Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Detects a data export performed by an employee whose Uniqkey account was created or activated within the preceding 14 days. A freshly provisioned account has little legitimate reason to export organization credentials, so this pattern can indicate a compromised onboarding flow or an account created specifically to stage exfiltration. The action filter matches the provisioning action identifiers from the Uniqkey audit-log catalog, with a name-based fallback for future action variants.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Uniqkey |
| ID | 3939f01f-9563-4cd3-8423-97a82e82719b |
| Severity | Medium |
| Kind | Scheduled |
| Tactics | CredentialAccess, Persistence |
| Techniques | T1555, T1136 |
| Required Connectors | UniqkeyEventsConnector |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
UniqkeyEvents_CL |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊