TI map IP entity to Workday(ASimAuditEventLogs)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Detects a match in Workday activity from any IP Indicator of Compromise (IOC) provided by Threat Intelligence (TI).

Attribute Value
Type Analytic Rule
Solution Threat Intelligence (NEW)
ID 92e8e945-6e99-4e4b-bef8-468b4c19fc3a
Severity Medium
Kind Scheduled
Tactics CommandAndControl
Techniques T1071
Required Connectors ThreatIntelligence, ThreatIntelligenceTaxii, Workday, MicrosoftDefenderThreatIntelligence
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
ASimAuditEventLogs EventVendor == "Workday" ?
ThreatIntelIndicators ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Threat Intelligence (NEW)