CYFIRMA - Brand Intelligence - Product/Solution Medium Rule

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This alert is raised when CYFIRMA detects a critical reputation score for an IP address linked to your infrastructure. The IP has been previously associated with hacking activity and web application attacks. Denied outbound traffic to a foreign country from a known Microsoft data center IP suggests potential misuse or compromise of cloud infrastructure.

Attribute Value
Type Analytic Rule
Solution Cyfirma Brand Intelligence
ID 458d964f-d039-4ce0-9741-0b6245ba3374
Severity Medium
Status Available
Kind Scheduled
Tactics ResourceDevelopment, InitialAccess
Techniques T1585.002, T1583.001, T1566, T1583
Required Connectors CyfirmaBrandIntelligenceAlertsDC
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CyfirmaBIProductSolutionAlerts_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Cyfirma Brand Intelligence