SpyCloud infostealer malware credential exposure

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Identifies credentials harvested by infostealer malware on a compromised device. This exposure may indicate an actively compromised endpoint with associated command-and-control risk.

Attribute Value
Type Analytic Rule
Solution SpyCloud Enterprise Protection CCF
ID ead4deed-9d48-4646-aee0-6b46c2dd1ae6
Severity High
Kind scheduled
Tactics CredentialAccess, CommandAndControl
Techniques T1555, T1071
Required Connectors SpyCloudEnterpriseProtectionCCF
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SpyCloudBreachWatchlistV2_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to SpyCloud Enterprise Protection CCF