CTERA Mass Deletions Detection Analytic

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This analytic rule detects and alerts when large amount of deletion operations generated by the CTERA Edge Filer

Attribute Value
Type Analytic Rule
Solution CTERA
ID 5365f294-0c67-432a-bacf-b1282a3b6c46
Severity High
Status Available
Kind Scheduled
Tactics Impact
Techniques T1485
Required Connectors CTERA
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
Syslog ProcessName == "gw-audit" ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to CTERA