Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This content is employed to correlate with Microsoft Defender XDR phishing-related alerts. It focuses on instances where a user successfully connects to a phishing URL from a non-Microsoft network device and subsequently makes successful sign-in attempts from the phishing IP address.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Standalone Content |
| ID | 779731f7-8ba0-4198-8524-5701b7defddc |
| Severity | Medium |
| Kind | Scheduled |
| Tactics | PrivilegeEscalation |
| Techniques | T1078 |
| Required Connectors | OfficeATP, PaloAltoNetworks, Fortinet, CheckPoint, Zscaler |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
CommonSecurityLog |
DeviceProduct startswith "FireWall"DeviceProduct startswith "FortiGate"DeviceProduct startswith "NSSWeblog"DeviceProduct startswith "PAN"DeviceProduct startswith "URL"DeviceProduct startswith "VPN"DeviceVendor has_any "Check Point,Fortinet,Palo Alto Networks,Zscaler" |
✓ | ✓ | ? |
SecurityAlert |
✓ | ✗ | ? | |
SigninLogs |
✓ | ✗ | ? |
The following connectors provide data for this content item:
Solutions: Common Event Format, IoTOTThreatMonitoringwithDefenderforIoT, Microsoft Defender for Cloud, Microsoft Defender for Cloud Apps, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Entra ID, Microsoft Entra ID Protection, MicrosoftDefenderForEndpoint, MicrosoftPurviewInsiderRiskManagement, VirtualMetric DataStream, Zscaler Internet Access
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊