Zero Networks Segment - Rare JIT Rule Creation

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies when a JIT Rule connection is new or rare by a given account today based on comparison with the previous 14 days. JIT Rule creations are indicated by the Activity Type Id 20

Attribute Value
Type Analytic Rule
Solution ZeroNetworks
ID 58688058-68b2-4b39-8009-ac6dc4d81ea1
Severity Medium
Status Available
Kind Scheduled
Tactics LateralMovement
Techniques T1021
Required Connectors ZeroNetworksSegmentAuditFunction, ZeroNetworksSegmentAuditNativePoller
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
ZNAudit_CL ? ?
ZNSegmentAuditNativePoller_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to ZeroNetworks