Uniqkey - Credential export from newly created account

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects a data export performed by an employee whose Uniqkey account was created or activated within the preceding 14 days. A freshly provisioned account has little legitimate reason to export organization credentials, so this pattern can indicate a compromised onboarding flow or an account created specifically to stage exfiltration. The action filter matches the provisioning action identifiers from the Uniqkey audit-log catalog, with a name-based fallback for future action variants.

Attribute Value
Type Analytic Rule
Solution Uniqkey
ID 3939f01f-9563-4cd3-8423-97a82e82719b
Severity Medium
Kind Scheduled
Tactics CredentialAccess, Persistence
Techniques T1555, T1136
Required Connectors UniqkeyEventsConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
UniqkeyEvents_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Uniqkey