Utimaco ESKM - High-volume private key retrievals by user

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identify users performing unusually high volumes of successful KMIP GET or EXPORT operations against key objects in the last 24 hours.

Attribute Value
Type Hunting Query
Solution Utimaco Enterprise Secure Key Manager
ID 9b1a3b3e-7e16-4a3b-8a8f-7f1f2b1c0b03
Tactics Collection, Exfiltration
Techniques T1552, T1005
Required Connectors UtimacoESKMConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
UtimacoESKMKmipServerLogs_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Utimaco Enterprise Secure Key Manager