UniFi Site Manager: IPS/IDS disabled or misconfigured

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies when a UniFi gateway threat-protection state transitions away from the expected IPS-active mode, which may indicate admin action or attacker tampering.

Attribute Value
Type Analytic Rule
Solution UniFi Site Manager (CCF)
ID 36a64027-729e-51d7-16bf-8e926c03712a
Severity High
Status Available
Kind Scheduled
Tactics DefenseEvasion
Techniques T1562
Required Connectors UniFiSiteManagerConnectorDefinition
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Unifi_SiteManager_Sites_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to UniFi Site Manager (CCF)