Field Effect MDR Alert: ARO Alert

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Creates an incident for each Field Effect MDR ARO alert ingested into the workspace.

Attribute Value
Type Analytic Rule
Solution FieldEffectMDR
ID 6d2d6b3f-7d7b-4d4a-9b2b-9f7f3b8c2a11
Severity Medium
Status Available
Kind Scheduled
Tactics Execution, DefenseEvasion
Techniques T1059, T1562
Required Connectors FieldEffectCCF
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
FieldEffectAROAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to FieldEffectMDR