Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
Identifies the first time a source IP communicates with a destination using a specific port based on learning period activity. Configurable Parameters: - Learning period time - learning period for threshold calculation in days. Default is set to 7.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Azure Firewall |
| ID | 932fe71a-7a8c-4f35-bf88-321ab68ff562 |
| Tactics | Exfiltration, CommandAndControl |
| Required Connectors | AzureFirewall |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
AZFWApplicationRule |
✓ | ✗ | ? |
AZFWNetworkRule |
✓ | ✗ | ? |
AzureDiagnostics 🔶 |
? | ✗ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊