CYFIRMA - Brand Intelligence - Product/Solution Medium Rule

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This alert is raised when CYFIRMA detects a critical reputation score for an IP address linked to your infrastructure. The IP has been previously associated with hacking activity and web application attacks. Denied outbound traffic to a foreign country from a known Microsoft data center IP suggests potential misuse or compromise of cloud infrastructure.

Attribute Value
Type Analytic Rule
Solution Cyfirma Brand Intelligence
ID 458d964f-d039-4ce0-9741-0b6245ba3374
Severity Medium
Status Available
Kind Scheduled
Tactics ResourceDevelopment, InitialAccess
Techniques T1585.002, T1583.001, T1566, T1583
Required Connectors CyfirmaBrandIntelligenceAlertsDC
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CyfirmaBIProductSolutionAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Cyfirma Brand Intelligence