SAST Auth Finding Correlated with Brute Force

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects applications with open SAST authentication findings that are simultaneously experiencing brute force login attempts in Azure AD. Correlates StratoSecure SAST findings with SigninLogs failure spikes.

Attribute Value
Type Analytic Rule
Solution StratoSecure
ID 4ae9f294-410d-4c11-9072-0d8fcf5162d8
Severity High
Status Available
Kind Scheduled
Tactics CredentialAccess, InitialAccess
Techniques T1110, T1078
Required Connectors StratoSecurePush
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SigninLogs ✓ ✗ ✓
StratoSecure_Findings_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to StratoSecure