Samsung Knox - Application Privilege Escalation or Change Events

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


When a Knox mobile app has transitioned from an acceptable uid/esuid/fsuid to a different, non-App id.

Attribute Value
Type Analytic Rule
Solution Samsung Knox Asset Intelligence
ID 215e89ca-cdbc-4661-b8b2-7041f6ecc7fb
Severity High
Status Available
Kind NRT
Tactics PrivilegeEscalation
Techniques T1548
Required Connectors SamsungDCDefinition
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Samsung_Knox_Process_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Samsung Knox Asset Intelligence