Successful logins to SOC Prime platform from bad IP addresses

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This rule identifies successful logins from IP addresses previously flagged as malicious (e.g., botnets, TOR exit nodes, or known malicious IPs)

Attribute Value
Type Analytic Rule
Solution SOC Prime CCF
ID f8e7d6c5-b4a3-4122-8110-0987654321fe
Severity Medium
Status Available
Kind Scheduled
Tactics InitialAccess
Techniques T1078
Required Connectors SOCPrimeAuditLogsDataConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SOCPrimeAuditLogs_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to SOC Prime CCF