Abnormal Security - Account Takeover case opened

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Creates an incident when Abnormal Security opens an Account Takeover (ATO) case, indicating a mailbox or user account is suspected to be compromised. The ATO case severity, status, and observed indicators are surfaced for triage.

Attribute Value
Type Analytic Rule
Solution AbnormalSecurity
ID da243bf4-382b-46b9-9b4d-ce6ffe9e7beb
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess, CredentialAccess
Techniques T1078, T1110
Required Connectors AbnormalSecurityPush
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
ABNORMAL_SECURITY_ATO_CASE_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to AbnormalSecurity