StealthTalk - Impossible travel

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies a single StealthTalk user authenticating from two different countries within a 30-minute window. Legitimate physical travel between countries cannot occur on that timescale, so this is a strong indicator of stolen credentials.

Attribute Value
Type Hunting Query
Solution StealthTalk
ID c1d4e7f2-8b3a-4c6d-9e5f-2a1b3c4d5e6f
Tactics InitialAccess, CredentialAccess
Techniques T1078
Required Connectors StealthTalkAnomalousAuth
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
StealthTalkAnomalousAuth_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to StealthTalk