CTE - Compromised Device Suspected (High-Volume IOC Blocks)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


A single device is generating an unusually high volume of threat-intel-matched (IOC) blocks in a short window. This pattern is more consistent with malware/beaconing behavior than manual browsing and should be investigated for device compromise. Note: the 5-per-hour threshold below is a starting point based on limited sample data - tune it once a real baseline is established.

Attribute Value
Type Analytic Rule
Solution Cybereinforce
ID 59246163-4cc0-4e96-a0f0-f098a83cf425
Severity High
Kind Scheduled
Tactics CommandAndControl, Exfiltration
Techniques T1071, T1041
Required Connectors cybereinforce_cte
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CybereinforceCTE_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Cybereinforce