DEV-0270 New User Creation

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


The following query tries to detect creation of a new user using a known DEV-0270 username/password schema

Attribute Value
Type Analytic Rule
Solution Dev 0270 Detection and Hunting
ID 7965f0be-c039-4d18-8ee8-9a6add8aecf3
Severity High
Status Available
Kind Scheduled
Tactics Persistence
Techniques T1098
Required Connectors SecurityEvents, WindowsSecurityEvents, MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DeviceProcessEvents ?
SecurityEvent ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Dev 0270 Detection and Hunting