Speculus - Sign-in attempt from high-risk IP indicator

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Matches Microsoft Entra ID sign-in attempts against high-risk Speculus IP indicators (risk score >= 75) received in the last 14 days. A sign-in from a known C2, botnet, or brute-force source IP may indicate credential theft or account takeover.

Attribute Value
Type Analytic Rule
Solution Speculus Threat Intelligence
ID e1b8d4a6-9c27-45f3-8a1e-7f2c0d9b5e64
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess, CredentialAccess
Techniques T1078, T1110
Required Connectors SpeculusThreatIntel, AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Speculus_Indicators_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Speculus Threat Intelligence