Netskope - Suspicious Application Activity (Low Confidence / Risky App)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects activity involving risky or low Cloud Confidence Level (CCL) applications, blocked application actions, or sensitive activities (upload, share, download) on unsanctioned apps. Helps surface Shadow IT and potential data leakage via risky cloud applications.

Attribute Value
Type Analytic Rule
Solution NetskopeAlertEvents
ID b2e7d3c5-9c46-4f2a-8d1b-3e5f7a9c2d41
Severity Medium
Status Available
Kind Scheduled
Tactics Exfiltration, CommandAndControl
Techniques T1567, T1102
Required Connectors NetskopeAlertEventsConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
NetskopeAlertEvents_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to NetskopeAlertEvents