Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Hunts for post-auth configuration tampering on Fortinet, Palo Alto, and Cisco appliances in CommonSecurityLog, including firewall policy weakening, local admin changes, auth updates, and VPN/routing/ACL modifications.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Hybrid Attack - Cloud & Identity |
| ID | 3d0ffd07-026f-44cf-9f60-8df51ba76690 |
| Tactics | DefenseEvasion, Persistence |
| Techniques | T1562.004, T1136.001, T1098 |
| Required Connectors | CefAma |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
CommonSecurityLog |
DeviceEventClassID in "0100044547,111010,44547"DeviceEventClassID == "CONFIG"DeviceEventClassID has_any "111007,111008,111010"DeviceProduct has_any "ASA,FTD,Firepower"DeviceProduct startswith "FortiGate"DeviceVendor in "Cisco,Fortinet,Palo Alto Networks" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity