Sentinel One - Same custom rule triggered on different hosts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Detects when same custom rule was triggered on different hosts.

Attribute Value
Type Analytic Rule
Solution SentinelOne
ID 5586d378-1bce-4d9b-9ac8-e7271c9d5a9a
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess, LateralMovement
Techniques T1190, T1210
Required Connectors SentinelOne
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SentinelOneActivities_CL ? ?
SentinelOneAgents_CL ? ?
SentinelOneAlerts_CL ? ?
SentinelOneGroups_CL ? ?
SentinelOneThreats_CL ? ?
SentinelOne_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to SentinelOne