CybereinforceCTE_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (10 columns)

Source: KQL validation test schema

Column Name Type
Actor string
Category string
Details dynamic
Entity string
EntityId string
EventType string
Severity string
Source string
TenantId guid
TimeGenerated datetime

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Cybereinforce Threat Enforcement (CTE)

Content Items Using This Table (19)

Analytic Rules (18)

In solution Cybereinforce:

Analytic Rule Selection Criteria
CTE - Admin Login Detected
CTE - Blocked URL Attempted
CTE - CTI Blocked URL Attempted
CTE - Compromised Device Suspected (High-Volume IOC Blocks)
CTE - Device Enrolled but On Hold
CTE - Device License Capacity Critical (99%)
CTE - Device License Capacity High (95%)
CTE - Device Repeatedly Blocked Across Multiple Days
CTE - Enrollment Token Generated
CTE - License Expiring Critically (7 Days)
CTE - License Expiring Soon (30 Days)
CTE - Possible Company-Wide C2 Campaign (Multiple Devices, Same Destination)
CTE - Risky Device (Multiple IOC URL Hits)
CTE - Rule Capacity Critical (95%)
CTE - Rule Capacity High (90%)
CTE - Security Rule Changed (Created/Updated/Deleted)
CTE - Stale Device (No Heartbeat in 30 Days)
CTE - Sudden Block Spike Detected

Workbooks (1)

In solution Cybereinforce:

Workbook Selection Criteria
CybereinforceCTE

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index