GTI - Data Leak Alert Detected

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Triggers an incident when a GTI Relevance System Alert of type data_leak is ingested. Data Leak alerts indicate that sensitive organisational data (credentials, PII, intellectual property, source code, databases, etc.) has been found exposed on the dark web, paste sites, or underground forums and matches your organisation profile. Each unique Alert ID is grouped into a single incident.

Attribute Value
Type Analytic Rule
Solution Google Threat Intelligence
ID d4e5f6a7-b8c9-0123-defa-234567890124
Severity High
Status Available
Kind Scheduled
Tactics Exfiltration, Impact, CredentialAccess, Collection
Techniques T1567, T1530, T1552, T1485
Required Connectors GoogleThreatIntelligenceRelevanceSystemAlertsAPI
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
RelevanceSystemAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Google Threat Intelligence