StealthTalk - Login outside work zone

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies a single StealthTalk authentication originating from a country or city that does not match the user's assigned (expected) geographic zone. Each individual mismatch is treated as an incident - there is no aggregation threshold, since a single login from an unexpected country is high-confidence evidence of a credential issue. An incident fires when LoginCountry differs from AssignedCountry OR LoginCity differs from AssignedCity. Source IPv4, raw event ID, and both the observed and expe

Attribute Value
Type Analytic Rule
Solution StealthTalk
ID a7c3e9b1-4f5d-4e2a-9b8c-1d2e3f4a5b6c
Severity High
Status Available
Kind Scheduled
Tactics InitialAccess, DefenseEvasion, CredentialAccess
Techniques T1078
Required Connectors StealthTalkAnomalousAuth
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
StealthTalkAnomalousAuth_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to StealthTalk