Cisco ASA - Possible Data Exfiltration Detection

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects potential data exfiltration when an internal source IP sends a large amount of outbound data to the internet, especially when the volume is significantly higher than its normal behavior.

Attribute Value
Type Analytic Rule
Solution CiscoASA
ID f3a8c2d0-7b41-4e9a-9f6a-2d8a1c4e5b72
Severity Medium
Status Available
Kind Scheduled
Tactics Exfiltration
Techniques T1041, T1048
Required Connectors CiscoAsaAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CommonSecurityLog DeviceAction in "accept,accepted,allow,allowed,permitted"
DeviceProduct has_any "ASA"
✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to CiscoASA