Vectra Create Detection Alert for Hosts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This analytic rule is looking for new attacker behaviors observed by the Vectra Platform. The intent is to create entries in the SecurityAlert table for every new detection attached to an entity monitored by the Vectra Platform

Attribute Value
Type Analytic Rule
Solution Vectra XDR
ID fb861539-da19-4266-831f-99459b8e7605
Severity Medium
Status Available
Kind Scheduled
Tactics Persistence
Techniques T1546
Required Connectors VectraXDR
Source View on GitHub

⚠️ Not listed in Solution JSON: This content item was discovered by scanning the solution folder but is not included in the official Solution JSON file. It may be a legacy item, under development, or excluded from the official solution package.

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Detections_Data_CL ✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Vectra XDR