Theom - Critical data in API headers or body

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Creates Sentinel incidents for critical/high Theom risks, associated with ruleId's TRIS0007 to TRIS0010 and TRIS0014

Attribute Value
Type Analytic Rule
Solution Theom
ID 2ef36aaa-ec4a-473a-9734-f364ce8868f8
Severity High
Status Available
Kind Scheduled
Tactics Collection
Techniques T1119
Required Connectors Theom
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
TheomAlerts_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Theom