Speculus - Network traffic to or from high-risk IP indicator

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Matches network events in CommonSecurityLog against high-risk Speculus IP indicators (risk score >= 75) received in the last 14 days. These IPs are associated with malicious activity such as command and control, botnets, ransomware infrastructure, or brute-force campaigns.

Attribute Value
Type Analytic Rule
Solution Speculus Threat Intelligence
ID a7c3f9e2-4d18-4b6a-9f0c-2e5d8b1a6c43
Severity High
Status Available
Kind Scheduled
Tactics CommandAndControl, InitialAccess
Techniques T1071, T1090
Required Connectors SpeculusThreatIntel
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Speculus_Indicators_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Speculus Threat Intelligence