Red Sift - Login from previously unseen IP address

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects a successful login from an IP address that has not been seen in the previous 14 days for that user, which may indicate compromised credentials or unauthorized access.

Attribute Value
Type Analytic Rule
Solution Red Sift
ID c3d4e5f6-a7b8-9012-cdef-123456789012
Severity Medium
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1078
Required Connectors RedSiftPush
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
RedSiftAuth_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Red Sift