SpyCloud Enterprise Malware Detection

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This alert creates an incident when an malware record is detected in the SpyCloud watchlist data

Attribute Value
Type Analytic Rule
Solution SpyCloud Enterprise Protection
ID 7ba50f9e-2f94-462b-a54b-8642b8c041f5
Severity High
Status Available
Kind Scheduled
Tactics CredentialAccess
Techniques T1555
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SpyCloudBreachDataWatchlist_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to SpyCloud Enterprise Protection