UniFi Site Manager: IPS signature count dropped >50%

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies when the IPS signature ruleset count drops by more than half versus the 7-day maximum, indicating broken threat-intel feeds or rollback.

Attribute Value
Type Analytic Rule
Solution UniFi Site Manager (CCF)
ID aa188a24-783a-76a1-cd11-3bcac0e97de9
Severity Medium
Status Available
Kind Scheduled
Tactics DefenseEvasion
Techniques T1562
Required Connectors UniFiSiteManagerConnectorDefinition
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Unifi_SiteManager_Sites_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to UniFi Site Manager (CCF)