NordPass - User deletes items in bulk

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This will alert you if a user deletes items in bulk, namely, more than 10 items or in the span of 10 minutes. If a mix of bulk and one-off deletions were performed, this will group all actions and report the total number of items deleted.

Attribute Value
Type Analytic Rule
Solution NordPass
ID f72f630f-c890-49fe-b747-80f4fb3b6348
Severity High
Kind Scheduled
Tactics Impact, Collection
Techniques T1485, T1074
Required Connectors NordPass
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
NordPassEventLogs_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to NordPass