Anomalous login activity originated from Botnet, Tor proxy or C2

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Shows login activity (successful or failed) originated from botnet, Tor proxy or C2, with at least one 'True' activity insight.

Attribute Value
Type Hunting Query
Solution UEBA Essentials
ID c3b09dd3-ee50-41ae-b863-8603620e5f48
Required Connectors BehaviorAnalytics
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
BehaviorAnalytics ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to UEBA Essentials