Cisco Umbrella - Request Allowed to harmful/malicious URI category

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


It is reccomended that these Categories shoud be blocked by policies because they provide harmful/malicious content..

Attribute Value
Type Analytic Rule
Solution GitHub Only
ID d6bf1931-b1eb-448d-90b2-de118559c7ce
Severity Medium
Kind Scheduled
Tactics CommandAndControl, InitialAccess
Required Connectors CiscoUmbrellaDataConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CiscoUmbrellaAdminAudit_CL ? ?
CiscoUmbrellaCloudFirewall_CL ? ?
CiscoUmbrellaDLP_CL ? ?
CiscoUmbrellaDNS_CL ? ?
CiscoUmbrellaFileEvent_CL ? ?
CiscoUmbrellaIPS_CL ? ?
CiscoUmbrellaRemoteAccessVPN_CL ? ?
CiscoUmbrellaWebTraffic_CL ? ?
CiscoUmbrellaZeroTrustAccessFlow_CL ? ?
CiscoUmbrellaZeroTrustAccess_CL ? ?
Cisco_Umbrella_audit_CL 🔶
Cisco_Umbrella_cloudfirewall_CL 🔶
Cisco_Umbrella_dlp_CL 🔶
Cisco_Umbrella_dns_CL 🔶
Cisco_Umbrella_fileevent_CL 🔶
Cisco_Umbrella_intrusion_CL 🔶
Cisco_Umbrella_ip_CL 🔶
Cisco_Umbrella_proxy_CL 🔶
Cisco_Umbrella_ravpnlogs_CL 🔶
Cisco_Umbrella_ztaflow_CL 🔶
Cisco_Umbrella_ztna_CL 🔶

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules