Cayosoft Guardian - Core Identity and Infrastructure Threats

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Creates Microsoft Sentinel incidents for identity and infrastructure security threats reported by Cayosoft Guardian across on-premises Active Directory and Microsoft Entra ID. This includes threats related to accounts, service accounts, computers, security groups, and trusted domains. Incident severity is determined dynamically based on the severity of the detected threat. This rule complements the Cloud Application Security Threats rule, which covers cloud application and service principal thr

Attribute Value
Type Analytic Rule
Solution Cayosoft Guardian
ID 4720d7a5-6845-4ce4-aa45-79334e1a1176
Severity Medium
Status Available
Kind Scheduled
Required Connectors CayosoftGuardianConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CayosoftThreatAlerts_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Cayosoft Guardian