Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Detects an actor reading an abnormally large number of credentials from Uniqkey within a single hour (default threshold: more than 50 access events). Bulk credential reads are rarely part of normal daily work and can indicate a compromised session harvesting secrets, or an insider collecting credentials ahead of departure. Tune the threshold to your organization's baseline, and consider a lower threshold for actors of type scim or system that normally never read credentials interactively.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Uniqkey |
| ID | 755c7adb-1015-4be3-9e56-55e72009c088 |
| Severity | Medium |
| Kind | Scheduled |
| Tactics | CredentialAccess |
| Techniques | T1555 |
| Required Connectors | UniqkeyEventsConnector |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
UniqkeyEvents_CL |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊