Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Triggers an incident when a GTI Relevance System Alert of type data_leak is ingested. Data Leak alerts indicate that sensitive organisational data (credentials, PII, intellectual property, source code, databases, etc.) has been found exposed on the dark web, paste sites, or underground forums and matches your organisation profile. Each unique Alert ID is grouped into a single incident.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Google Threat Intelligence |
| ID | d4e5f6a7-b8c9-0123-defa-234567890124 |
| Severity | High |
| Status | Available |
| Kind | Scheduled |
| Tactics | Exfiltration, Impact, CredentialAccess, Collection |
| Techniques | T1567, T1530, T1552, T1485 |
| Required Connectors | GoogleThreatIntelligenceRelevanceSystemAlertsAPI |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
RelevanceSystemAlerts_CL |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Analytic Rules · Back to Google Threat Intelligence