TI map IP entity to Workday(ASimAuditEventLogs)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Detects a match in Workday activity from any IP Indicator of Compromise (IOC) provided by Threat Intelligence (TI).

Attribute Value
Type Analytic Rule
Solution Threat Intelligence
ID a924d317-03d2-4420-a71f-4d347bda4bd8
Severity Medium
Kind Scheduled
Tactics CommandAndControl
Techniques T1071
Required Connectors ThreatIntelligence, ThreatIntelligenceTaxii, Workday, MicrosoftDefenderThreatIntelligence
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
ASimAuditEventLogs EventVendor == "Workday" ?
ThreatIntelligenceIndicator ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Threat Intelligence