Vectra AI Detect - Detections with High Severity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Create an incident for high severity malicious behavior detected by Vectra AI (Threat score superior to 7.0). The Severity is a mapping with the Threat score assigned to a detection. It ranges between 0 and 10. The severity_threshold variable can be adjusted as desired.

Attribute Value
Type Analytic Rule
Solution Vectra AI Detect
ID 39e48890-2c02-487e-aa9e-3ba494061798
Severity High
Status Available
Kind Scheduled
Tactics CredentialAccess, Discovery, LateralMovement, Collection, CommandAndControl, Exfiltration, Impact
Techniques T1003, T1087, T1021, T1119, T1071, T1041, T1499
Required Connectors CefAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CommonSecurityLog DeviceEventClassID != "asc"
DeviceEventClassID != "audit"
DeviceEventClassID != "campaigns"
DeviceEventClassID != "health"
DeviceEventClassID != "hsc"
DeviceProduct == "X Series"
DeviceVendor == "Vectra Networks"
?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Vectra AI Detect