Claroty - Unresolved alerts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Query searches for Claroty alerts with unresolved status to identify alerts that remain open for investigation.

Attribute Value
Type Hunting Query
Solution Claroty
ID fad6cb81-9a05-4acb-9c5b-a7c62af28034
Severity Medium
Tactics InitialAccess, Discovery, Impact
Techniques T1190, T1082, T1499
Required Connectors CefAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CommonSecurityLog DeviceVendor == "Claroty"

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Claroty