Utimaco ESKM - Rare KMIP users in the last 24 hours

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies KMIP user accounts seen in the last 24 hours that were not observed in the prior 14 days. Rare accounts may indicate newly provisioned credentials or unauthorized integrations.

Attribute Value
Type Hunting Query
Solution Utimaco Enterprise Secure Key Manager
ID 9b1a3b3e-7e16-4a3b-8a8f-7f1f2b1c0b01
Tactics InitialAccess, Persistence
Techniques T1078
Required Connectors UtimacoESKMConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
UtimacoESKMKmipServerLogs_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Utimaco Enterprise Secure Key Manager