Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies privilege, sharing or group-membership changes in Uniqkey where the actor and the target of the change are the same person. In a healthy administrative process, access changes are made by a different administrator, so a self-referential grant is a strong indicator of insider privilege escalation or a compromised administrator account expanding its own reach.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Uniqkey |
| ID | 4b1fefb3-419a-4bbe-8a74-ef8288a8d8d0 |
| Severity | Medium |
| Kind | Scheduled |
| Tactics | PrivilegeEscalation, Persistence |
| Techniques | T1078, T1098 |
| Required Connectors | UniqkeyEventsConnector |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
UniqkeyEvents_CL |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊