Retrospective hunt for Forest Blizzard IP IOCs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Matches domain name IOCs related to Forest Blizzard group activity with CommonSecurityLog and SecurityAlert dataTypes. The query is scoped in the time window that these IOCs were active.

Attribute Value
Type Hunting Query
Solution Legacy IOC based Threat Protection
ID b8b7574f-1cd6-4308-822a-ab07256106f8
Severity High
Tactics CommandAndControl
Techniques T1071
Required Connectors CiscoASA, CiscoAsaAma, PaloAltoNetworks, AzureSecurityCenter
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CommonSecurityLog ?
SecurityAlert ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Legacy IOC based Threat Protection