CYFIRMA - Attack Surface - Malicious Domain/IP Reputation High Rule

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This alert is raised when CYFIRMA detects a critical reputation score for an IP address linked to your infrastructure. The IP has been previously associated with hacking activity and web application attacks. Denied outbound traffic to a foreign country from a known Microsoft data center IP suggests potential misuse or compromise of cloud infrastructure.

Attribute Value
Type Analytic Rule
Solution Cyfirma Attack Surface
ID 7ff6f6d7-9672-4567-99fc-cb8a58c3bce7
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess, CommandAndControl, Reconnaissance, Impact, DefenseEvasion, Exfiltration
Techniques T1566.002, T1071.001, T1090.002, T1595.002, T1036.005, T1499, T1041
Required Connectors CyfirmaAttackSurfaceAlertsConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CyfirmaASDomainIPReputationAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Cyfirma Attack Surface