Detect potential file enumeration activity (ASIM Web Session)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This detection method identifies potential cases of file enumeration activity. The query is designed to identify client sources that generate multiple requests resulting in 404 error codes

Attribute Value
Type Analytic Rule
Solution Web Session Essentials
ID b3731ce1-1f04-47c4-95c2-9827408c4375
Severity Medium
Status Available
Kind Scheduled
Tactics Discovery, CommandAndControl, CredentialAccess
Techniques T1083, T1071, T1110
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Web Session Essentials