Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies actors making their first configuration change in the lookback window. New legitimate admins look identical to compromised credentials - review whether each surfaced actor is expected to have admin rights.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Tailscale (CCF) |
| ID | a91f4d3c-1b7e-4f2a-9c1d-0e3b5f7c8d9a |
| Tactics | InitialAccess, Persistence |
| Techniques | T1078 |
| Required Connectors | TailscaleCCF |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
Tailscale_Audit_CL |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊