Netskope - DLP Incident Spike

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects a spike in Netskope DLP incidents within a short window. A sudden increase in DLP violations for a single user or DLP profile can indicate active data exfiltration, a misconfigured policy, or bulk handling of sensitive data. Triggers when a user generates more DLP incidents in the last hour than a configurable threshold.

Attribute Value
Type Analytic Rule
Solution NetskopeAlertEvents
ID c3f8e4d6-0d57-4a3b-9e2c-4f6a8b0d3e52
Severity High
Status Available
Kind Scheduled
Tactics Exfiltration, Collection
Techniques T1567, T1530
Required Connectors NetskopeAlertEventsConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
NetskopeAlertEvents_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to NetskopeAlertEvents