Cisco Cloud Security - Rare User Agent Detected

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Rule helps to detect a rare user-agents indicating web browsing activity by an unusual process other than a web browser.

Attribute Value
Type Analytic Rule
Solution CiscoUmbrella
ID 8c8de3fa-6425-4623-9cd9-45de1dd0569a
Severity Medium
Status Available
Kind Scheduled
Tactics CommandAndControl, Exfiltration
Techniques T1071.001, T1041
Required Connectors CiscoUmbrellaDataConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Cisco_Umbrella_audit_CL 🔶 ? ?
Cisco_Umbrella_cloudfirewall_CL 🔶 ? ?
Cisco_Umbrella_dlp_CL 🔶 ? ?
Cisco_Umbrella_dns_CL 🔶 ? ?
Cisco_Umbrella_fileevent_CL 🔶 ? ?
Cisco_Umbrella_intrusion_CL 🔶 ? ?
Cisco_Umbrella_ip_CL 🔶 ? ?
Cisco_Umbrella_proxy_CL 🔶 ? ?
Cisco_Umbrella_ravpnlogs_CL 🔶 ? ?
Cisco_Umbrella_ztaflow_CL 🔶 ? ?
Cisco_Umbrella_ztna_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to CiscoUmbrella