Disabled accounts using Squid proxy

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Query finds accounts recorded as disabled by AD in previous time period but still using proxy in current time period. Presumes default squid log format is used. http://www.squid-cache.org/Doc/config/access_log/

Attribute Value
Type Hunting Query
Solution Standalone Content
ID 959fe0f0-7ac0-467c-944f-5b8c6fdc9e72
Tactics CredentialAccess
Techniques T1110
Required Connectors Syslog
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/Syslog/disabled_account_squid_usage.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries