Uniqkey - Excessive credential access

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects an actor reading an abnormally large number of credentials from Uniqkey within a single hour (default threshold: more than 50 access events). Bulk credential reads are rarely part of normal daily work and can indicate a compromised session harvesting secrets, or an insider collecting credentials ahead of departure. Tune the threshold to your organization's baseline, and consider a lower threshold for actors of type scim or system that normally never read credentials interactively.

Attribute Value
Type Analytic Rule
Solution Uniqkey
ID 755c7adb-1015-4be3-9e56-55e72009c088
Severity Medium
Kind Scheduled
Tactics CredentialAccess
Techniques T1555
Required Connectors UniqkeyEventsConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
UniqkeyEvents_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Uniqkey