Anomaly in SMB Traffic(ASIM Network Session schema)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This detection detects abnormal SMB traffic, a file-sharing protocol. By calculating the average deviation of SMB connections over last 14 days, flagging sources exceeding 50 average deviations.

Attribute Value
Type Analytic Rule
Solution Network Session Essentials
ID 8717e498-7b5d-4e23-9e7c-fa4913dbfd79
Severity Medium
Status Available
Kind Scheduled
Tactics LateralMovement
Techniques T1021, T1021.002
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Network Session Essentials