High Urgency IONIX Action Items

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query creates an alert for active IONIX Action Items with high urgency (9-10). Urgency can be altered using the "min_urgency" variable in the query.

Attribute Value
Type Analytic Rule
Solution IONIX
ID 8e0403b1-07f8-4865-b2e9-74d1e83200a4
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1190, T1195
Required Connectors CyberpionSecurityLogs
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CyberpionActionItems_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to IONIX