PRODAFT USTA - Corporate credential compromised

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies a new PRODAFT USTA Account Takeover Prevention ticket that exposes a corporate credential (IsCorporate = true). These typically originate from infostealer infections on a victim host and indicate that a valid corporate identity may be available to threat actors. Investigate the affected account, reset credentials, and review the victim host for malware.

Attribute Value
Type Analytic Rule
Solution PRODAFT USTA - Account Takeover Prevention
ID 9ad6cf22-ffbb-4422-9933-9bbd0104f818
Severity High
Status Available
Kind Scheduled
Tactics CredentialAccess, InitialAccess
Techniques T1555, T1078
Required Connectors PRODAFTUstaATPCCPDefinition
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
PRODAFTUstaCompromisedCredentials_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to PRODAFT USTA - Account Takeover Prevention