |
aws_s3_bucket_scan | GetBucketLocation actions from one AWS user to many Amazon S3 buckets. This could indicate S3 bucket reconnaissance. |
azure_mfa_fatigue | Azure multi-factor authentication (MFA) fatigue. This detects instances of Azure MFA fatigue attacks. MFA fatigue attacks send multiple fraudulent push notifications in an attempt to gain access to a user’s account. |
beacon_detect | Beaconing activity detection. This could indicate that a host is infected with malware, and reaching out to a command and control server. |
box_brute_force | Box cloud account brute force detection. This performs checks for password spray and successful logins from the same source. |
cisco_asa_brute_force | Cisco ASA brute force detection. This performs checks for password spray and successful logins from the same source. |
cisco_ise_radius_brute_force | Cisco ISE radius logs brute force detection. This performs checks for password spray and successful logins from the same source. |
citrix_netscaler_brute_force | Citrix NetScaler brute force detection. This performs checks for password spray and successful logins from the same source. |
dc_alert_agg | Multiple detection rules matched events related to a domain controller. |
disabled_user_list | List of disabled Microsoft Windows user accounts. |
domain_hunter | A never-before-seen (NBS) domain was detected. This checks both the FQDN and parent domain. It looks for domains with recent registration dates, potential DNS tunneling, and potential domain masquerading. |
druva_brute_force | Druva brute force detection. This performs checks for password spray and successful logins from the same source. |
duo_mfa_fatigue | Duo multi-factor authentication (MFA) fatigue. This detects instances of Duo MFA fatigue attacks. MFA fatigue attacks send multiple fraudulent push notifications in an attempt to gain access to a user’s account. |
entrust_brute_force | Entrust IntelliTrust brute force detection. This performs checks for password spray and successful logins from the same source. |
epic_brute_force | Epic Systems brute force detection. This performs checks for password spray and successful logins from the same source. |
gcp_cross_project_image | Google Cloud Platform (GCP) images inserted into a project that is not the source. |
home_domain_permutation | Network traffic to domains that are similar to (permutations of) the customer’s discovered “home domain.” This may indicate a phishing attack or some other suspicious activity. |
hx_weaksignal | Multiple unique Endpoint Security (HX) weak signal IOCs found on one system within a short time. This requires a list of Endpoint Security (HX) IOCs named "hx.weaksignal." |
legitimate_web_service_url_analyzer | Anomalies found from analyzing this URL. This could indicate abuse of a legitimate web service to spread malware or to organize botnet command and control infrastructure. |
linux_brute_force | Linux brute force detection. This performs checks for password spray and successful logins from the same source. |
linux_decode | Linux auditd decoder. |
logtracker | Detection of missing log source events and fluctuations in event volume. |
multistage_rule | A multistage rule fired. |
o365_brute_force | Office 365 brute force detection. This performs checks for password spray and successful logins from the same source. |
okta_brute_force | Okta brute force detection. This performs checks for password spray and successful logins from the same source. |
okta_mfa_fatigue | Okta multi-factor authentication (MFA) fatigue. This detects instances of Okta MFA fatigue attacks. |
outbound_data | Anomaly detection for outbound network traffic volume. |
phish_correlation | Phishing URL from a Trellix Email Security — Server alert that is correlated to unblocked HTTP traffic. This indicates that a user may be a victim of an unblocked phishing URL. Check logs for further evidence of compromise. |
powershell_url | Suspicious powershell activity observed by detecting a sequence of process creation, URL request, and file write events within a short time frame. This analytic is powered by IOC streamer telemetry. |
process_ip | Possible ingress tool transfer activity leveraging and chaining network and file write events that originate from the same process within a short time frame. This analytic is powered by IOC streamer telemetry. |
process_tracker | A never-before-seen (NBS) process by this user on this host was detected in this environment. This analytic is powered by Windows logs. |
process_url | Possible ingress tool transfer activity leveraging and chaining Internet traffic and file write events that originate from the same process within a short time frame. This analytic is powered by IOC streamer telemetry. |
psexec_service_masquerading | Windows service installations that appear to be masquerading as the PsExec program. |
rdp_multiple_hosts | Multiple host RDP logins by same user. |
rdp_multiple_users | Multiple user RDP logins to same host. |
salesforce_brute_force | Salesforce brute force detection. This performs checks for password spray and successful logins from the same source. |
sourcefire_multiple_rules | Multiple distinct Sourcefire rules from one source IP address. |
useragent_tracker | A never-before-seen (NBS) user agent was detected in this environment. |
user_deleted_within_24hours | A user account was deleted within 24 hours of its creation. |
windows_brute_force | Windows NT LAN Manager (NTLM) brute force detection. This performs checks for password spray and successful logins from the same source. |
windows_kerberos_user_enum | Multiple "unique users not found" errors from one source. This could indicate a user enumeration attempt. |
windows_recon_commands | Several unique processes from one user or host within a short period of time. This could indicate reconnaissance activity. |
windows_scheduled_tasks_backdoor | Modification of a Windows scheduled task which is executed on the same host within a short period of time. This could indicate an attempt to use the task scheduler as a backdoor. |
windows_share_scanning | Windows share scanning detection. This correlates a host with the following sequence of events: multiple failed Windows share attempts, successful access to shares, and new services being created on at least one target system. |