CTE - Security Rule Changed (Created/Updated/Deleted)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


A URL blocking/enforcement rule was created, updated, or deleted (potential policy tampering). Deduplicated per rule/day to avoid re-alerting on replayed audit events for the same change.

Attribute Value
Type Analytic Rule
Solution Cybereinforce
ID cf7ad1f5-7325-4bda-83d4-957ec943c457
Severity Medium
Kind Scheduled
Tactics DefenseEvasion
Techniques T1562
Required Connectors cybereinforce_cte
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CybereinforceCTE_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Cybereinforce