Darktrace Model Alert

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query searches for Darktrace model alerts and creates a Microsoft Sentinel alert from each matching event. Edit this analytic rule if you would like it to create Microsoft Sentinel incidents.

Attribute Value
Type Analytic Rule
Solution Darktrace
ID 9392a06f-63a4-4a5d-8ca3-647064b13c28
Severity High
Kind NRT
Tactics InitialAccess, Execution, LateralMovement, CommandAndControl
Techniques T1190, T1059, T1021, T1071
Required Connectors DarktraceActiveAISecurityPlatform
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DarktraceModelAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Darktrace