Uniqkey - Security policy change

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects modifications to Uniqkey organization security policies, such as authentication, password or sharing policy settings. Weakening a policy is a common preparatory step before credential abuse, and even legitimate changes deserve a review trail, so each policy change is raised as an alert with the acting administrator attached.

Attribute Value
Type Analytic Rule
Solution Uniqkey
ID ac008972-e70f-4040-96ad-bdce1c642839
Severity Medium
Kind Scheduled
Tactics DefenseEvasion, Persistence
Techniques T1562
Required Connectors UniqkeyEventsConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
UniqkeyEvents_CL ? ✓ ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Uniqkey