Disabled accounts using Squid proxy

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Query finds accounts recorded as disabled by AD in previous time period but still using proxy in current time period. Presumes default squid log format is used. http://www.squid-cache.org/Doc/config/access_log/

Attribute Value
Type Hunting Query
Solution Standalone Content
ID 959fe0f0-7ac0-467c-944f-5b8c6fdc9e72
Tactics CredentialAccess
Techniques T1110
Required Connectors Syslog
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
SigninLogs ?
Syslog ProcessName contains "squid" ?

Associated Connectors

The following connectors provide data for this content item:

Connector Solution
AzureActiveDirectory Microsoft Entra ID
CiscoMeraki(usingRESTAPI) CiscoMeraki
CiscoMerakiNativePoller CiscoMeraki
CiscoSDWAN Cisco SD-WAN
Forescout Forescout (Legacy)

Solutions: Cisco SD-WAN, CiscoMeraki, Forescout (Legacy), Microsoft Entra ID


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries